paperlane.

PAPERLANE

Privacy policy

What we process, why we need it and how to contact us about your data.

Last updated: 14 September 2026

Who provides Paperlane

Paperlane is provided by Micha Schepen (Molenring 93, 2741 MZ Waddinxveen, the Netherlands). For privacy questions and requests, email vschepen@gmail.com. Micha Schepen is responsible for information used to run Paperlane, provide support and manage the service. When a merchant imports customer information, Paperlane processes it to provide that merchant’s requested order workflow. The merchant remains responsible for deciding what customer information to import and the lawful basis for doing so.

Information used by the app

  • Store connection: Shopify store name, domain, store and installation identifiers, permissions and access credentials needed to connect the installed app.
  • Product catalog: product and variant identifiers, SKUs, descriptions, prices and currencies from Shopify or a catalog you import.
  • Saved orders: the reference, customer label, original filename, selected products, quantities, prices, extracted source text, timestamps and any resulting Shopify draft identifier.
  • Usage and subscription: saved-draft counts, subscription status, plan and billing-cycle information supplied by Shopify. Paperlane does not receive your payment-card details.
  • Privacy and support: information in requests from Shopify or messages you send us. A Shopify privacy request may include a customer identifier, email, phone number and order identifiers.

Original Excel, CSV and PDF files are read in your browser. Paperlane does not upload or store the original files. Extracted catalog data and the details you save are sent to your private workspace. Avoid importing personal information that is unnecessary for the order.

How information is used

We use this information to sign you in, match products, save reviewed drafts, create Shopify drafts when you ask, check your allowance, provide support, protect the service and handle privacy requests. Service and account processing is needed to provide the service you request. Security and abuse prevention support our legitimate interest in operating a reliable service. We also process information where necessary to meet applicable legal obligations.

Paperlane does not sell your imported data, use it for advertising or send your purchase orders to an AI model for processing.

Services that receive information

Shopify supplies the store catalog, authenticates your installation and handles subscription approval and billing. When you select Create draft in Shopify, Paperlane sends the selected variant identifiers, quantities and an order-reference note to Shopify. That draft then becomes part of your store’s Shopify records.

Paperlane is hosted using OpenAI Sites and Cloudflare infrastructure, including database storage. These providers process information needed to host, deliver and secure the service, which can include network identifiers and operational logs. Support emails are handled through Gmail. These services operate internationally; processing may take place outside your country. Contact us for information about the applicable hosting arrangements and transfer safeguards.

See the privacy information from Shopify, OpenAI, Cloudflare and Google.

Storage, retention and deletion

Catalogs and saved drafts remain in your workspace while you use the app, until they are deleted or your store’s data is removed. Usage records are retained to enforce the free allowance and billing-cycle limits. Deleting a draft does not restore used credits.

You can request an export, correction or deletion by email. A merchant can also handle Shopify customer requests in Help & getting started. Because imported customer labels and source text may not uniquely identify a Shopify customer, the correct records must be selected and checked before export or deletion.

Uninstalling disconnects the app. When Paperlane receives Shopify’s verified store-deletion notification for that removed installation, it removes the associated workspace, catalogs, drafts, credentials, sessions, usage and pending requests. Contact us if you need deletion assistance. Deleting Paperlane records does not delete drafts already created in Shopify. Separate provider logs, backups and legally required records follow the relevant provider or legal retention requirements.

We keep support correspondence only as needed to resolve the request and meet applicable record-keeping obligations.

Cookies and security

Paperlane uses essential cookies for sign-in and to secure the Shopify connection. The app session lasts up to eight hours and the temporary sign-in check lasts up to ten minutes. Our hosting providers may also use essential security cookies. Paperlane does not add advertising or analytics cookies.

Connections use HTTPS. Access credentials and pending Shopify privacy-request contents are encrypted before database storage. Access to saved workspace records is restricted to the authenticated store or authorized service administration. Saved order details are not end-to-end encrypted.

Your requests and rights

Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of your personal data, and object to certain processing. You may also complain to your local data-protection authority. Contact vschepen@gmail.com with your store domain and the type of request. Do not send passwords or access tokens. We may need to verify your identity or authority before sharing or deleting records.

If you are a customer of a store using Paperlane, contact that store first so it can identify the relevant order. You can also contact us for assistance. We handle requests within the applicable legal time limits.

Changes

We will update this page when the way Paperlane handles information changes and revise the date above. Material changes will be brought to affected merchants’ attention.