Dock

Privacy Policy

Last updated 11 August 2026 · Version 1.2

This is the privacy notice for the Dock app (formerly Soloflo Hub), presented to Shopify merchants who install it and, through them, to the end customers whose order data passes through the app.

1. Who we are

Dock ("the platform") is operated by AGA Print Ltd, trading as Solopress ("we", "us"), a company registered in England & Wales, company number 04717223, with registered address 9 Stock Road, Southend-on-Sea, Essex, SS2 5QF, United Kingdom.

For the purposes of UK GDPR / EU GDPR:

  • Controller (when end customers interact directly with our own services): us.
  • Processor (when we process personal data on behalf of a Shopify merchant using our app): us, acting on the merchant's instructions. The merchant is the controller.

For data-protection questions, contact: dpo@solopress.com.

2. What personal data we process

From Shopify merchants (the stores that install our app)

  • Shop domain (*.myshopify.com) and store name
  • Merchant account email and name (received via Shopify OAuth)
  • App configuration (our API keys, tenant binding)
  • OAuth session tokens

From end customers (the people buying print products via the merchant's store)

For every order placed through our Shopify app:

  • Recipient name (first + last)
  • Shipping address (company name if supplied, address lines, city, postcode, country)
  • Line-item configuration (product choices, artwork references) — not personal data itself, but linked to the order
  • Order reference (merchant's own Shopify order number + our internal reference)

From people who contact us (before they are customers)

If you ask us for a demo or send us an enquiry — through the form on mydock.io or by email:

  • Your name and email address
  • Your store address and which sales channel you use, if you tell us
  • Anything you write in your message

What we do not collect

  • Credit card or payment instrument data (handled by Shopify / the merchant's payment processor — we never see it)
  • Customer email or phone number (we have explicitly not requested these scopes)
  • Browsing or tracking cookies on the merchant's storefront
  • Any data about the end customer beyond what appears on the order

3. Why we process it (purpose)

We process merchant and end-customer data for one purpose only: to fulfil the printed goods ordered via the merchant's Shopify store.

  1. Receive the order from the merchant's Shopify store via a Shopify webhook.
  2. Translate the order into a production job and submit it to Solopress (our parent print manufacturer).
  3. Pass production status updates (in production / dispatched / tracking number) back to the merchant so their customer can be notified.

Enquiries are a separate and narrower purpose. If you contact us, we use what you send to reply and — if you go ahead — to set your account up. Our lawful basis is legitimate interests: answering a business enquiry you started. We do not add you to a marketing list, and there is no tracking on the form.

We do not:

  • Sell or share the data with third parties beyond what is described in Section 4.
  • Use the data for profiling, targeted advertising, or analytics.
  • Use the data to train AI models.

4. Who we share data with

RecipientWhat we shareWhy
Solopress (print production)Recipient name + shipping address + line-item configurationTo produce and dispatch the physical print order
DigitalOcean (infrastructure — EU region)All data above, as part of normal application hostingApplication hosting + object storage + database
Resend (transactional email, optional)Merchant email + tenant-level notifications; demo and enquiry messages you send usSending merchant-facing operational emails and delivering your enquiry to our team — never end-customer emails

No data is sold. No data is shared for advertising. No data is transferred outside the UK/EEA in normal operation.

5. How long we keep it

DataRetentionReason
Order records (incl. recipient name + address)7 years after fulfilmentUK statutory tax / commercial records retention (Companies Act 2006, s386)
OAuth session tokensLifetime of the Shopify app installationRequired to call Shopify on the merchant's behalf
Merchant account dataLifetime of the installation + 30 days after uninstallUninstall grace period for re-installs
Support / audit logs24 months rollingOperational diagnosis + security forensics
Demo requests and other enquiries12 months after our last contact — or, if you become a merchant, the merchant account row above applies insteadLong enough to pick an open enquiry back up; enquiries that go nowhere are deleted

On merchant uninstall or explicit deletion request, we respond to Shopify's mandatory GDPR webhooks (shop/redact, customers/redact, customers/data_request) within the required window.

6. Your rights (UK GDPR / EU GDPR)

If you are an end customer whose order passed through Dock, your primary point of contact is the merchant you ordered from — they are the data controller. They can ask us (as their processor) to act on your behalf.

You have the right to:

  • Access the personal data we hold about you
  • Ask for correction of inaccurate data
  • Ask for erasure ("right to be forgotten"), subject to the 7-year tax retention above
  • Restrict processing
  • Object to processing
  • Data portability
  • Complain to the UK Information Commissioner's Office (ico.org.uk)

To exercise any of these, contact the merchant you ordered from, or contact us directly at dpo@solopress.com.

7. Security

We protect personal data using:

  • HTTPS / TLS encryption for all data in transit
  • Encryption at rest on all database volumes (Postgres) and object storage (DigitalOcean Spaces)
  • Role-based access control for our internal admin tools
  • Multi-factor authentication on all cloud infrastructure accounts (DigitalOcean, GitHub, Coolify)
  • Strong password hashing (scrypt) on application admin accounts
  • Two-factor authentication implemented for all elevated roles (SuperAdmin, tenant Owner, tenant Admin), with mandatory enforcement being rolled out
  • Audit trails on order data access

8. Cookies

The Dock admin dashboard (used by merchants) uses a single session cookie for authentication. No third-party tracking cookies are set by our app on the merchant's storefront via the widget.

9. Changes to this policy

We may update this policy as the app evolves. Material changes will be notified to active merchants via email. The "Last updated" date above reflects the current version.

10. Contact

RoleContact
General privacy queriesdpo@solopress.com
Data Protection Officerdpo@solopress.com (Liam Cleere)
PostalAGA Print Ltd (trading as Solopress), 9 Stock Road, Southend-on-Sea, Essex, SS2 5QF, United Kingdom