Last updated: August 6, 2026
This policy describes how PrintStack (“we,” “us”) collects, uses, and protects information in connection with PrintStack.ai (the “Service”).
We do not sell personal information.
Vendor records are shared across the Service by default. When your company adds a vendor, its business profile — name, contact details, and capabilities — joins a platform-wide catalog visible to other print shops, unless PrintStack scopes it to your company. Content gathered from a vendor’s public website feeds a shared corpus that powers the vendor directory and AI recommendations for every shop.
What stays private to your company: your notes about a vendor, your quotes and transaction history with them, and files you upload — unless you mark a file as shared. Vendors can claim their directory profile and opt out of the public directory.
We share data with processors only as needed to run the Service: payment processing (Stripe), email delivery (Resend), cloud hosting and storage (DigitalOcean), shipping (Shippo and carriers), and AI providers used to generate summaries and embeddings (Anthropic, Google, Voyage AI). Each processes data under its own contractual and security obligations.
If your company connects QuickBooks Online, we exchange accounting data (customers, invoices, payments) with Intuit solely to provide the integration you configure. We access only the data the integration needs, we do not use QuickBooks data for advertising, and disconnecting the integration stops the exchange. Data already exchanged before you disconnect is retained under this policy. Intuit’s handling of that data is governed by Intuit’s own privacy policy.
The Service uses cookies to keep you signed in: a staff session cookie, a customer-portal session cookie, and short-lived cookies used during two-factor and passkey sign-in. We measure product usage with a self-hosted analytics tool (Umami) served from our own domain — it uses no advertising networks and does not track you across other sites. Public pages, including the vendor directory and payment and proof pages, record page views and actions the same way.
Data is encrypted in transit (TLS) and at rest. Access is limited by role-based permissions and tenant isolation, with audit logging of sensitive actions. Payment card data is handled by Stripe and never touches our servers.
We retain data for as long as your company’s account is active or as needed to comply with legal obligations, resolve disputes, and enforce agreements. Some records are retained by design: financial records (invoices, payments, and the audit trail) are kept, and user accounts are deactivated rather than deleted so the audit trail keeps a true record of who did what. You may request export or deletion of your company’s data, subject to records we are required to keep.
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal information we hold about you. Contact us to exercise them; if you are an employee or customer of a company using the Service, we may direct your request to that company as the data controller.
We may update this policy from time to time. Material changes will be communicated through the Service or by email.
Privacy questions: support@printstack.ai.