appcessorise.

Privacy Policy

Last updated 18 September 2026

This policy explains what personal data we collect when you use Appcessorise, why we hold it, and what you can ask us to do with it. We do not sell personal data.

What we collect

  • Account details: your email address and password (stored only as a hash). If you sign in with Google we receive your email address and a Google account identifier, not your password.
  • Developer data: your API key, and logs of requests made with it, including timestamps and error details.
  • Order details: the customer's name, email address, delivery address and phone number where given, plus the order contents and status.
  • Artwork: the image used for a product, and the generated mockup, stored as links to the image files.
  • Payment data: handled by Stripe. We receive a payment reference and the result, never full card numbers.
  • Contact form: the name, email, phone, company and message you send us.
  • Technical data: server logs including IP address and browser type, kept for security and debugging.

Why we use it

  • To take payment, produce and deliver orders, and provide support — this is necessary to perform our contract with you.
  • To calculate and pay developer commissions.
  • To keep the service secure, detect fraud and abuse, and enforce limits — our legitimate interest in running a safe service.
  • To meet tax, accounting and other legal obligations.
  • To send service emails about your orders and account. Marketing email, if we ever send it, needs your consent and can be withdrawn at any time.

Who we share it with

We use these providers, who process data on our behalf:

  • Stripe — payment processing and fraud checks.
  • Printful — printing and shipping. They receive the delivery address and the artwork for the ordered item.
  • Resend — sending transactional email.
  • Google — optional sign-in, if you use it.
  • Hetzner — hosting the application and database.

Some of these are based outside the UK and EEA, so data may be transferred internationally under the safeguards those providers offer, such as standard contractual clauses. We also disclose data where the law requires it.

How long we keep it

  • Account data: while your account is open, then deleted or anonymised within a reasonable period after closure.
  • Order and transaction records: kept as long as tax and accounting rules require.
  • Mockups that are never bought: deleted automatically after they expire.
  • Server logs: a short rolling window for security and debugging.

Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, ask for it in a portable format, and withdraw any consent you gave. Contact us and we will respond within the period the law allows. You can also complain to your data protection regulator; in the UK that is the ICO.

Cookies

We use a small number of strictly necessary cookies: a session cookie to keep you signed in, a "remember me" cookie if you choose it, and a security token that protects forms against cross-site request forgery. Stripe may set cookies during checkout for fraud prevention. We do not use advertising cookies, and we do not track you across other websites. Blocking essential cookies will stop sign-in and checkout working.

Children

The service is not intended for children, and accounts require you to be 18 or older.

Changes

If we change this policy we will update the date above, and tell account holders by email if the change is significant.

Contact

Questions about this page? Get in touch.