PrintStack

Privacy Policy

Last updated: August 6, 2026

This policy describes how PrintStack (“we,” “us”) collects, uses, and protects information in connection with PrintStack.ai (the “Service”).

1. Information we collect

  • Account information — name, email address, role, and authentication data (password hashes, two-factor enrollment, passkeys). We never store plaintext passwords.
  • Business data you submit — customers, jobs, vendors, invoices, payments, documents, and communications your company manages in the Service.
  • Usage data — log and analytics data such as pages visited, actions taken, IP address, and browser type, used for security auditing and product improvement.

2. How we use information

  • To operate, secure, and improve the Service.
  • To generate AI-assisted features (for example vendor summaries and recommendations) from your company’s data and the shared vendor catalog described in section 3.
  • To send transactional email your company initiates or that the Service requires (invoices, receipts, proofs, account security).
  • To respond to support requests and meet legal obligations.

We do not sell personal information.

3. The shared vendor catalog

Vendor records are shared across the Service by default. When your company adds a vendor, its business profile — name, contact details, and capabilities — joins a platform-wide catalog visible to other print shops, unless PrintStack scopes it to your company. Content gathered from a vendor’s public website feeds a shared corpus that powers the vendor directory and AI recommendations for every shop.

What stays private to your company: your notes about a vendor, your quotes and transaction history with them, and files you upload — unless you mark a file as shared. Vendors can claim their directory profile and opt out of the public directory.

4. Service providers

We share data with processors only as needed to run the Service: payment processing (Stripe), email delivery (Resend), cloud hosting and storage (DigitalOcean), shipping (Shippo and carriers), and AI providers used to generate summaries and embeddings (Anthropic, Google, Voyage AI). Each processes data under its own contractual and security obligations.

5. QuickBooks Online

If your company connects QuickBooks Online, we exchange accounting data (customers, invoices, payments) with Intuit solely to provide the integration you configure. We access only the data the integration needs, we do not use QuickBooks data for advertising, and disconnecting the integration stops the exchange. Data already exchanged before you disconnect is retained under this policy. Intuit’s handling of that data is governed by Intuit’s own privacy policy.

6. Cookies and analytics

The Service uses cookies to keep you signed in: a staff session cookie, a customer-portal session cookie, and short-lived cookies used during two-factor and passkey sign-in. We measure product usage with a self-hosted analytics tool (Umami) served from our own domain — it uses no advertising networks and does not track you across other sites. Public pages, including the vendor directory and payment and proof pages, record page views and actions the same way.

7. Security

Data is encrypted in transit (TLS) and at rest. Access is limited by role-based permissions and tenant isolation, with audit logging of sensitive actions. Payment card data is handled by Stripe and never touches our servers.

8. Retention

We retain data for as long as your company’s account is active or as needed to comply with legal obligations, resolve disputes, and enforce agreements. Some records are retained by design: financial records (invoices, payments, and the audit trail) are kept, and user accounts are deactivated rather than deleted so the audit trail keeps a true record of who did what. You may request export or deletion of your company’s data, subject to records we are required to keep.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal information we hold about you. Contact us to exercise them; if you are an employee or customer of a company using the Service, we may direct your request to that company as the data controller.

10. Changes

We may update this policy from time to time. Material changes will be communicated through the Service or by email.

11. Contact

Privacy questions: support@printstack.ai.