Privacy policy
How Aoloha handles information when you visit this website, use Proofdrop, or connect Google Drive.
Effective date: September 30, 2026
Who we are
Aoloha operates Proofdrop and aoloha.com. For privacy questions or requests, contact hello@aoloha.com.
For merchant account, connection, security, and support information, Aoloha determines how information is used to provide and protect the service. For customer photos, we process uploads on the merchant’s behalf. The merchant determines why the photos are collected, which storage provider is used, who can access them, and how long to keep them.
Information we handle
- Merchant and app information: Shopify store domain, app settings, encrypted Shopify access and refresh credentials, and installation status.
- Google connection information: the connected merchant’s Google email address and account identifier, encrypted access and refresh credentials, and the app folder identifier.
- Uploads: customer photo bytes while processing an upload, generated filenames, file and job identifiers, storage provider, photo links, timestamps, and processing status. Images may contain personal information or embedded metadata; Proofdrop does not promise to remove image metadata.
- Security and operations: request information handled by our hosting and security providers, security-check results, temporary authorization data, and hashed network identifiers used for rate limiting.
- Support: the email address, message, and other details you choose to send us.
Proofdrop does not store customer contact-form names, email addresses, message text, customer account IDs, or order records in its app database. Those contact-form fields are handled by the merchant’s Shopify store. This does not prevent a customer from including personal information in a photo.
How we use information
We use this information to authenticate merchants, save app preferences, connect selected storage, upload photos, add photo links to contact messages, provide cleanup controls, prevent abuse, resolve support requests, and meet legal obligations. We do not sell personal information, use uploaded photos or Google user data for advertising, or use them to train general-purpose AI or machine-learning models.
Where applicable, the grounds for handling merchant and support information are providing the requested service, our legitimate interests in maintaining a secure service and responding to requests, and legal obligations. Google account access requires the account holder’s authorization. Merchants are responsible for a lawful basis and appropriate notices for their customers’ uploads.
Google user data & Limited Use
Proofdrop requests Google Drive’s https://www.googleapis.com/auth/drive.file scope to create and manage the app’s folder and uploaded photos, and https://www.googleapis.com/auth/userinfo.email to identify the connected merchant account. The Drive permission is limited to files created by or explicitly opened with the app; Proofdrop’s implementation uses its app-created folder and upload registry. It does not request broad access to the rest of your Drive.
We store your Google email and account identifier to show and match the connected account. Encrypted tokens let the service carry out the upload and cleanup features you authorize. We retain the folder and app-created file identifiers to deliver links and track cleanup.
Proofdrop’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google user data is used only to provide or improve the user-facing storage and cleanup features. Transfers are limited to what is necessary for those features, security, applicable law, or a permitted business transfer with appropriate consent. Human access is limited to your affirmative agreement to view specific data, necessary security investigation, legal compliance, or permitted internal operations using aggregated and anonymized data. We do not use Google user data for advertising, creditworthiness, lending, or general-purpose AI training.
Retention & deletion
- Photos remain in the merchant’s Google Drive or Shopify Files until the merchant deletes them. Uploads can remain even if the customer abandons the form.
- Temporary upload-job records are eligible for removal after 24 hours; expired authorization grants and older rate-limit records are also removed during subsequent authorization activity. This is activity-triggered cleanup, not a guaranteed deletion at an exact time.
- The app-created photo registry remains to support cleanup, including records marking completed deletions, until app metadata is removed.
- Merchant settings and connection information remain while needed for the installation. Disconnecting Google Drive removes the stored Drive connection and pending authorization information. Uninstall and shop-redact webhooks remove app-owned metadata and credentials when received and processed.
- Support messages and operational records are kept only as needed for support, security, and applicable recordkeeping obligations; deletion requests are reviewed for these purposes.
Disconnecting or uninstalling does not delete photos already stored with the merchant. Use the app’s cleanup controls before disconnecting or uninstalling, or manage the files directly in the storage provider. Cleanup is permanent and breaks existing photo links. We do not empty your Google Drive Trash.
Your choices & privacy requests
Merchants can disconnect Google Drive in Proofdrop and revoke access through Google Account connections. Revoking access stops future authorized API activity but does not delete existing stored photos or all app metadata by itself.
Depending on your location and the information concerned, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of your personal information, and to withdraw consent where processing relies on it. Send requests to hello@aoloha.com. We may ask for information necessary to verify your authority. You may also complain to the relevant data-protection authority.
Customers should first contact the store that collected their photo, because the merchant controls that photo and its storage. Aoloha can assist with app-related information it holds. Please do not email passwords, access tokens, or sensitive photos with your request.
Website, cookies & security
This website contains no contact form, advertising trackers, analytics scripts, or app-created cookies. Contact buttons open your email application. Cloudflare may process connection and security information as our hosting provider. The app’s upload security check uses Cloudflare Turnstile; Shopify, Google, and their services have their own cookie and privacy practices.
We use encrypted stored credentials, authenticated merchant actions, signed requests, bounded uploads, and security checks. No system can guarantee absolute security. Merchants should avoid asking customers to upload identity documents, payment details, health information, or other sensitive personal information.
Children & policy updates
Proofdrop is intended for merchants managing their stores, not as a service directed to children. Merchants should configure their forms appropriately for their audience and legal obligations. If you believe information about a child was submitted improperly, contact the collecting store or Aoloha.
We may update this policy to reflect changes in the service or legal requirements. The effective date above identifies this version. Material changes will be communicated through an appropriate service channel where required.
Built for clearer customer conversations.
Questions about setup, privacy, or your data?