Privacy Policy

Last updated: March 2026

1. Introduction

Welcome to BrandLift. BrandLift ("we", "our", or "us") operates the Live Designer application available through the Shopify App Store, the website at livedesigner.ai, and related services including Kodiak Print on Demand fulfillment (collectively, the "Service").

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By installing our app or using our Service, you agree to the collection and use of information in accordance with this policy.

BrandLift is operated by Kodiak Decorated Products, located in Green Bay, Wisconsin, United States.

2. Definitions

  • Service means the BrandLift Live Designer application, the livedesigner.ai website, Kodiak Print on Demand fulfillment services, and all related tools and integrations.
  • Personal Data means data about a living individual who can be identified from that data or from that data combined with other information.
  • Usage Data means data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
  • Merchant refers to a Shopify store owner who installs and uses BrandLift Live Designer.
  • End Customer refers to a customer of a Merchant who interacts with BrandLift through the Merchant's storefront.
  • Kodiak POD refers to our first-party print-on-demand fulfillment service operated by Kodiak Decorated Products.

3. Information We Collect

3.1 Merchant Account Information

When you install our app, we collect information about your Shopify store through the Shopify API with your authorization, including: store name and domain, owner name and email address, business name and address, phone number, locale and timezone, and store configuration settings necessary to provide our services.

When you set up billing for Kodiak POD fulfillment, we also collect: business address, notification email preferences, and timezone preferences. Payment card information is collected and stored exclusively by Stripe, our payment processor — we never store, process, or have access to full card numbers, CVV codes, or complete expiration dates.

3.2 Product Data

We access and process product information to enable customization and fulfillment features, including: product titles, descriptions, images, variants, pricing, inventory status, and print area configurations. This data is used to power the design and customization experience and to facilitate order fulfillment.

3.3 Order Data

We process order information to generate print-ready files and facilitate fulfillment, including: customer customization choices and design data, order line items and quantities, shipping addresses (when using fulfillment integrations), order status and tracking information, and payment status for Kodiak POD orders.

3.4 End Customer Data

When end customers use BrandLift Live Designer on a Merchant's storefront, we may process:

  • Images uploaded for product customization
  • Design choices and customization selections (text, fonts, colors, layout)
  • Device and browser information for rendering purposes
  • Shipping addresses when orders are fulfilled through our fulfillment services

We do not sell or share end customer personal information with third parties for marketing purposes. End customer design data is processed solely for order fulfillment and is associated with the Merchant's account.

3.5 Payment Information

For Kodiak POD fulfillment charges, payment processing is handled by Stripe, Inc. We store only: Stripe Customer IDs (tokenized identifiers), Payment Method IDs (tokenized identifiers), the last four digits of payment cards (for display purposes only), card brand and expiration month/year (for display purposes only), and transaction amounts, dates, and status.

We never store, transmit, or process full card numbers, CVV/CVC codes, or any data that would increase our PCI compliance scope. All payment card data is handled exclusively by Stripe in compliance with PCI DSS Level 1 standards.

3.6 Usage Data

We collect information that your browser sends when you visit our Service, including: IP address, browser type and version, pages visited and time spent, unique device identifiers, referring URLs, and diagnostic data.

3.7 Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

  • Strictly Necessary Cookies: Required for authentication, session management, and basic Service functionality.
  • Functional Cookies: Remember your preferences and design settings for a personalized experience.
  • Analytics Cookies: Help us understand how visitors interact with the Service by collecting anonymized usage data.

You can instruct your browser to refuse all cookies, but some portions of our Service may not function properly without them.

4. How We Use Your Information

We use collected data to:

  • Provide and maintain product customization and fulfillment services
  • Generate print-ready files for orders
  • Process and fulfill orders through Kodiak POD and third-party print-on-demand integrations
  • Calculate and process fulfillment charges via Stripe
  • Send transactional notifications related to orders and billing (payment confirmations, failed payment alerts, shipping updates)
  • Communicate with you about your account and provide support
  • Improve our Service through aggregated and anonymized analytics
  • Monitor for and address technical issues and security threats
  • Comply with legal obligations

5. Data Sharing and Disclosure

We share your information only in the following circumstances:

