Privacy Policy
Last updated 11 August 2026 · Version 1.2
This is the privacy notice for the Dock app (formerly Soloflo Hub), presented to Shopify merchants who install it and, through them, to the end customers whose order data passes through the app.
1. Who we are
Dock ("the platform") is operated by AGA Print Ltd, trading as Solopress ("we", "us"), a company registered in England & Wales, company number 04717223, with registered address 9 Stock Road, Southend-on-Sea, Essex, SS2 5QF, United Kingdom.
For the purposes of UK GDPR / EU GDPR:
- Controller (when end customers interact directly with our own services): us.
- Processor (when we process personal data on behalf of a Shopify merchant using our app): us, acting on the merchant's instructions. The merchant is the controller.
For data-protection questions, contact: dpo@solopress.com.
2. What personal data we process
From Shopify merchants (the stores that install our app)
- Shop domain (*.myshopify.com) and store name
- Merchant account email and name (received via Shopify OAuth)
- App configuration (our API keys, tenant binding)
- OAuth session tokens
From end customers (the people buying print products via the merchant's store)
For every order placed through our Shopify app:
- Recipient name (first + last)
- Shipping address (company name if supplied, address lines, city, postcode, country)
- Line-item configuration (product choices, artwork references) — not personal data itself, but linked to the order
- Order reference (merchant's own Shopify order number + our internal reference)
From people who contact us (before they are customers)
If you ask us for a demo or send us an enquiry — through the form on mydock.io or by email:
- Your name and email address
- Your store address and which sales channel you use, if you tell us
- Anything you write in your message
What we do not collect
- Credit card or payment instrument data (handled by Shopify / the merchant's payment processor — we never see it)
- Customer email or phone number (we have explicitly not requested these scopes)
- Browsing or tracking cookies on the merchant's storefront
- Any data about the end customer beyond what appears on the order
3. Why we process it (purpose)
We process merchant and end-customer data for one purpose only: to fulfil the printed goods ordered via the merchant's Shopify store.
- Receive the order from the merchant's Shopify store via a Shopify webhook.
- Translate the order into a production job and submit it to Solopress (our parent print manufacturer).
- Pass production status updates (in production / dispatched / tracking number) back to the merchant so their customer can be notified.
Enquiries are a separate and narrower purpose. If you contact us, we use what you send to reply and — if you go ahead — to set your account up. Our lawful basis is legitimate interests: answering a business enquiry you started. We do not add you to a marketing list, and there is no tracking on the form.
We do not:
- Sell or share the data with third parties beyond what is described in Section 4.
- Use the data for profiling, targeted advertising, or analytics.
- Use the data to train AI models.
4. Who we share data with
| Recipient | What we share | Why |
|---|---|---|
| Solopress (print production) | Recipient name + shipping address + line-item configuration | To produce and dispatch the physical print order |
| DigitalOcean (infrastructure — EU region) | All data above, as part of normal application hosting | Application hosting + object storage + database |
| Resend (transactional email, optional) | Merchant email + tenant-level notifications; demo and enquiry messages you send us | Sending merchant-facing operational emails and delivering your enquiry to our team — never end-customer emails |
No data is sold. No data is shared for advertising. No data is transferred outside the UK/EEA in normal operation.
5. How long we keep it
| Data | Retention | Reason |
|---|---|---|
| Order records (incl. recipient name + address) | 7 years after fulfilment | UK statutory tax / commercial records retention (Companies Act 2006, s386) |
| OAuth session tokens | Lifetime of the Shopify app installation | Required to call Shopify on the merchant's behalf |
| Merchant account data | Lifetime of the installation + 30 days after uninstall | Uninstall grace period for re-installs |
| Support / audit logs | 24 months rolling | Operational diagnosis + security forensics |
| Demo requests and other enquiries | 12 months after our last contact — or, if you become a merchant, the merchant account row above applies instead | Long enough to pick an open enquiry back up; enquiries that go nowhere are deleted |
On merchant uninstall or explicit deletion request, we respond to Shopify's mandatory GDPR webhooks (shop/redact, customers/redact, customers/data_request) within the required window.
6. Your rights (UK GDPR / EU GDPR)
If you are an end customer whose order passed through Dock, your primary point of contact is the merchant you ordered from — they are the data controller. They can ask us (as their processor) to act on your behalf.
You have the right to:
- Access the personal data we hold about you
- Ask for correction of inaccurate data
- Ask for erasure ("right to be forgotten"), subject to the 7-year tax retention above
- Restrict processing
- Object to processing
- Data portability
- Complain to the UK Information Commissioner's Office (ico.org.uk)
To exercise any of these, contact the merchant you ordered from, or contact us directly at dpo@solopress.com.
7. Security
We protect personal data using:
- HTTPS / TLS encryption for all data in transit
- Encryption at rest on all database volumes (Postgres) and object storage (DigitalOcean Spaces)
- Role-based access control for our internal admin tools
- Multi-factor authentication on all cloud infrastructure accounts (DigitalOcean, GitHub, Coolify)
- Strong password hashing (scrypt) on application admin accounts
- Two-factor authentication implemented for all elevated roles (SuperAdmin, tenant Owner, tenant Admin), with mandatory enforcement being rolled out
- Audit trails on order data access
8. Cookies
The Dock admin dashboard (used by merchants) uses a single session cookie for authentication. No third-party tracking cookies are set by our app on the merchant's storefront via the widget.
9. Changes to this policy
We may update this policy as the app evolves. Material changes will be notified to active merchants via email. The "Last updated" date above reflects the current version.
10. Contact
| Role | Contact |
|---|---|
| General privacy queries | dpo@solopress.com |
| Data Protection Officer | dpo@solopress.com (Liam Cleere) |
| Postal | AGA Print Ltd (trading as Solopress), 9 Stock Road, Southend-on-Sea, Essex, SS2 5QF, United Kingdom |