Inksfy POD SaaS

Privacy Policy

We take a minimalist approach to data: we only collect what we need to run the Service for you, we keep it secure, and we never sell it.

Effective: May 8, 2026
Last updated: May 8, 2026

INKSFY LLC ("Inksfy", "we", "us", or "our") operates the Inksfy POD SaaS platform (the "Service"), a multi-tenant Print-on-Demand back-office that helps merchants automate product publishing, order fulfillment, and pricing across connected e-commerce channels (such as Temu, eBay, and Shopify). This Privacy Policy explains what personal data we collect, how we use and protect it, and the rights you have over it.

By creating an account, signing in, or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Service.

01

Data Controller

The data controller responsible for your personal data under this Policy is:

INKSFY LLC
A California limited liability company
16029 Main St, La Puente, CA 91744, United States
Privacy contact: hello@inksfy.com
02

Scope

This Policy applies to:

  • The Inksfy POD SaaS web application and all of its sub-domains operated by INKSFY LLC.
  • Application Programming Interfaces (APIs) we expose to authenticated merchants.
  • Transactional emails, system notifications, and support communications we send.

It does not apply to third-party platforms (such as Temu, eBay, Shopify, payment providers, or any other website you visit through links on our Service), each of which has its own privacy practices.

03

Information We Collect

3.1 Account & profile data

Email address, display name, hashed password, login method preference, time-zone and language settings, profile avatar, and any optional information you choose to provide in your profile.

3.2 Authentication data

Server-side session records, HTTP-only session cookies, public passkey credentials you enroll, and one-time magic-link tokens. We never store plaintext passwords; see Section 07 · Security.

3.3 Channel credentials

When you connect a sales channel (e.g. a Temu shop, an eBay account, or a Shopify store), we receive and store, on your behalf, OAuth access and refresh tokens, API keys, store identifiers, and similar credentials necessary to call that channel's APIs. These credentials are stored encrypted and used solely to operate the Service for you.

3.4 Channel business data

Once a channel is connected, we synchronize and store business data the channel exposes to you under your authorization, which may include:

  • Products, SKUs, attributes, images, size charts and templates;
  • Order records, fulfillment status, shipping labels, tracking numbers;
  • Pricing data, inventory data, financial summaries, settlement reports;
  • Buyer-related information limited to what the channel discloses for fulfillment purposes (e.g. shipping recipient name and address). Where a channel transmits encrypted shipping addresses (such as Temu's encrypted-address scheme), we do not decrypt them and rely on the channel's own buy-shipping flow.

3.5 Uploaded creative assets

Images, designs, mockups, copyright-related materials, and any other files you upload to the Service. These are stored in encrypted object storage operated by our sub-processor (see Section 05 · Sub-processors).

3.6 Operational data

IP address, browser user-agent, device and locale information, application logs, audit-trail entries (e.g. login success/failure, sensitive configuration changes), error reports, and aggregate performance metrics.

3.7 Cookies & similar technologies

We use a small number of strictly-necessary and security cookies; see Section 10 · Cookies for details.

04

How and Why We Use Your Data

We use the data described in Section 03 for the following purposes:

Purpose Lawful Basis (GDPR)
Provide and operate the Service (account, listings, orders, fulfillment, pricing). Performance of a contract
Synchronize data with the e-commerce channels you have connected. Performance of a contract / consent
Send transactional emails (sign-in links, alerts, system notices). Performance of a contract
Detect and prevent fraud, abuse, and account compromise; rate-limiting and CAPTCHA. Legitimate interest / legal obligation
Maintain audit logs and security records. Legitimate interest / legal obligation
Improve service quality, debug errors, plan capacity (using aggregated or pseudonymous data where possible). Legitimate interest
Comply with applicable tax, accounting, and other legal obligations. Legal obligation

We do not sell your personal data, share it with third parties for their own advertising, or use your business data to train artificial-intelligence models for unrelated third parties.

05

Sub-processors

We rely on a limited set of vetted infrastructure providers ("sub-processors") to deliver the Service. Each sub-processor is bound by a written agreement that requires confidentiality, security, and data-protection commitments at least as strong as ours.

