Privacy policy
Effective date: 16 July 2026
Who we are
Picturepops (operating at https://picturepops.com, owned by Daniel Douek) sells personalized pop-up greeting cards. Customers upload their own photos, add a note, and we produce and ship a physical card. This policy explains what data we collect, how we use it, who we share it with, and your rights.
Data we collect
We collect only what we need to build your card and ship it to you. When you visit the site (before signing up):
- A random visitor ID stored in a browser cookie (pp_vid, 365-day lifetime). We use it to remember your progress if you leave mid-way and to link a design in progress to your account when you sign up.
- Standard web-server logs (IP address, user agent, referrer, timestamp) retained for up to 30 days for security and diagnostics.
- Anonymous analytics events (page views, step completion) if analytics is enabled.
When you start the card builder:
- The name you enter, stored in your browser (localStorage) and on your Shopify customer record once you provide an email.
- Your email address, stored on your Shopify customer record; used for order confirmations, shipping updates, and — if you opt in — marketing.
- Optional attribution (how you heard about us), stored on your customer record as metadata.
- Photos you upload from your device (kept only in your browser's local storage until you place an order) or photos you select via Google Photos (see below).
- Any text you add to your card (top sentence, per-photo captions, note, recipient details).
When you place an order:
- Shipping address (recipient name, street, city, state, ZIP).
- Payment information, processed by Shopify Payments — we do not receive or store your card number.
- Order metadata (item, quantity, timestamps).
How we use Google Photos data (Photos Picker API)
If you choose "Import from Google Photos" during card creation, we use the Google Photos Picker API with the scope https://www.googleapis.com/auth/photospicker.mediaitems.readonly.
What we access:
- Only the specific photos you explicitly select in Google's own picker UI. We never enumerate, browse, index, or search your Google Photos library, albums, or metadata.
- The OAuth access token issued by Google, which lives only in browser memory for the duration of your picker session — it is never stored, never sent to our servers, and is discarded when the session ends.
What we do with those photos:
- Fetch the bytes of the specific images you picked, download them into your browser, and include them on the physical card we produce for you.
- Store the downloaded copy on our fulfilment servers only as long as needed to print your order (typically less than 72 hours).
- We do not use Google Photos data for any purpose other than fulfilling the card you designed. We do not use it to train machine-learning models. We do not use it for advertising. We do not sell it. We do not share it with third parties except our print/fulfilment partner listed below.
Compliance: Picturepops' use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Deletion: You can revoke Picturepops' access to your Google Photos at any time from https://myaccount.google.com/permissions. Revoking access invalidates our token immediately. To delete already-downloaded copies of your photos from our fulfilment servers, contact daniel@picturepops.com and we'll remove them within 30 days.
Who we share your data with
We do not sell your personal information. We share limited data with the service providers below only as needed to run the store:
- Shopify (shopify.com) — hosts the storefront, checkout, and customer records.
- Shopify Payments / Shop Pay — processes payments.
- Our print & fulfilment partner — receives your photos, card text, and shipping address to produce and ship your order.
- Google — we do not send them any data about you; the Google Photos Picker API is a client-to-client flow where the photos you
select flow from Google's servers to your browser directly.
- Marketing tools (only if you opt in to marketing) — email service provider for order-related and promotional emails.
Cookies and similar technologies
We use:
- pp_vid — random visitor ID, 365 days, first-party, secure, samesite=lax.
- pp_email — set once you provide your email, 365 days, first-party.
- Standard Shopify cookies for cart state and login.
- Optional analytics cookies (Google Analytics, or similar) if we enable them.
You can clear all Picturepops cookies at any time in your browser settings.
Data retention
- Marketing email list: until you unsubscribe.
- Customer records with order history: kept for as long as needed for order support and tax records (typically 7 years for financial
records).
- Photos on our fulfilment servers: up to 72 hours after your order ships; then deleted.
- In-progress designs stored in your browser: until you clear browser data or 30 days after last activity.
Your rights
You can, at any time:
- Access what personal data we hold about you — email hello@picturepops.com.
- Correct anything that's wrong — reply to any order-related email or use the contact form.
- Delete your account, data, and any residual photo copies — email hello@picturepops.com with subject Delete my data. We respond
within 30 days.
- Opt out of marketing — every marketing email has an unsubscribe link, or reply STOP.
- Withdraw consent for Google Photos access — visit https://myaccount.google.com/permissions.
California residents: you have additional rights under the California Consumer Privacy Act (CCPA). We do not sell your personal
information as defined by CCPA. Contact hello@picturepops.com to exercise any CCPA rights.
Children's privacy
Picturepops is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you
believe a child under 13 has provided us data, contact us and we will delete it.
Security
We use HTTPS everywhere. Payment card data is handled entirely by Shopify Payments (PCI-DSS Level 1). Google Photos access tokens
live only in memory in your browser session, never persisted server-side. Photos on our fulfilment servers are stored encrypted at
rest.
Changes to this policy
If we make material changes, we'll update the effective date at the top and — if the change is significant — notify users by email.
Contact
- Email: daniel@picturepops.com
- Business: Daniel Douek, Picturepops
- Website: https://picturepops.com