Last updated: August 17, 2026
Privacy Policy
FormLift: File Upload Forms helps Shopify merchants create custom storefront forms with file upload fields. This Privacy Policy explains what data the app processes and how that data is used.
Information We Process
When a merchant installs or uses the app, we may process:
- Shop information, such as the shop domain and app installation data.
- Form settings created by the merchant, including field labels and styles.
- Uploaded file metadata, such as filename, file type, file size, and upload token.
- Files submitted through storefront forms when a merchant enables upload fields.
- Aggregated popup impression and submission counts used to show campaign performance.
The app does not sell personal information. Depending on the merchant's form settings, submission emails are sent through Shopify's contact form email system or Amazon Simple Email Service (SES). The app provides file links so merchants can access submitted uploads.
How We Use Information
We use information to:
- Authenticate the Shopify app installation.
- Render the merchant's selected form on the storefront.
- Upload, store, and provide download links for submitted files.
- Maintain app security, prevent abuse, and troubleshoot issues.
- Show merchants aggregated popup campaign performance.
- Provide merchant support when requested.
File Uploads and Download Links
Uploaded files are stored in a private storage bucket. Download links use random tokens and redirect to short-lived signed storage URLs. Anyone with a valid download link may be able to access the uploaded file, so merchants should treat these links as confidential.
Service Providers
We use third-party providers to operate the app, including Shopify for app platform services, Render for application hosting, a MongoDB database provider for application data, Amazon S3 for file storage, and Amazon SES for merchant-enabled email notifications. These providers process data as needed to deliver the app's functionality.
Data Retention
Uploaded files are assigned a retention date based on the merchant's app plan and are removed by an automated cleanup process after that date. Form and submission data is retained while the merchant uses the service, subject to legal and operational requirements. Merchants can request deletion of app data and uploaded files by contacting us.
Security
We use private storage, signed upload and download URLs, and access controls to help protect submitted files. No method of transmission or storage is completely secure, but we work to use reasonable safeguards.
Merchant and Customer Rights
Merchants and customers may request access, correction, or deletion of personal information where applicable. Customers should contact the merchant directly for questions about a specific storefront submission.
Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised last updated date.
Contact
For privacy questions or deletion requests, contact us at uzzamwebdev@gmail.com.