Privacy Policy
Stackhero is a Shopify app that invites a store's customers to send a short video of a product they bought, records their permission to use it in advertising, and rewards them for it. Doing that means handling personal data. This page explains exactly what we handle, why, where it lives, and how to get it deleted.
Who we are
Stackhero is operated by SPACE CADET d.o.o., a company registered in Croatia (MBS 081627179), Ulica Ivana Šibla 17, 10000 Zagreb, Croatia.
For anything in this policy, contact dino@spacecadet.site or hello@stackhero.app.
Our role, and the merchant's
When a merchant installs Stackhero, that merchant decides which of their customers get invited and what happens to the videos. For that customer data, the merchant is the data controller and Stackhero is a processor acting on their instructions.
For the merchant's own account — their shop, settings and billing — Stackhero is the controller.
What we collect
From the merchant's Shopify store
- Shop domain, shop name, contact email and store currency.
- An access token that lets the app call Shopify on the store's behalf.
- The settings the merchant chooses inside the app.
About orders, so we know who to invite
- Order number and Shopify order ID.
- Customer ID, email address and first name.
- Names and IDs of the products in the order.
- Order total, only to apply a minimum-order rule if one is set.
From customers who upload a video
- The video file itself.
- Their email address and first name, carried over from the order.
- Any optional caption they write.
- A record of their consent: the timestamp, the version of the wording they agreed to, and the IP address the upload came from. We keep this so the merchant can prove permission to advertise was actually given.
- Technical details of the video — length, width and height — used to crop it into advertising formats.
We do not collect payment card details, addresses, phone numbers, or browsing behaviour, and we do not use any of this data to train machine learning models.
Why we use it, and on what basis
- To run the service the merchant asked for — sending invitations, storing uploads, issuing rewards. Performance of a contract.
- To use a video in advertising — the customer's explicit consent, given by ticking the rights box before uploading. They can withdraw it at any time (see below).
- To keep the service working and secure — error logs and abuse prevention. Legitimate interests.
- To bill the merchant — handled by Shopify, not by us. Legal obligation and contract.
Where the data is stored
Customer videos and records are stored in the European Union. Our service providers are:
| Provider | What it handles | Location |
|---|---|---|
| Neon | Database — orders, settings, consent records | EU (Frankfurt) |
| Cloudflare R2 | Video storage | EU |
| Vercel | Application hosting | EU (Frankfurt), company based in the USA |
| Resend | Sending invitation and reward emails | USA |
| Shopify | The store platform and app billing | Global |
Transfers outside the EU rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
- Approved videos: kept until the merchant deletes them. The merchant holds an advertising licence to these, so we do not remove them automatically. A merchant can switch on automatic deletion after a chosen number of days.
- Rejected videos: deleted after 30 days by default.
- Cropped advertising versions: deleted after 30 days by default and re-created on demand.
- Abandoned uploads: files that never completed are deleted within about a day.
- Everything for a store: permanently deleted when Shopify sends us a shop deletion request, which happens after an app is uninstalled.
Your rights
If you are in the EU or UK you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how it is used, or withdraw consent for your video to be used in advertising.
Customers: contact the store you bought from first — they decide what happens to your video. You can also write to us directly and we will act on it and inform the store.
Requests that reach us through Shopify are handled automatically: a deletion request removes the person's video from storage and erases their records.
You may also complain to your local data protection authority. In Croatia this is AZOP (azop.hr).
Withdrawing video consent
Ticking the rights box before uploading is what allows a store to use a video in paid advertising. You can withdraw that permission at any time by contacting the store or us. Withdrawing stops future use — it cannot retroactively undo advertising that has already run.
Security
- Everything is transmitted over encrypted connections (HTTPS).
- Videos are stored privately. They are never publicly listed, and links to view or download them expire after a short period.
- Access tokens are held only for as long as the app is installed and are deleted when it is removed.
Children
Stackhero is not intended for children. When uploading, customers must confirm they are 18 or older, or have the consent of a parent or guardian.
Changes to this policy
If we change how we handle data we will update this page and the date at the top. Significant changes will be communicated to merchants inside the app.
Contact
SPACE CADET d.o.o.
Ulica Ivana Šibla 17, 10000 Zagreb, Croatia
dino@spacecadet.site