YOUR INFORMATION
Privacy policy
Updated 9 September 2026
Who operates Madeboard
Madeboard is operated under the registered Australian business name Keltriva. In this policy, Keltriva, we and us refer to the business operator trading under that name. For privacy questions or support, email support@keltrivahq.com.
This policy covers Madeboard’s Shopify application, public website and support communications. The merchant that accepts a customer’s order has its own privacy policy. Our data processing terms describe our responsibilities when handling orders for merchants.
Information we process
- Store and access information: shop domain and identifier, installation and refresh dates, studio name, subscription status, and the version, time and Shopify user identifier recorded when merchant terms are accepted.
- Order information: order identifiers, numbers, dates, production status, item titles, variants, SKUs, quantities and custom item properties. Properties and artwork can include personal names, images and instructions.
- Privacy requests: request and order identifiers, receipt time and response completion time. We do not save customer email or phone fields from Shopify’s privacy webhook payloads.
- Support communications: your email address and the information you choose to send us.
- Technical information: hosting and email providers process connection and security information such as IP addresses, request times and service logs. Our application error messages log a reference and error category rather than order contents or access tokens.
Our order query does not request customer profile names, email addresses, phone numbers, billing or shipping addresses, or payment-card details. Personal information can still appear in item properties and artwork. Merchants should limit those fields to what is needed to produce the order.
Why we use it
We use this information to connect the store, display production jobs and instructions, save progress, show artwork links, create printable sheets, check subscription access, provide support, keep the service secure and handle privacy requests. We process order information on the merchant’s instructions for these purposes.
Madeboard does not sell customer data, use it for targeted advertising, or use it to generate AI output. We do not include advertising pixels or behavioural analytics in the app or public pages. Madeboard does not profile customers or make automated decisions with legal or similarly significant effects.
Artwork and external services
Madeboard stores artwork links, not copies of the original artwork files. Viewing an image or opening a link makes a request from your browser to the original file host, which can receive your IP address and request details. Availability and retention of those files are controlled by Shopify or the merchant’s upload provider.
The service uses OpenAI Sites hosting on Cloudflare infrastructure, including a Cloudflare D1 database. Shopify supplies authentication, authorised order access and subscription services. Support email uses Google Workspace. These providers process information needed to supply their services. We may also disclose information when required by applicable law.
We operate in Australia, but our providers operate internationally. Information may be processed outside Australia, including in the United States and other countries used by those providers. Madeboard does not offer an Australia-only storage commitment. Contact us if you need details about a provider or transfer before using the service.
Security
The published service uses HTTPS. Cloudflare documents encryption at rest for D1 databases and encryption in transit for database connections. Madeboard verifies Shopify session credentials, restricts data access to the connected store and checks webhook signatures. Online Shopify access tokens are not persisted in our application database. No online service can promise absolute security.
Retention and deletion
- Orders on the board: each successful import sets that order’s expiry to 90 days later. Marking an order Done does not extend its expiry or fulfil it in Shopify.
- Orders leaving the board: after a successful refresh identifies an order as no longer eligible, its expiry is shortened to no more than 30 days later. Later refreshes do not repeatedly extend that inactive period.
- Expired orders: they are excluded from the board and customer exports. Cleanup deletes the order, its items, properties, artwork links and Madeboard production status. If an eligible order is subsequently imported again, it starts with a new production status.
- Customer deletion: when Shopify delivers a verified deletion request, matching order and item details are cleared. Minimal shop and order identifiers remain as deletion markers to prevent accidental re-import, until the store’s Madeboard data is deleted.
- Uninstallation: receipt of Shopify’s uninstall notification disconnects the app and clears the subscription cache. A verified Shopify store-deletion request deletes the store’s application records. As a fallback, cleanup deletes stores still marked uninstalled after 48 hours.
- Privacy requests: completed request records expire 30 days after the recorded response. Open requests remain until resolved or the store is deleted, so a missed response is not silently erased.
- Store settings and acceptance records: retained while the app remains installed, then removed with store deletion.
Cleanup runs in batches through maintenance and during site activity. Expiry blocks application access immediately, but physical removal can be delayed until a cleanup run succeeds. This service does not promise erasure at an exact clock time. Existing records without an expiry receive the applicable 30- or 90-day period on their first cleanup.
Provider backups, recovery history and technical logs follow the providers’ own retention processes; removal from the live database does not instantly erase every recovery copy. We do not promise a provider backup or log deletion deadline. Support correspondence is reviewed and removed when no longer needed to resolve the issue or meet applicable obligations.
Shopify’s 60-day order access window is separate from these retention rules. Shopify orders, original artwork, downloaded exports and printed sheets are separate copies controlled by the merchant or original provider.
Your requests and choices
If you are a customer, contact the merchant that accepted your order for access, correction, deletion or questions about the merchant’s use of your information. The merchant can send requests through Shopify. We assist with information that remains in Madeboard and may need to verify authority before releasing it.
Merchants can download requested data in Settings → Customer privacy requests, provide it securely to the customer and record the response. This remains accessible without a subscription or acceptance of updated terms. Correct order details in Shopify and refresh Madeboard. Contact support about information that cannot be corrected there, consent withdrawals, processing restrictions or an unresolved request.
For a privacy concern about Madeboard, email support@keltrivahq.com. We aim to respond within 30 days. If you remain dissatisfied, you can contact the privacy regulator responsible for your location, including the Office of the Australian Information Commissioner where it has jurisdiction. Your rights depend on the applicable law.
Changes
We update the version date when this policy changes. Material changes to the purposes or terms of processing will be brought to merchants’ attention before they take effect, where required.