Dropslot

Privacy policy

Last updated October 5, 2026

Dropslot is a Shopify app made by DCODED. It adds an upload field to a store's product pages so shoppers can attach photos and files to the items they buy. This policy explains what data Dropslot handles, why, and how long it is kept.

Data we collect from merchants

Files your shoppers upload

A shopper's file goes from their browser straight to Shopify and is saved in your store's own Shopify Files (Content → Files). Dropslot doesn't keep a copy. Shopify serves these files from its CDN at a long, random address, which is added to the cart line so it shows on the order. Anyone with the address can open the file, as with other files in Shopify Files.

For the Uploads page, Dropslot keeps an index of each upload: the file's Shopify ID and address, the original file name, type, size and pixel size, the product it was uploaded on, the field label and the time. On Plus, the ZIP download fetches the selected files from Shopify and streams them to you without storing them.

Data about your customers

Dropslot has no access to your customers or orders and never sees, reads or stores shoppers' names, emails, addresses or orders. Uploads are not linked to a customer account. Files may show whatever a shopper chooses to upload, such as a photo of a person; they are stored in your store, under your control, and you can delete them in Dropslot or in Shopify Files at any time.

How the data is used

Only to run Dropslot for your store: accept uploads, list them for you, and answer your support requests. We do not sell data, use it for advertising, or share it with anyone except the services below.

Services that process data

This website

dropslot.dcoded.dev uses Google Analytics to count visits and see which pages are useful. It sets cookies and receives your IP address and browser details. We don't combine this with app data. You can block it with any tracker blocker or Google's opt-out add-on. The Dropslot app and the upload field on your store don't use analytics.

Retention and deletion

Security

Data is sent over HTTPS and stored on an encrypted volume. Every request from your storefront is signed by Shopify and checked, and upload tickets expire after 30 minutes. Credentials are kept as encrypted secrets, separate from the code.

Contact

Questions about privacy: dropslot@dcoded.dev.