Privacy Policy
Last updated: September 28, 2026
This Privacy Policy describes how Brand Studio ("we", "us", "the App") collects, uses, and protects information when you use Brand Studio as a Shopify app or as a web app.
1. Who we are
Brand Studio is a Shopify app and a web app developed and operated by Dreamstate I/S, CVR no. 43627805, registered in Denmark. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the information described in this policy. You can contact us at any time at contact@dreamstate.dk.
2. What we collect
From your Shopify store
When you install the App, we receive the following information from Shopify via OAuth:
- Shop domain - your
*.myshopify.comaddress - Access token - used to call the Shopify Admin API on your behalf, scoped to the permissions you granted at install
- Product data - product titles, descriptions, and existing image URLs that you choose to work with inside the App
When you use the web app
- Account details - your email address, your name if you give it, and your workspace name. Passwords are stored only as a secure hash by our authentication provider.
- Billing details - Stripe collects your payment details. We receive your Stripe customer ID, plan, subscription status, renewal date, and payment amounts. We never receive or store full card numbers.
That you provide directly
- Uploaded images - any product photo you upload for generation
- Prompts - text you write describing the desired output
- Custom API keys (optional) - if you opt into the Bring Your Own Key feature, API keys for supported external AI providers
- Support messages - anything you send us through the in-app chat
That we generate ourselves
- Generated images - the AI output produced from your uploads and prompts
- Usage records - date, time, generation settings, success or failure status, and current monthly count for plan enforcement
- Subscription state - your current plan, billing status, and renewal date as reported by Shopify Billing or Stripe
What we do NOT collect
- We do not collect data about your end customers (their names, emails, addresses, orders, or any personal data). The App only interacts with product data and your merchant account.
- We do not use cookies, fingerprinting, or any browser tracking technology beyond what is needed to keep you signed in: Shopify's embedded app session in the Shopify app, and essential sign-in cookies in the web app. We use no advertising or analytics cookies.
- We do not sell or rent any data to third parties, ever.
3. How we use your data
We process the data described above for the following purposes:
- To provide the service - generating images, saving them to your products, enforcing plan limits
- To bill you - Shopify (in the Shopify app) or Stripe (in the web app) handles payment processing; we receive notifications about subscription state and payments via their webhooks
- To run your account - sending account emails such as email confirmation and password reset links, and service notices such as changes to our terms or this policy. We do not send marketing emails.
- To support you - responding to your messages in the in-app chat
- To prevent abuse - rate limiting and content moderation to protect the service and other merchants
- To improve the service- aggregate, non-identifying metrics like "X% of generations succeeded this week". We never inspect individual prompts or images for product development.
4. Service providers
We share necessary data with trusted service providers in the categories below. We choose them carefully and use them only as needed to operate the App:
- Cloud database, file storage, and authentication providers - host the App backend and store merchant data in EU regions where possible.
- AI generation providers - receive uploaded images, prompts, and related generation settings to create requested outputs. We do not allow these providers to use merchant content to train public models where our provider terms give us that control.
- Shopify - receives subscription events and serves generated images you save to your products. shopify.com/legal/privacy
- Stripe - processes web app payments and subscriptions, and hosts the checkout and billing pages. stripe.com/privacy
- Email delivery providers - send account emails for the web app.
- Error tracking and performance monitoring providers - help us diagnose failures. We strip personal data before sending diagnostic events where possible.
- Hosting and infrastructure providers - serve the App frontend and backend. Standard request logs only.
5. Where your data lives
Our primary database and file storage is hosted in EU regions where possible. Generated images may be processed temporarily by AI generation providers, which may operate servers globally. Standard contractual clauses are in place where required for cross-border data transfers under GDPR.
6. How long we keep it
- Shopify app uploads and generated image files - purged from storage automatically after 30 days. The metadata row (prompt, generation settings, status, timestamps) is kept for audit purposes.
- Web app uploads and generated images - kept in your workspace library until you delete them or your workspace is deleted.
- Web app account and workspace - kept while your account is open. You can ask us to delete your workspace from Settings or by email, and we delete your workspace data within 30 days of the request. Payment records that accounting law requires us to keep are retained for the legally required period.
- Merchant record + usage history - kept while you have the App installed.
- After uninstall - we delete your merchant record, all custom keys, support messages, and usage history within 48 hours via Shopify's mandatory
shop/redactwebhook. - Support messages - kept for the duration of the conversation thread, deleted with the merchant record on uninstall.
- Error logs - automatically expire after 30 days.
7. Security
We take security seriously. Specifically:
- All traffic is encrypted in transit using TLS 1.2 or higher.
- All data is encrypted at rest in our database.
- API keys you provide for Bring Your Own Key are stored encrypted and only decrypted in memory at the moment a generation request runs.
- Image storage uses signed URLs that expire after 1 hour, so even if a URL leaks it can't be reused.
- Access to production systems is restricted to a small number of authorized administrators with multi-factor authentication.
8. Your rights under GDPR
If you are based in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- Right of access - request a copy of all data we hold about you
- Right to rectification - correct inaccurate data
- Right to erasure - request that we delete your data (uninstalling the Shopify app also triggers automatic deletion)
- Right to restriction of processing
- Right to data portability - receive your data in a machine-readable format
- Right to object to processing
- Right to lodge a complaint with your local data protection authority
To exercise any of these rights, email contact@dreamstate.dk. We will respond within 30 days. We do not require any specific form or formality - a plain email is sufficient.
9. Shopify GDPR webhooks
Shopify requires every app to handle three mandatory compliance webhooks. We implement all of them:
- customers/data_request - received when a customer asks Shopify for their data. Since we do not store any customer data, we acknowledge the webhook and report no data held.
- customers/redact - received when a customer asks for their data to be deleted. Same as above: no customer data to delete.
- shop/redact - received 48 hours after a merchant uninstalls our app. Triggers full deletion of the merchant record, all generation history, all support messages, and all stored API keys.
10. Children
Our service is intended for use by merchants, not by children. We do not knowingly collect personal data from anyone under 16. Our content policy expressly prohibits generating images of identifiable minors.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced inside the App and via email to merchants on a paid plan. The "Last updated" date at the top of this page always reflects the most recent revision.
12. Contact
Questions, concerns, or requests about this policy or your data:
- Email: contact@dreamstate.dk
- Postal: Dreamstate I/S, Drejøgade 26B, 4. 403, 2100 København Ø, Denmark
For data protection concerns specifically, you can also contact your local supervisory authority. A list of EU/EEA authorities is available at edpb.europa.eu.