Privacy policy

Last updated: 21 July 2026

Data we process

QuickAttach processes the Shopify order and customer data required to attach files to an order, send transactional download emails, record delivery activity, and update fulfillment status. This may include order identifiers, purchased line items, customer name, and customer email address.

How data is used

Data is used only to provide the service, deliver merchant-supplied attachments, prevent abuse, maintain security, and support merchants. QuickAttach does not sell personal data or use it for advertising or unrelated profiling.

Storage and retention

Production metadata is stored in PostgreSQL and attachments are stored in private Cloudflare R2 object storage. Data is encrypted in transit and protected at rest by the infrastructure providers. Attachments and related delivery data are retained for up to 365 days unless a deletion request requires earlier removal. Encrypted state backups are retained for up to 30 days.

Service providers

QuickAttach uses Shopify, Railway, Cloudflare R2, and Resend to provide authentication, hosting, storage, and transactional email. Each provider receives only the information needed to perform its service.

Merchant and customer rights

QuickAttach supports Shopify's mandatory privacy webhooks for customer data requests, customer deletion requests, and shop deletion requests. Merchants may also request access, correction, or deletion by contacting us.

Security

We use private storage, least-privilege credentials, per-shop data boundaries, encrypted backups, and restore procedures. No internet service can guarantee absolute security, but we maintain controls appropriate to the data processed.

Contact

Email support@getquickattach.com or call +61 481 436 002 for privacy questions.