Privacy Policy
Last updated: July 20, 2026 · Applies to the AfterKit app for Shopify and afterkit.appAfterKit is operated by ADV Media Solutions, LLC (“we”, “us”). AfterKit is a Shopify app that delivers digital products — files, license keys and logins — to a merchant’s buyers. This policy explains what data we handle to do that, and nothing else: we don’t run ads, we don’t sell data, and we don’t use your data or your buyers’ data for any purpose beyond operating the service.
Data we collect from Shopify
When a merchant installs AfterKit, we receive data through Shopify’s APIs, strictly scoped to what delivery requires:
- Order data — order id, order number, and the purchased line items, so we know what to deliver.
- Buyer contact data — the buyer’s email address and name attached to an order, so we can send the delivery email and control access to the buyer hub.
- Product data — product and variant ids/titles the merchant links to deliverables.
We do not request or store buyer phone numbers, physical addresses, or any payment details.
Data created while the service runs
- Merchant content — files the merchant uploads, license keys and login credentials they import, branding (logo, colors), and community posts.
- Buyer activity — download and streaming events, including IP address and browser user-agent, kept for delivery security and abuse prevention.
- Community content — if the merchant enables Community: buyer questions, replies, display names and notification preferences.
How data is protected
- All traffic is encrypted in transit (TLS/HTTPS).
- All stored data sits on encrypted volumes; database backups are encrypted (AES-256) by our hosting provider.
- Shopify access tokens and license key values are additionally encrypted at the field level (AES-256-GCM).
- Download and streaming links are short-lived signed URLs; hub access is tokenized and every hub request is signature-verified.
Where data lives
Application servers and databases are hosted in the European Union (Amsterdam). Uploaded files are stored with Cloudflare R2. Delivery and notification emails are sent through Resend.
How long we keep data
- While the app is installed — data is kept as long as it’s needed to serve deliveries.
- After uninstall — everything is permanently deleted after a 30-day grace window (kept only so a merchant who reinstalls doesn’t lose their setup). This includes database records and uploaded file content.
- Erasure requests — Shopify’s GDPR webhooks are fully automated: a shop-erasure request deletes the shop’s data and files; a customer-erasure request scrubs that buyer’s personal data (email, IP, user-agent) and pseudonymizes their community posts. Data-export requests are compiled automatically and sent to the merchant to pass on to their customer.
Third parties we rely on
- Shopify — commerce platform (orders, webhooks, billing).
- Railway — application and database hosting (EU).
- Cloudflare R2 — file storage; this website is served by Cloudflare.
- Resend — transactional email delivery.
Each processes data only as needed to provide their service to us. We do not share data with anyone else.
Merchants’ responsibilities
Merchants remain the data controller for their buyers. AfterKit acts as a processor on the merchant’s instructions — delivering their products and, where enabled, hosting their buyer community.
This website
afterkit.app is a static site. It sets no cookies, runs no analytics, and collects nothing. If you email us, we use your address only to reply.
Contact
Privacy questions or requests: support@afterkit.app. We answer within 72 hours.