S ShopStart
Security & trust

Shop data should stay with the shop that owns it.

ShopStart uses role-based access, tenant separation, transport security, protected secrets, audit logging and controlled infrastructure to help protect customer and operating information. Security is treated as part of the platform, not a marketing add-on.

Core controls

Designed around separation, least access and traceability.

These are the controls ShopStart currently describes in its production privacy and platform policies. We do not claim certifications or guarantees that have not been earned.

01

Tenant separation

ShopStart enforces tenant boundaries so one shop's private operating data is not made available to another shop merely because both use the same platform.

02

Role-based access

Owner, staff, dealer and administrative permission surfaces are separated, and users receive access according to their assigned role and workspace.

03

Transport security

ShopStart uses protected web transport for data moving between supported browsers, the ShopStart application and platform services.

04

Protected secrets

Application secrets and service credentials are kept out of normal customer-facing interfaces and handled through controlled platform configuration.

05

Audit logging

Operational and security-sensitive activity can generate audit events used to operate, secure and troubleshoot the service.

06

Backups and operations

ShopStart maintains backups and operational records as part of service reliability, security, dispute resolution and recovery practices.

Payments

Raw subscription card numbers are handled by the payment provider.

ShopStart may retain payment-provider references needed to operate subscription billing, but payment-card details for the ShopStart subscription are collected and processed by the payment provider rather than stored by ShopStart as raw card numbers.

Shop customer payments are separate.A print shop's own customer-payment flow and connected merchant account are separate from the ShopStart software subscription and remain subject to the shop's payment-provider relationship.
Infrastructure providers

Purpose-built services instead of one giant server doing everything.

ShopStart may use established providers for hosting, content delivery and security, private file storage and payment processing.

DigitalOcean Cloud hosting and database infrastructure may use DigitalOcean services.
Cloudflare Content delivery, security and private object-storage functions may use Cloudflare services.
Stripe Subscription billing and payment-provider functions may use Stripe services.
Data ownership

Your business data remains your business data.

ShopStart customers retain ownership of their submitted customer, job, artwork, pricing and business content.Print Life Solutions receives only the limited rights needed to host, process, transmit, back up and display that content to provide and secure ShopStart, subject to the Terms and Privacy Policy.

No online system can guarantee absolute security. For the complete legal terms, retention details, privacy rights and service limitations, review the Privacy Policy and Terms of Service.