LS - PrintFormi — privacy notice
Last updated 2026-08-12.
LS - PrintFormi turns a Shopify order into the paperwork around it: invoices, packing slips, returns forms and similar documents, printed by the merchant or downloaded by the shopper from a link in the shop’s own emails. This notice describes what personal data that involves, why, where it is held and for how long.
Who is responsible
| Registered name | LorinSoft LLC |
|---|---|
| Registered address | jk Marica Gardens 12/20, Plovdiv, Bulgaria |
| Company number | BG206285889 |
| [email protected] | |
| Telephone | +359899203126 |
Our role
For the order and customer data flowing through LS - PrintFormi the merchant is the data controller and LorinSoft LLC is a data processor, acting on the merchant’s instructions. The processor terms below are accepted by installing the app.
What is processed, and why
| Data | Why | Kept |
|---|---|---|
| Order contents, totals, addresses, customer name | Rendering the document that was asked for | Not stored. Read from Shopify at the moment of rendering and discarded with the request |
| Invoice numbers against order IDs | A reprint must carry the number the customer already holds, and the sequence must have no gaps | Until the shop is erased. Contains no personal data |
| Bulk export PDFs | A large export is rendered in the background and downloaded afterwards | Until erased on request or with the shop |
| Company name and VAT number, per customer | Printing them on business invoices | Held on the customer record in Shopify, not in our database |
| Shopify access token, installing user’s name and email | Making API calls on the shop’s behalf | Until uninstall plus 48 hours. Encrypted at rest |
| Application logs | Diagnosing failures a merchant reports | 180 days, then deleted automatically |
The design goal is that an app which stores almost nothing has almost nothing to answer for. Documents are generated on request rather than kept, which is why most of the table above says so.
Sub-processors
- Shopify — the source of all order and customer data.
- Our hosting provider — the server and database, located in the European Union.
- Our email provider — carries the invoice email, and only that. One message at a time: the address on the order, the subject and text the shop wrote, and the invoice. A shop that sends from its own mailbox does not use it at all, and for that shop this row is not a sub-processor of anything.
That email exists because Shopify cannot send it. Shopify’s order-email mutations are payment requests — they refuse an order that is already paid — and none of them can attach a file, so a shop whose customer needs the invoice itself rather than a link to it needsLS - PrintFormi to send the message.
When it does, the shopper’s address is read from the order to address that one message and is not written down. LS - PrintFormi keeps no delivery log, so there is no record here naming a shopper, and nothing to hand over or erase when one asks. A shop that never turns the automatic email on and never presses the button on an order sends nothing through this route at all.
A shop can give LS - PrintFormi its own mailbox instead, under Settings, and then the message is sent by that shop’s own mail server and never touches ours. The one thing stored for it is the password to that mailbox, encrypted with the same key as the Shopify access tokens, never displayed again, and erased with the rest of the shop’s data when the app is uninstalled.
Monitoring. The app reports its own health to a private panel we run — error counts, queue depth, disk space, and the fact that an install or an uninstall happened. It is not a sub-processor of your data, because none of your data is in it: shop domains, order numbers, order and customer identifiers, email addresses and discount codes are stripped before anything is sent, and a shop appears only as an irreversible hash. What travels is what a failure looks like, never who it happened to.
Security
Everything is served over TLS. At rest, the values worth stealing are encrypted individually with AES-256-GCM: Shopify access and refresh tokens and the installing user’s name and email.
What that does not cover. The encryption key lives on the same host as the database. It therefore protects against a stolen disk, a copied backup or a leaked image — and not against an attacker who has gained root on the running machine. We would rather state that plainly than imply a guarantee the code does not make.
Erasure
- A customer erasure request deletes any stored export containing that customer’s orders. The export file goes entirely rather than being edited; the job row stays with its file cleared, so the merchant’s history still shows that an export happened.
- Uninstalling marks the shop inactive but keeps its templates, so a merchant who reinstalls does not lose their work.
- 48 hours after uninstall Shopify asks us to erase the shop, and everything belonging to it is deleted: templates, settings, invoice numbers, jobs, stored exports, email records and sessions.
- One thing outlives the shop, and it cannot be traced back to it: the date the free trial ended, how many orders were printed for in the 30 days before the erasure, and a one-way HMAC of the shop domain under a secret only this app holds. There is no domain, no name, no address and no order in it, and it cannot be reversed or matched against a list of stores by anyone else. It exists so that uninstalling and reinstalling does not hand out a second free trial, and it is the only record that survives. It is deleted 30 days after the erasure — the window it was kept for — after which a shop that comes back is treated as new, with a full trial and an empty meter.
Your rights
Shoppers should raise access, correction and erasure requests with the merchant they bought from — they are the controller, and Shopify’s own tools carry those requests to us automatically. Merchants can contact LorinSoft LLC directly using the details above.
Processor terms (GDPR Article 28)
By installing LS - PrintFormi, the merchant and LorinSoft LLC agree that:
- personal data is processed only on the merchant’s documented instructions, which the app’s own settings constitute;
- everyone with access is bound by confidentiality, and access to production data is limited to those who need it to operate the service;
- the security measures described above are maintained, and the merchant is told about a personal data breach without undue delay;
- sub-processors are limited to those listed above, and this notice is updated before any is added;
- we assist the merchant with data subject requests and with the mandatory Shopify privacy webhooks;
- on request we make available the information needed to demonstrate compliance, and allow an audit of it;
- on the merchant’s instruction, or 48 hours after uninstall, the data is deleted.
Changes
Material changes are reflected here with a new date at the top. This notice is versioned with the app’s source, so its history is the repository’s history.