Privacy policy
Ranger Downloads is a Shopify app built and operated by Ioun Developers. It delivers digital files to the customers of the stores that install it. This policy explains what the app stores, why, who else sees it, and how long it lasts.
Merchants who install the app are our customers. Their buyers are not: we handle a small amount of buyer data on the merchant’s behalf, as a processor, so a buyer with a question should start with the store they ordered from.
What the app stores
- Order metadata. The Shopify order id, the order number, and the customer email address the order was placed with. Where Shopify’s order data includes a customer record, we also store that numeric customer id. This is what lets the app decide who a download belongs to and where to send it.
- Files and file metadata. The files a merchant uploads, along with names, sizes, content types, labels and version history. Files are stored in a private Cloudflare R2 bucket and are only ever served through short-lived signed URLs. Where an order contains several files, we also store a zip of that exact set of files, so the buyer can take the order in one go.
- The merchant’s email logo, if they upload one. Because an email cannot use a link that expires, this one image is served from a stable address rather than a signed URL.
- Download audit events. Each download attempt records a timestamp, the IP address it came from, the browser user agent string, and whether it was allowed. These exist to enforce download limits and to flag a link being used from an unusual number of addresses. Flags raised that way are stored until the merchant resolves them.
- Email send logs. A record of which delivery and update emails were sent, to which address, and whether the sending provider accepted them.
- Back-catalogue data, for merchants who use the historical import. Summarised from their own past orders: product titles, vendor, product type, a representative SKU, how many orders and how many buyers a product had, and when it first and last sold.
- Store configuration. The merchant’s own settings: email templates, limits, delivery policies, sending domain, file tags, and their current plan and Shopify subscription identifiers.
- Shopify session data, including the access token that lets the app call Shopify on the store’s behalf for as long as it is installed.
The app never receives or stores payment details. All payments and all billing for the app itself are handled by Shopify.
When a merchant writes to us through the feedback bubble inside the app, that message is emailed to our support address and is not stored in the app’s database.
Why it is stored
Every item above exists to run the delivery the merchant installed the app to do: match a paid order to files, email the buyer, authorise each click on a link, hold a link to its limits, bill the right plan, and tell the merchant what happened. None of it is sold, rented, or used for advertising or profiling, and none of it is used to train anything.
Who else sees it
The app runs on a small set of services, each of which sees only what it needs to:
- Shopify is the source of order and product data and handles authentication, payments and app billing. We also read the plan a store is on from Shopify’s partner-facing API.
- Cloudflare R2 stores the uploaded files. The bucket is private.
- Resend sends the delivery and update emails, and so processes the recipient address and the message body.
- Railway hosts the application and its Postgres database.
When a merchant sets up their own sending domain, the app also looks up that domain’s public nameservers so it can give instructions for the right DNS panel. That lookup involves no personal data.
How long it is kept
Data is kept for the life of the installation: a download link that has to keep working needs the record behind it to keep existing.
Uninstalling the app does not delete it immediately. We mark the store as uninstalled, delete its Shopify session, and put it back on the free plan, but the library and the buyers’ links are kept so that an accidental uninstall followed by a reinstall loses nothing. Shopify sends a shop redaction request about 48 hours after an uninstall, and that is what deletes for real: we delete the store’s files and zips from storage, then delete the store’s records, which removes its files, versions, product assignments, downloads, download events, flags, email logs, back-catalogue data and tag settings.
Shopify’s customer redaction request is handled too. The customer’s email address is replaced with a one-way token, and the IP address and user agent on their download events are erased. The download records themselves are kept, without anything identifying the buyer, because they are the merchant’s own record that an order was fulfilled and how many times a file was taken.
A customer data request is answered by emailing the merchant everything the app holds for that customer, so the merchant can pass it on. We send it to the merchant rather than to the buyer because we have no relationship with the buyer that would let us verify who is asking.
Merchant and customer rights
Merchants can see and change everything the app holds for their store from inside the app. Uninstalling starts the deletion described above.
Buyers should send access and erasure requests to the store they bought from. Shopify’s process routes those requests to us automatically, and the app answers them as described above. If you are a buyer and cannot reach the store, write to us and we will help you find the right route.
Security
Download links are private and are checked on every click rather than trusted once, so revocation, expiry and limits take effect on the very next attempt. Files are never public: a valid click is exchanged for a storage address that expires in about a minute. Access to the production systems is limited to the people who operate the app.
Changes
If this policy changes, the date at the top changes with it. This page is the current version.
Contact
Questions about this policy, or about data the app holds, go to support@rangerdownloads.com.