  • Payment Processing (Stripe): When you use Kodiak POD, payment information is processed by Stripe, Inc. We share merchant name, email, phone, address, and tokenized payment method identifiers with Stripe for the purpose of processing fulfillment charges. Stripe's privacy policy is available at stripe.com/privacy.
  • Email Notifications (Amazon Web Services): We use Amazon Simple Email Service (SES) to send transactional emails related to billing and order status. We share only the recipient email address and the content of the notification with AWS for email delivery. AWS's privacy policy is available at aws.amazon.com/privacy.
  • Fulfillment Partners: When you use third-party fulfillment integrations (such as Printify or Printful), order details, design files, and shipping addresses are shared with the selected fulfillment provider to process and ship orders. We share only the data necessary for fulfillment.
  • Shopify: As a Shopify app, we interact with Shopify's platform APIs to create and manage products, process orders, and handle subscription billing. Shopify's privacy policy is available at shopify.com/legal/privacy.
  • Email Marketing (Klaviyo): If a Merchant connects their Klaviyo account, we may share store and customer engagement data with Klaviyo for the Merchant's email marketing purposes. This integration is optional and controlled by the Merchant.
  • Legal Requirements: We may disclose your Personal Data if required by law or in response to valid requests by public authorities.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before such a transfer.

We do not sell your Personal Data to third parties. We do not share your Personal Data with advertisers or ad networks.

6. Data Security

We implement appropriate technical and organizational measures to protect your Personal Data, including:

  • Encryption of all data in transit using TLS 1.2 or higher
  • Secure authentication via Shopify OAuth and JWT session tokens
  • Role-based access control (merchant, administrator, staff roles)
  • Webhook signature verification for Stripe and Shopify integrations
  • PCI DSS compliance through Stripe's SAQ-A integration model (no cardholder data on our servers)
  • Rate limiting on API endpoints to prevent abuse
  • Idempotency controls on financial transactions to prevent duplicate charges
  • Regular monitoring and security assessments

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

7. Data Retention

We retain your Personal Data only as long as necessary:

  • Account Data: Retained while your account is active and for 30 days following app uninstallation or account cancellation.
  • Customer-Uploaded Images: Processed for order fulfillment and retained for the duration of the Merchant's subscription to support reorder functionality.
  • Order and Design Data: Retained for the duration of your subscription. Anonymized order data may be retained for analytics.
  • Payment Transaction Records: Retained for 7 years to comply with financial record-keeping requirements and tax obligations.
  • Usage Data: Aggregated and anonymized for analytics. Raw usage data is retained for no more than 12 months.

Upon app uninstallation, we process Shopify's mandatory shop/redact webhook and delete all store-specific data within 48 hours, except where retention is required by law or for legitimate business purposes (such as financial records).

You may request deletion of your data at any time by contacting us.

8. Shopify Data Handling

As a Shopify app, we comply with Shopify's data protection requirements:

  • Customer Data Requests: When we receive a customers/data_request webhook from Shopify, we respond within 48 hours with a summary of the customer data we store.
  • Customer Data Deletion: When we receive a customers/redact webhook, we delete all personal data associated with the specified customer, including saved designs and order customization data. Anonymized order records may be retained for Merchant accounting purposes.
  • Shop Data Deletion: When we receive a shop/redact webhook (48 hours after app uninstallation), we delete all data associated with the store.

9. International Data Transfers

Your information may be transferred to and processed on servers located in the United States. If you are located outside the United States, your data will be transferred across international borders. By using our Service, you consent to this transfer. We take reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

10. Your Privacy Rights

For EU/EEA Residents (GDPR)

If you are a resident of the European Union or European Economic Area, you have the right to:

  • Access – Request copies of your Personal Data
  • Rectification – Request correction of inaccurate or incomplete data
  • Erasure – Request deletion of your Personal Data
  • Restriction – Request restriction of processing of your Personal Data
  • Data Portability – Request transfer of your data in a structured, machine-readable format
  • Objection – Object to our processing of your Personal Data
  • Withdraw Consent – Withdraw consent at any time where we relied on consent to process your data

Our legal basis for processing is performance of a contract (providing the Service you subscribed to) and legitimate interests (improving our Service, preventing fraud).

For California Residents (CCPA)

If you are a California resident, you have the right to: know what Personal Data we collect, request deletion of your data, and opt out of the sale of your data. We do not sell your Personal Data.

For All Users

You may exercise any of these rights by contacting us at privacy@livedesigner.ai. We will respond to your request within 30 days.

11. Children's Privacy

Our Service is not intended for use by anyone under the age of 18. We do not knowingly collect Personal Data from children under 13 (or under 16 in the EEA). If we become aware that we have collected data from a child, we will take steps to delete that information promptly.

12. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also notify you via email or through the app. Your continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights:

Privacy inquiries: privacy@livedesigner.ai

General support: support@livedesigner.ai

Mailing address: BrandLift / Kodiak Decorated Products, Green Bay, WI 54304, United States