Skip to content

FAQ: Privacy and Data ​

The privacy policy, the data processing addendum and the security overview on printersfriend.com are the binding documents. This page answers the questions shops ask most, with the guide for each under Data, privacy and GDPR. Email hello@printersfriend.com for anything else.

Ownership and Location ​

Who owns my data? ​

You do. Everything you put into Printer's Friend stays yours, and Printer's Friend holds a licence to process it only to provide the service. Where you load personal data about your own customers, you are the controller and Printer's Friend is the processor under the DPA.

Where is it stored? ​

The platform, its database and its backups run at Hetzner Online GmbH in Helsinki, Finland. Transactional email leaves through Amazon SES in the United States (us-east-1) unless you connect your own email provider.

Who else processes it? ​

The smallest set the platform can run on:

SubprocessorWhereWhat forWhen
Hetzner Online GmbHHelsinki, FinlandHosting, database and backup storageAlways
Amazon Web Services (SES)us-east-1, United StatesTransactional emailAlways, unless you connect your own sender
StripeUnited States and IrelandYour subscription, and customer payments when you connect StripeAlways for the subscription
TwilioUnited StatesSMSOnly when you connect your own Twilio account
AnthropicUnited StatesAnswers for Demi; workspace data is passed as context for the query and is not used for trainingOnly when the assistant is enabled
Umami, self-hostedHelsinki, FinlandPage view analytics for the marketing siteOnly after you accept analytics in the cookie banner

Providers you connect yourself (your email service, Twilio, Stripe, your accounting ledger) are your own processors under your own agreements with them.

Can Printer's Friend staff see my data? ​

Support can access a workspace to resolve a ticket. Opening the billing portal and other sensitive actions are written to the audit log in your workspace.

Keeping and Deleting ​

How long is my data kept? ​

For as long as the account is active. After a cancellation the workspace stays open and read-only for 30 days, then every record is permanently deleted apart from tax records, which the law requires us to keep for 7 years. A failed payment never deletes anything. See Cancelling and the 30 day window.

How are backups taken? ​

Nightly, encrypted, stored in the same Hetzner data centre, and kept as daily copies for 16 days, then weekly, monthly and yearly copies. A deleted workspace drops out of the backups as they age through that schedule.

Can I get everything out? ​

Customer activity exports as CSV from each customer record with Export activity (CSV). On Premium and above the REST API reads customers, orders and inventory. A full export of the workspace is available on request from hello@printersfriend.com.

Your Customers' Data ​

How does a customer get their own data or ask for deletion? ​

From the portal's privacy page. Download my data gives them a JSON file covering only themselves: their contact details and the quotes, orders, invoices and messages they are party to. Request deletion notifies the shop owner and the platform's privacy address, and tells the customer the shop will confirm the date of erasure within 30 days.

The portal privacy page with the export and deletion request optionsData and privacy in the customer portal.

How do I answer a deletion request? ​

Open the customer record and use Anonymise portal user. It scrubs the person's identifying details, ends their portal login and keeps the financial records that retention law requires. See Answering a deletion request.

Can I email every contact I have? ​

Only contacts with a recorded marketing consent receive broadcasts. Consent is recorded on the contact with its source (for example a customer import with a consent column), and every broadcast carries a one click unsubscribe link and the List-Unsubscribe header. Transactional messages such as proofs and invoices are not affected.

What stops a customer seeing another customer's orders? ​

Every record belongs to one shop and, in the portal, to one organisation. A request for another organisation's record answers 404. In the workspace, every request is scoped to your shop.

Security ​

How are accounts protected? ​

Passwords are at least 12 characters. Owners and managers sign in with an authenticator app and recovery codes. API tokens expire after 365 days and show their expiry. Password reset links are valid for one workspace only. Credentials you connect under Integrations are encrypted in the database.

What does Demi send to Anthropic? ​

The data needed to answer the question, as context for that query. It is not used for training, and nothing is sent while the assistant is not enabled.

Where do I report a security problem? ​

hello@printersfriend.com. The security overview describes the responsible disclosure programme.

Printer's Friend - software for apparel print shops