Privacy Policy
This policy describes how PAPA Tech Solutions (“we”) handles information when you install and use App In Minutes, the embedded Shopify app that generates a branded Android and iOS shopping app for a merchant’s store. A separate policy covers the companion mobile app App In Minutes Preview.
Who we are
PAPA Tech Solutions operates App In Minutes. Contact: support@papatechsolutions.com.
What the app does
After you install App In Minutes from the Shopify App Store, the app runs inside Shopify admin. It connects to your shop with OAuth, mints a Storefront API token, lets you set branding (name, color, layout, font, icon), optionally preview the storefront on a phone, and — after a one-time Shopify Billing purchase — generates signed Android and/or iOS builds.
Information we collect
- Shop identity. Shop domain, display name, and the installing merchant’s name, email, and locale as provided by Shopify during OAuth (session storage).
- Storefront access. We create a Storefront API token for your shop and store it encrypted. It is used so the generated mobile app (and Preview) can read your catalog and create checkouts.
- App configuration. App name, icon, theme color, layout, font, theme mode, package name, and publish-checklist progress that you enter in the wizard.
- Catalog and content (on your behalf). Product, collection, inventory, tags, store content/pages, and checkout data are requested from Shopify APIs so we can configure and preview the mobile app. We do not build advertising profiles from this catalog.
- Orders (limited). We use Admin order scopes so a shopper who proved ownership of their order in the generated app can cancel it. We do not store a customer order archive in App In Minutes.
- Customer Account API. Scopes for customer login, profile, and orders are requested so the generated mobile app can offer Shopify customer accounts. App In Minutes itself does not keep a customer database; customer records stay on Shopify.
- Billing. Plan selection and one-time purchase status from the Shopify Billing API (Android, iOS, bundle, Flutter source, and remainder upgrades). We do not collect card numbers. Charges appear on your Shopify invoice.
- Signing credentials you upload. Optional Apple API key, Apple Team ID, and Google Play service-account JSON are stored encrypted so we can sign or upload builds to your developer accounts. We never submit apps from PAPA’s store listings on your behalf as the merchant of record.
- Build artifacts. Icons, Android keystores (encrypted), and generated AAB/APK/IPA/source zip files are stored so you can download them. Artifacts are held in Firebase Storage and delivered with time-limited signed URLs.
- Operational email. If SMTP is configured, we may email the shop’s address about build started, succeeded, or failed.
Shopify APIs we use
Access is limited to the scopes granted at install, including product and Storefront (unauthenticated catalog and checkout) scopes, content, Customer Account API scopes for the generated app, and order read/write for buyer-initiated cancellation. You can uninstall the app at any time in Shopify admin, which revokes access.
Where data is stored
- Shop sessions, configuration, entitlements, and billing events in PostgreSQL (hosted by our infrastructure provider).
- Build files and icons in Google Firebase Storage.
- CI build jobs on GitLab (the Flutter template pipeline) using the configuration you submitted.
Tokens, keystores, Apple keys, and Play service accounts are stored encrypted at rest.
What we do not do
- We do not sell personal information.
- We do not use shop or customer data for third-party advertising.
- We do not create shopper accounts inside App In Minutes itself.
- Payments for App In Minutes happen through Shopify Billing, never as a card charge on this website.
Retention, uninstall, and Shopify compliance
If you uninstall App In Minutes, we stop using the Admin API for that shop. Shopify’s mandatory webhooks are implemented:
- customers/data_request and customers/redact — App In Minutes does not store per-customer records (only shop-level branding, sessions, and encrypted storefront tokens), so these topics are acknowledged with nothing to export or delete at the customer row level.
- shop/redact — after uninstall, Shopify may ask us to delete shop data; we redact the shop record per that request.
Billing events may be retained as needed for accounting and dispute handling.
Children
App In Minutes is intended for Shopify merchants (businesses), not for children under 13.
Changes
We may update this policy. The “Last updated” date at the top will change when we do.
Contact
Related: Privacy policy for App In Minutes Preview · Support