Sub-processor Purpose Region
Neon, Inc. Managed PostgreSQL database (primary application data store). USA
Cloudflare, Inc. R2 object storage (uploaded assets), Turnstile bot protection, CDN, DNS. Global / USA
Upstash, Inc. Managed Redis (cache, rate-limit storage, queue coordination). USA
Resend, Inc. Transactional email delivery. USA
Hetzner / DigitalOcean Virtual private server infrastructure for application and worker nodes. EU / USA
Authorized e-commerce platforms (Temu, eBay, Shopify, etc.) Bidirectional data exchange limited to the platforms you explicitly connect via OAuth or API key. As designated

We may update this list as our infrastructure evolves. Material additions affecting personal-data processing will be communicated through the Service or via email to organization administrators.

06

International Data Transfers

Inksfy is established in the United States and our primary infrastructure is located in the United States and the European Union. If you access the Service from another jurisdiction, your data will be transferred to and processed in those regions. Where required, we rely on appropriate transfer mechanisms (such as the European Commission's Standard Contractual Clauses and equivalent safeguards) to protect cross-border transfers.

07

Security Measures

We implement layered technical and organizational measures, including:

  • Transport encryption. All traffic is served over HTTPS with TLS 1.2 or higher.
  • Password handling. Passwords are pre-hashed in your browser before transmission and stored on the server only as a salted, irreversible derivation produced by an industry-standard memory-hard key-derivation function. Plaintext passwords are never transmitted, logged, or stored. Our password storage aligns with OWASP ASVS Level 2 and NIST SP 800-63B.
  • Credential storage. Channel OAuth tokens and API keys are stored encrypted at rest and access is limited to the originating organization.
  • Multi-tenant isolation. Organization-scoped role-based access control (RBAC) with row-level ownership checks prevent one tenant from reading another's data.
  • Account protections. Cloudflare Turnstile CAPTCHA on sensitive endpoints, IP-based rate limiting, and audit logging of authentication events.
  • Infrastructure hardening. Hardened operating system images, network firewalls, fail2ban, restricted SSH access, and encrypted backups.
  • Operational discipline. Least-privilege administrative access, change-tracked deployments, and incident-response procedures.

No system can be guaranteed 100% secure. We will notify affected users and the relevant authorities of a personal-data breach where required by applicable law.

08

Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

Account data
Lifetime of your account, plus up to 30 days after a verified deletion request.
Channel business data
Up to 24 months after creation, or longer where required by tax / accounting law.
Audit logs
Up to 90 days, longer where required for security investigations or legal hold.
Application error logs
Up to 30 days.
Encrypted backups
Rolling window of up to 30 days.

When a retention period ends, we delete or irreversibly anonymize the data, unless we are required to retain it by law.

09

Your Rights

9.1 Rights for all users

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your personal data, subject to legal retention obligations.
  • Export a copy of your personal data in a machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a competent supervisory authority.

9.2 Additional rights — EEA, UK, and Switzerland (GDPR / UK GDPR)

  • Restrict or object to processing.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Identify our representative or contact your local data-protection authority.

9.3 Additional rights — California residents (CCPA / CPRA)

  • Right to know the categories and specific pieces of personal information we have collected.
  • Right to delete personal information we have collected.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information — note that we do not sell or share personal information for cross-context behavioral advertising.
  • Right to limit use and disclosure of sensitive personal information.
  • Right not to receive discriminatory treatment for exercising these rights.

9.4 How to exercise your rights

To exercise any of these rights, email hello@inksfy.com from the email address associated with your account. We will respond within the time-frame required by applicable law (no later than 30 days for most requests), and we will not charge a fee for reasonable requests.

10

Cookies

We use a minimal set of cookies, all of which are either strictly necessary or security-related:

  • Strictly-necessary session cookies — keep you signed in for the duration of your session. Set as HTTP-only and Secure.
  • Preference cookies — remember user-interface preferences such as your chosen language.
  • Bot-protection cookies — issued by our security provider to validate that requests are not from automated bots.

We do not use cookies for advertising, cross-site tracking, or third-party analytics profiling. Because the cookies we set are required to operate the Service, disabling them will prevent the Service from functioning correctly.

11

Children

The Service is a business-to-business platform intended for use by professional sellers and merchants. It is not directed to, and we do not knowingly collect personal data from, individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact us so we can delete it.

12

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our infrastructure, or applicable law. The "Last Updated" date at the top of this page indicates when this Policy was last revised. For material changes, we will additionally notify organization administrators by email or by an in-app notice. Continued use of the Service after the update takes effect constitutes acceptance of the revised Policy.

13

Contact Us

For privacy questions, requests, or complaints, contact us at:

INKSFY LLC
Attn: Privacy Officer
16029 Main St, La Puente, CA 91744, United States

© 2026 INKSFY LLC. All rights reserved.

Back to top