KILB Product Designer

Privacy Policy

KILB Product Designer for Shopify · Last updated 11 August 2026

1. Controller and contact

Christian Kilb, Saseler Mühlenweg 2, 22395 Hamburg, Germany, operates KILB Product Designer. Questions and privacy requests can be sent to [email protected]. Additional business information is available in the legal notice.

2. Scope and roles

This policy covers the Shopify app served from app.product-designer.io. For merchant account, support, security, and service-operation data, Christian Kilb acts as controller. For personal data that a merchant's customers enter into a product design or that is associated with an order, the merchant generally determines the purposes and means of processing and Christian Kilb processes the data on the merchant's instructions. Customers should therefore direct shop-specific privacy requests to the merchant first.

3. Data the app processes

  • Merchant and app-user data: shop domain, Shopify access scopes and tokens, session identifiers, and the Shopify user ID, name, email address, locale, and account role supplied during authentication.
  • Merchant configuration: product and variant mappings, canvas settings, fonts, pricing rules, templates, predefined images, and library metadata.
  • Customer design data: text, QR-code content, uploaded images, selected library images, canvas documents, previews, and generated fulfillment files.
  • Order-related data: order number, line-item ID, quantity, and the Product Designer line-item properties required to associate and verify a saved design. The app does not require payment-card details.
  • Technical data: request time, IP address, browser or device information, requested URL, error details, and similar security and operational metadata that may appear in infrastructure logs.

4. Purposes and legal bases

The data is processed to:

  • install, authenticate, operate, secure, support, and bill for the app;
  • let merchants configure customizable products and let customers create, save, purchase, and fulfill designs;
  • generate previews and fulfillment files, verify personalization charges, and prevent tampering;
  • respond to support, security, and legally required data requests.

For data controlled by Christian Kilb, the legal bases are performance of a contract or steps requested before a contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c)), and legitimate interests in providing a secure, reliable service and preventing abuse (Article 6(1)(f)). For customer data processed on behalf of a merchant, the merchant is responsible for selecting and communicating the applicable legal basis.

5. Storage and service providers

  • Shopify: configurations, designs, product mappings, and most images are stored as merchant-owned Shopify metaobjects, metafields, and Shopify Files. Shopify also provides authentication, app pricing, cart, checkout, order, webhook, and extension infrastructure.
  • Hetzner Online GmbH, Germany: hosts the app server, its operational PostgreSQL database, and app-controlled fulfillment-file storage.

The PostgreSQL database stores Shopify sessions and per-shop pricing and signing state; it is not the primary store for merchant configurations or customer designs. Service providers receive data only as needed to perform their services. The app does not sell personal data and does not use it for third-party advertising.

6. Files and download links

Shopify Files are delivered through Shopify's public content-delivery network. Merchants and customers should not upload confidential material as a design image. Print-ready render files remain on app-controlled storage and use unguessable capability URLs. Anyone who receives such a URL can download the file until it is deleted, so the URL should be treated as confidential.

7. Retention and deletion

  • Merchant-controlled Shopify records remain until the merchant deletes them or Shopify removes them under its retention rules.
  • On uninstall, the app deletes local Shopify sessions, pricing state, signing state, and app-controlled render files. Merchant-owned Shopify metaobjects and Shopify Files intentionally remain in the shop so the merchant can recover them after reinstalling or delete them through Shopify.
  • A Shopify customer-redaction request deletes associated design groups, render files, and uploaded design images.
  • A Shopify shop-redaction request triggers best-effort deletion of the shop's Shopify custom data and files, app-controlled files, sessions, and local shop state.
  • Technical logs are retained only as long as reasonably necessary for security, incident investigation, and reliable operation.

8. International transfers

The app server is hosted in Germany. Shopify may process data in other countries as described in Shopify's privacy and data-processing terms. Where personal data is transferred outside the European Economic Area, the responsible provider must use a lawful transfer mechanism, such as an adequacy decision or standard contractual clauses.

9. Your rights

Subject to applicable law, individuals may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interests. They may also complain to a competent data-protection authority. Merchant customers should contact the merchant first; Christian Kilb will assist merchants with verified requests relating to the app.

10. Security

The app uses encrypted HTTPS connections, Shopify authentication and signed webhooks, access controls, signed personalization quotes, and restricted operational access. No security measure is absolute, but controls are reviewed and updated in proportion to the nature of the data and the service.

11. Changes

This policy may be updated when the app, its providers, or legal requirements change. The current version and its effective date will remain available at this URL.