Privacy policy
Last updated September 30, 2026
Mint Forms is a Shopify app made by Mint Labs ("we", "us"). It lets a merchant put forms (contact, registration, quote requests and others) on their Shopify store, collects what shoppers send through those forms, shows it to the merchant, and emails the merchant about new submissions. This policy explains what the app handles about merchants and about the merchant's shoppers, why, and when it's deleted. For shopper data we act as a service provider (processor) to the merchant, who is the controller and decides what their forms ask.
The short version
- We store what shoppers type into the merchant's form (and files they attach, on the Pro plan) so the merchant can read and answer it.
- Submissions are deleted automatically after the period the merchant chooses (90 days unless they change it; anywhere from 1 to 730 days), and everything is deleted when the merchant uninstalls.
- Only the merchant, signed in to their Shopify admin, can see submissions and download files. We never sell or share them, use them for advertising or AI training, or combine them across stores.
- No cookies, no browser storage and no tracking on the storefront. We don't store IP addresses.
Information about merchants
| Information | Why |
|---|---|
| Store domain and a Shopify access token | To publish the merchant's forms to their storefront and, if they turn it on, create or update customers from submissions. |
| Store name, store email, contact email, primary domain and time zone | The contact email receives new-submission emails unless the merchant chooses other recipients; the store email receives test emails; the store name is the sender name; the time zone formats dates in emails and exports. |
| Forms and settings (fields, texts, notification recipients, retention period) | To show the forms and handle submissions the way the merchant set them up. |
| Plan and subscription status | Read from Shopify to decide which features apply. Payments are handled entirely by Shopify. |
Information about the merchant's shoppers
| Information | How it's used | Kept |
|---|---|---|
| The answers a shopper sends, exactly as typed — whatever the merchant's form asks, typically a name, email address, phone number and a message — plus the form's name, the date and the store page it was sent from | Shown to the merchant in the app's inbox, included in the merchant's notification email (unless they turn that off) and in their CSV exports. | The merchant's retention period (default 90 days), or until the merchant deletes it |
| Files a shopper attaches (Pro plan: images and PDFs up to 10 MB) | Stored privately; only the merchant can download them from their admin. Files attached but never sent with a form are deleted after 2 hours. | With their submission |
| An index of the email addresses and the last 9 digits of phone numbers in each submission | So that a privacy request from the shopper (access or erasure) finds every one of their submissions. | With their submission |
| The customer ID Shopify passes when the shopper is logged in to the store | To find their submissions for privacy requests, and so a logged-in customer can update their own details (Pro customer action). | With their submission |
| Marketing consent: whether the shopper ticked the merchant's consent checkbox (never ticked in advance) and its exact wording | Shown to the merchant. If the merchant turns on "create or update a Shopify customer" (Pro), a ticked box sets email marketing consent (single opt-in) on that customer in the merchant's store; an unticked box never changes it. | With their submission; in Shopify under the merchant's control |
| Customer records (Pro, only if the merchant turns it on) | The shopper's email and the answers the merchant maps (name, phone, note, metafields) are written to the merchant's Shopify customers, with the merchant's tags. We don't keep a separate copy. | In the merchant's store |
| Rate-limit keys: a keyed one-way hash of the shopper's IP address and a counter | To stop automated or repeated submissions. The IP address itself is never stored. | Minutes; deleted within a day |
Emails we send
We only email the merchant: a notification for each new submission (if the form has notifications on) and test emails the merchant asks for. They are sent through Cloudflare Email Service from our sending domain (mail.stickermint.com) with the store's name as the sender; the shopper's email address, if the form asked for one, is the reply-to address so the merchant can answer directly. We don't keep copies of sent emails. We never email shoppers.
Customer privacy requests
- Access requests (Shopify's
customers/data_request): the app home shows the request and the merchant downloads every submission we hold for that shopper as a file to send them. - Erasure requests (
customers/redact): we permanently delete every submission of that shopper at that store — matched by email address, phone number or customer ID, including submissions where their email appears in an answer — and the files attached to them. - Store deletion (
shop/redact, sent 48 hours after a merchant uninstalls): we permanently delete everything we hold for the store, files included. If that request never arrives, we delete it all 30 days after uninstall anyway.
Where data is processed and how it's protected
The app runs on Cloudflare (hosting, database in North America, file storage and email sending) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Storefront requests are signed by Shopify and checked before anything is stored. Access is limited to Mint Labs staff who need it to run the service; the app itself has no screen that shows us shoppers' submissions. We use no other sub-processors, analytics or trackers. See our security policy.
Retention
Submissions and their files are deleted automatically once they are older than the merchant's retention period (checked every 10 minutes), or earlier when the merchant deletes them. Access tokens are deleted as soon as the app is uninstalled, and everything else 48 hours later when Shopify asks us to delete the store's data (at the latest 30 days after uninstall). Short-lived server logs kept by Cloudflare don't contain what shoppers typed.
Your rights
Depending on where you are, you may have the right to access, correct or delete information about you. Shoppers should contact the store whose form they used; merchants can delete any submission in the app. You can also email us and we'll pass the request to the store. We respond within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com