Privacy Policy
Effective September 1, 2026
OpCreative is a print-on-demand fulfillment platform. This policy describes what we collect from sellers and their orders, why we collect it, who processes it on our behalf, and the choices you have. The short version: we collect what fulfillment genuinely needs, we sell nothing, and connections you grant — API keys or AI clients — only ever act with your own account's permissions.
What we collect
Account data: your name, email address, password hash or Google account link, phone number if you add one, language and timezone preferences, and company details you enter (company name, tax ID).
Order and fulfillment data: the orders you create or import — products, quantities, recipient names and shipping addresses, tracking numbers, and order notes. Recipient details belong to your customers; you are responsible for having the right to share them with us for fulfillment.
Financial records: your prepaid balance, transactions (top-ups, charges, refunds) and invoices. Card details are handled by our payment processors and never stored on our servers.
Technical data: server logs with IP addresses and request identifiers, kept for security, debugging and abuse prevention.
How we use it
To run the service: producing and shipping your orders, moving money on your balance, sending the notifications you enable, and answering support tickets.
To keep the platform safe: authentication, rate limiting, audit logging of sensitive actions, and fraud and abuse detection.
We do not sell your data, and we do not use your data to train AI models.
AI clients and API access
If you connect an AI client (Claude, ChatGPT or another MCP-compatible app) or create an API key, that connection acts with your account's own permissions — it can never see more than your account can. Write actions require your explicit confirmation in the conversation.
What an AI client does with data it reads through your connection is governed by that provider's own privacy policy. You can revoke a connection or API key at any time from your profile; OAuth access tokens expire after 60 minutes and refresh tokens rotate on every use.
Every credential we store — password, API key, OAuth token — is stored hashed, never in plain text.
Who processes it for us
We use a small set of processors to run the service: Vercel (hosting), Neon (database), Resend (transactional email), our shipping carriers and label providers (to produce and deliver parcels — they receive recipient names and addresses), and our payment processors. Each receives only what its job requires.
Retention
Order and financial records are kept for as long as your account exists and as required for tax and accounting law. Server logs are kept for a limited operational window. When you delete your account, personal data is removed or anonymised except where the law requires us to keep it.
Your choices
You can access and correct your account data in your profile, export your orders from the dashboard, disconnect AI clients and revoke API keys, and request account deletion by contacting support. If you are in a jurisdiction with statutory data rights (such as the GDPR), you can exercise them through the same contact.
Changes
When this policy changes materially we will note it on the changelog and update the effective date above.