Privacy policy
RunSheet · last updated 29 July 2026
RunSheet is a production dashboard for Shopify merchants who make customized products. It reads the orders on your store so the people at your bench can see what to make. This page describes exactly what it holds and what it does not.
What RunSheet processes
- Order line items — product title, variant title, quantity, order reference and order date, and the custom properties attached to the line at checkout.
- Product data — product title, product type and the featured product image, used to identify items on screen and on the printed sheet.
- Staff identity — the Shopify user ID of each staff member who opens the app, and a display name they set themselves. This is what lets a merchant see who moved a job forward.
- Production data RunSheet creates itself — production statuses, batches, and a history of status changes. None of this comes from Shopify and none of it is written back to Shopify.
What RunSheet does not process
- No customer personal data. RunSheet does not request, receive or store customer names, email addresses, phone numbers, shipping addresses or billing addresses. It holds no customer records at all — there is no customer table in its database.
- No payment information of any kind.
- No write access to your store. RunSheet requests read-only
Shopify permissions (
read_orders,read_products). It cannot change, fulfil or cancel anything in your Shopify admin.
A note about customization text
Custom line-item properties are free text typed by your shopper at checkout — engraving text, a gift note, a monogram. RunSheet cannot know in advance what is in them, and a shopper may put a personal name in one ("Happy 40th, Sarah"). RunSheet therefore treats every property value as sensitive: values are never written to application logs or error reports, and they are deleted with the rest of your store's data as described below.
Who can see it
Only you and your own staff. RunSheet is reached through your Shopify admin, so access is controlled by Shopify's own staff permissions — anyone with a staff account on your store who can open the app can see the production data in it, and nobody else can. Every record is scoped to the store that owns it, and one merchant's data is never visible to another.
RunSheet's operators can access the database for support and maintenance. That access is used to keep the service running and to answer requests you make, not to read your orders.
How it is stored
Data is held in a Postgres database hosted in Sydney, Australia, and the application runs in the same region. Every record is scoped to the store it belongs to, and the access token RunSheet uses to read your store is encrypted before it is stored.
How long it is kept
For as long as RunSheet is installed on your store. There is no separate archive and no backup that outlives the account.
Deletion
When you uninstall RunSheet, Shopify sends a shop/redact request
approximately 48 hours later. On receiving it, RunSheet deletes every row
belonging to your store — line items, properties, batches, statuses, status
history, staff records and stored credentials. Nothing is retained.
You can also request deletion at any time, installed or not, by emailing support@runsheetapp.app from an address on the store's account. Requests are actioned within 30 days.
Sharing
RunSheet does not sell data and does not share it with third parties for advertising or analytics. The only processors involved are the hosting and database providers that run the service itself.
Contact
Questions about this policy, or any request concerning your data: support@runsheetapp.app.