Appearance
Data, privacy and GDPR
Your workspace holds personal data about your customers, and you are the controller of it. This page covers what the product does so you can answer a request without guessing.
What a customer can do themselves
The portal has a Privacy page:

| Action | What happens |
|---|---|
| Export my data | Downloads a JSON archive of their data, immediately |
| Request deletion | Queues a deletion request for you to review |
Deletion is a request rather than an instant wipe on purpose: financial records have statutory retention periods, and a customer cannot delete an invoice you are legally required to keep.
How deletion actually works
Deletion is anonymisation, not hard deletion:
| Data | Treatment |
|---|---|
| Names, emails, phone numbers | Scrubbed. Contacts and portal users get placeholder values such as deleted-123@anon.invalid |
| Passwords and sessions | Cleared, so the login no longer works |
| The organisation's assets | Removed from disk, including derived previews. Tenant-wide product and store imagery is untouched |
| Orders, invoices, payments | Retained, with personal identifiers scrubbed |
| The anonymisation itself | Logged in the audit log |
The commercial ledger stays intact while the personal identifiers go. In Australia financial records are retained 7 years; most jurisdictions have a comparable requirement. This approach satisfies an erasure request without breaching a retention obligation, and it is what you should tell a customer who asks.
Marketing consent
| Channel | Mechanism |
|---|---|
| One-click unsubscribe on every marketing email, through a signed link. Unsubscribed contacts are excluded automatically | |
| SMS | Inbound STOP and START are handled automatically. An opted-out contact is excluded |
Transactional messages about a job the customer has ordered are separate from marketing. Do not use a broadcast to send something that should be a transactional notification, or an unsubscribe will stop the customer hearing that their order shipped.
Isolation between shops
Every record belongs to exactly one workspace, and isolation is enforced at the data layer rather than by hiding buttons. A request for another workspace's record 404s. That includes Demi, which is scoped to your workspace and cannot see anyone else's data.
Portal customer isolation
A portal user belongs to one organisation and can only see that organisation's orders, artwork, invoices, designs and messages. Asking for another organisation's invoice by id returns a 404.
Search engines
Private surfaces, the portal, workspace, admin, cart and checkout, send an X-Robots-Tag: noindex header. Note this is done with a header rather than a robots.txt disallow, deliberately: a disallowed URL is never fetched, so a crawler would never see the header.
Your own exports
| Want | Do |
|---|---|
| One customer's history | Export activity (CSV) on their customer record |
| Invoices | Download PDFs from invoices |
| Report data | CSV export from reports |
| Everything, programmatically | The REST API, on Premium and above |
What to have written down
If you handle EU, UK, Australian or Californian personal data, you should be able to state: what you collect, why, how long you keep it, who you share it with, and how someone exercises their rights. The product gives you the mechanics; the policy is yours. A data processing agreement covering Printer's Friend as your processor is available from support.