Privacy Policy
Effective date: October 4, 2026
This policy describes how ArtUp Labs ("we", "us") handles data in the ArtUp Labs app for Shopify (the "App"), its admin at app.artuplabs.com, its theme block and the AR room page at artuplabs.com/room/. The App turns product photos into 3D models, adds them to products as product media, and lets shoppers view products in their room.
Summary
- The App does not collect personal data of your customers (shoppers).
- We store the data needed to run the App for your store: your store's access session, records of 3D generations for your products, and your store's plan and generation counts for billing.
- We send product photo URLs to fal.ai to generate 3D models.
- Generated model files are deleted from our storage within 14 days; logs are kept for 14 days.
- When you uninstall the App, Shopify asks us to delete your store's data and we delete it.
Data we collect and store
All App data is stored with Amazon Web Services (AWS) in the us-east-1 (N. Virginia, USA) region.
Store session
When you install the App, Shopify gives us an access token for your store. We store the session record in AWS DynamoDB: your store's myshopify.com domain, the access token, the granted access scopes, the token expiry and technical fields (session ID, OAuth state). The App uses store-level (offline) sessions and does not store data about your staff accounts. The App asks for these access scopes: read_products, write_products, write_files.
Generation jobs
When you click Generate 3D on a product, we store a generation job record in AWS DynamoDB: your store domain, the product ID, the product title, the product image URL, the fal.ai request ID and its status URLs, the keys of the generated model files, model size and triangle count, the height you enter on Accept, the ID of the 3D model media added to the product, the job status, error text and timestamps, and for billing: which generation counter the job counted against, whether the generation is billable beyond your plan's included generations, and whether its usage was reported to Shopify. We also keep per-store generation counters to enforce limits; daily counters expire automatically after 2 days. Generation job records are kept while the App is installed; after you uninstall, Shopify sends a shop/redact request (about 48 hours after the uninstall) and we delete them.
Plan and billing
Billing goes through Shopify. To know your plan we keep a cached copy of your subscription in AWS DynamoDB: your store's Shopify shop ID (shop GID), the plan handle, the trial end date and when it was last checked. It is checked with Shopify again when it is more than an hour old, and dropped when Shopify tells us your subscription changed. Monthly generation counters expire automatically 70 days after their month begins; the free trial's generation counter has no expiry. The cached plan and all counters are deleted on shop/redact.
Generated model files
Generated 3D model files (GLB) are stored in AWS S3 and are deleted automatically 14 days after they are created. When you accept a model, the App uploads it to your Shopify store as product media; from then on it is stored by Shopify in your store and you control it like any other product media.
Logs and queues
Our servers write operational logs to AWS CloudWatch; they may contain your store domain, product IDs and error messages and are deleted after 14 days. Background tasks pass through AWS SQS queues with the store domain and product ID; messages are processed within minutes, and failed ones are kept for up to 14 days for retry and inspection.
Backups
Our DynamoDB tables have point-in-time recovery enabled, so a deleted record can remain in AWS backups for up to 35 days before it is gone.
Data we share
- fal.ai — to generate a 3D model we send the URL of the product's photo (a Shopify CDN link) to fal.ai and download the resulting model. fal.ai processes the request under its own terms and privacy policy.
- Shopify — the App reads products and your store's shop ID and writes 3D model media through the Shopify Admin API. To check your plan it sends your shop ID to the Shopify Partner API, which returns your subscription (plan and trial end). For each generation billed beyond your plan's included generations it sends a usage event to the Shopify App Events API with your shop ID, the time and an event key made of the product ID, the attempt number and your shop ID; Shopify adds the charge to your bill.
- Amazon Web Services — hosting, database, file storage, queues and logs.
- Cloudflare — DNS for artuplabs.com and delivery of the AR room page.
- Delivery networks — the room page is delivered through Cloudflare and the App through AWS CloudFront; they process visitors' IP addresses to deliver pages. We do not store IP addresses in the App's database.
We do not sell data and do not share it for advertising.
Shoppers and the AR room page
The theme block ("View in my room" / "Add to my room") keeps the shopper's room set — product variant IDs, model file links and product titles — only in the shopper's browser (localStorage on your store's site). It does not send it to us. "View in my room" opens artuplabs.com/room/ with the room set in the link; the page shows the models in the browser and loads model files from Shopify's CDN. The room page has no accounts, sets no cookies and runs no analytics. AR on iPhone through the ArtUp Labs App Clip, which opens the same page, is rolling out (pending Apple approval). "Add all to cart" sends the shopper to your store's own cart. We do not receive names, emails, addresses, orders or payment data of your customers.
GDPR and data deletion
- App uninstalled — we delete your store's sessions (access tokens) right away.
- shop/redact — when Shopify sends this request after you uninstall the App, we delete all generation jobs and counters of your store, all of its model files in our storage, and its sessions.
- customers/data_request and customers/redact — the App holds no customer data, so there is nothing to export or delete; we acknowledge these requests.
3D models already added to your products stay in your store until you delete them in Shopify. You can ask us to delete your store's data at any time by writing to support@artuplabs.com.
Security
Data is transferred over HTTPS. Access tokens and API keys are stored in AWS and are not shown in the App's interface. Model preview links in the admin expire after 15 minutes.
Changes
If we change this policy, we will update this page and its effective date.
Contact
Questions about privacy: support@artuplabs.com.