Privacy policy
1. Scope and overview
Rollbum operates in the United States. This policy explains how Rollbum handles information when you use the Rollbum iPhone app, rollbum.com, the Shopify store, checkout, photobook production, and support services. We do not sell your photos or use them to train general-purpose artificial-intelligence models.
2. Information we handle
Account information: We may receive your name, email address, account identifier, sign-in provider, verification status, and account creation date. Apple, Google, and Firebase process authentication information under their own policies. Rollbum does not receive your Apple or Google password.
Photos and project content: The app requests access under Apple's controls and uploads only photos, layouts, captions, previews, or project files you use in a cloud-saved project or submitted book. Selected content is processed to save projects, prepare print files, improve print resolution, recover projects, and fulfill orders.
Orders and payments: Shopify handles authoritative product, cart, checkout, payment, customer, address, tax, discount, order, refund, fulfillment, tracking, and store-analytics information. Rollbum receives what is needed to verify a paid order, produce the book, resolve problems, and synchronize production and shipment. Rollbum does not receive or store complete card numbers or card security codes.
Usage and security: Google Analytics for Firebase measures app usage, including sign-up, sign-in, book creation, photo counts, page counts, and checkout progress. Our custom events do not contain photo content, filenames, project titles, shipping details, names, or email addresses. Services also process IP addresses, request times, technical errors, and security signals.
Support: If you contact us, we receive the contact details, message, order references, and attachments you choose to provide.
3. How we use information
- Provide accounts, editing, storage, checkout, printing, delivery, and customer support.
- Authenticate users, prevent abuse, secure uploads, and troubleshoot the services.
- Calculate pricing and tax, process payments, fulfill orders, and maintain transaction records.
- Measure product performance and improve features and reliability.
- Comply with law, enforce terms, and protect users, Rollbum, and others.
4. Service providers and disclosures
Rollbum uses Shopify for the store, checkout, payments, orders, refunds, customer notifications, fulfillment records, and store analytics; Cloudflare for edge processing, queues, private object storage, image processing, and production infrastructure; Firebase and Google for authentication and app analytics; Apple for the iPhone app and Apple-provided account or platform services; RPI Print for manufacturing and shipping; and delivery carriers and support providers where needed.
We may also disclose information to professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate misuse, resolve a dispute, or complete a business transaction. Providers may process information in countries where they operate under applicable safeguards.
5. Photos and production files
Rollbum does not upload your entire photo library. Source and print-ready PDFs are private and are not placed in Shopify. RPI receives short-lived access to production files needed for a submitted print order.
6. Retention and deletion
Active projects and photos are retained so you can edit and recover books. Deleted projects may remain recoverable for 30 days before cleanup. Current cleanup settings generally use 30 days for finished or failed unpaid submissions and 65 days for paid-order files; unresolved orders can require longer retention. RPI separately retains print assets for its production and reprint-support window.
Shopify order and payment records, support correspondence, analytics, security records, and narrow Rollbum/Shopify/RPI correlation records may be retained longer for operations, accounting, fraud prevention, disputes, and legal obligations. Deleting the app or a project does not automatically erase an active or paid order.
7. Store cookies, app analytics, and tracking choices
The Shopify store uses cookies and similar technologies for storefront sessions, security, preferences, checkout, and reporting. The native app uses app storage and software development kits rather than ordinary website cookies. If the app requests Apple's App Tracking Transparency permission, advertising-related consent signals remain disabled when permission is denied or restricted. See the Cookie Policy.
8. Your choices and rights
You can manage photo access and tracking permission in iOS Settings, choose what to submit, update checkout information in Shopify, and contact us to request access, correction, deletion, portability, or another right available where you live. We may need to verify a request. Mandatory retention and active-order requirements can limit deletion.
We do not sell personal information for money. If an advertising activity is considered sharing, targeted advertising, or a sale under applicable law, use the customer privacy controls shown by Shopify or contact us.
9. Security and children
We use access controls, signed short-lived production links, encrypted network connections, bounded uploads, signature verification, minimized logging, and app-attestation checks. No online service can promise absolute security. The services are not directed to children under 13, and we do not knowingly collect personal information from a child under 13.
10. Changes and contact
We may update this policy when the services or law change. The date shown by Shopify is the current effective date. For privacy questions or requests, email hello@rollbum.com. Do not send passwords, complete card numbers, or security codes.