YOU
The founder. You came here deliberately, gave us an email address, and asked us to print something. Your data is handled the way any shop handles a customer’s.
THE1STSALE
This page describes what we collect, what we deliberately refuse to keep, and what does and does not reach a printed sheet.
THE SHORT VERSION
Almost every privacy policy describes one relationship. This product has two, and keeping them apart is the honest way to explain it.
YOU
The founder. You came here deliberately, gave us an email address, and asked us to print something. Your data is handled the way any shop handles a customer’s.
YOUR FIRST CUSTOMER
A stranger to us. They bought something from you, possibly years ago, and never agreed to anything with us. They get the most conservative treatment we can give them: they are reduced to a place.
Where this policy says your customer, it means the person in the record you are framing — not you.
The1stSale (“we”, “us”) operates the1stsale.com and is the data controller for the information described here. Reach us at hello@the1stsale.com.
For the record you import from a connected store, you are the controller of your own customer’s data and we act as your processor — see section 12.
Connecting Shopify, Stripe, Square, Etsy, PayPal, BigCommerce or eBay grants us read-only access for a few seconds. We ask for the narrowest permission each platform offers — the ability to read orders, and nothing else. We cannot alter, refund or create anything in your store, and we cannot see your products, staff, payouts or settings.
Concretely, one connection does this and then stops:
The twelve fields are: order number, amount, currency, date, time, product name, quantity, customer city, customer country, order status, and two flags recording whether the order looks like a test. Your customer’s name, email address, phone number and street address are never among them — they are not stored, not logged, and not printed.
That list is written to a single-use file, expires after fifteen minutes, and is deleted the moment the builder reads it. If you walk away, it expires on its own.
You can attach a screenshot, invoice or confirmation email instead of connecting a store, or simply type the details yourself. Anything you upload is used once to read the order details out of it and is not kept afterwards.
Automated screenshot reading is not currently enabled. If we enable it in future, this page will say so, and will name the provider, before it processes anything.
A record you type in yourself is marked Founder recorded. A record read directly from a store over a read-only connection is marked as verified. Editing a verified record removes that mark, because the mark describes where the data came from rather than how it looks.
The printed record can carry your business name, the order number, the amount, the date and time, the product, and a city and country. It never carries your customer’s name, email address, phone number or street address. This is a deliberate constraint in the product, not a setting you have to find: a person on a wall for decades should be a place, not a mailing address.
Payments are processed by Stripe and PayPal. Card details are entered on their systems and never reach our servers — we receive only the outcome, the amount, and a reference. Their handling of your data is governed by their own privacy policies.
Prints are produced and shipped by Gelato, which receives the finished artwork and the delivery details needed to post it to you. It does not receive anything about your business beyond what the artwork itself shows, and we send it no separate customer records.
Only the parties named above: the commerce platform you choose to connect, Stripe or PayPal for payment, Gelato for printing, our email provider for transactional messages, and our hosting provider.
We do not sell personal data. We do not share it for advertising. There are no advertising pixels, no analytics profiling and no third-party trackers on this site.
We use only what the site needs to work: a session cookie to keep you signed in where relevant, and a token that lets you return to an unfinished poster. No advertising or cross-site tracking cookies are set, which is why this site does not ask you to accept any.
When you import an order, the details of your customer are your responsibility under your own privacy policy and your agreement with your commerce platform. We act as your processor: we use that data only to build the record you asked for, we keep it for the periods above, and we do not use it for anything else.
Because the printed record reduces a person to a city and country, and because their name and contact details are never retained, printing one does not publish anything that identifies your customer.
Depending on where you live — including under the UK and EU GDPR, the Australian Privacy Act, and California law — you may have the right to access the personal data we hold about you, correct it, have it deleted, object to or restrict how we use it, receive a portable copy, and complain to your data protection authority.
Write to hello@the1stsale.com and we will respond within one month. There is no charge, and asking costs you nothing else.
There is no “do not sell my personal information” link on this site because there is nothing to opt out of: we do not sell it.
Traffic is encrypted in transit. Credentials are held outside the public web root and are never committed to source control. Passwords are stored only as hashes. The strongest protection here is structural rather than procedural: the data we never keep cannot be exposed, and access tokens, customer names and street addresses are all in that category.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and the relevant authority as the law requires.
Our providers operate internationally, so your data may be processed outside your country. Where that happens we rely on the safeguards those providers maintain, including standard contractual clauses where they apply.
This is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
If we change how data is handled, we will update this page and the date at the top of it. Material changes will be notified by email where we hold an address for you.
Questions, requests and complaints: hello@the1stsale.com.
EVERY CLAIM ON THIS PAGE DESCRIBES HOW THE SOFTWARE ACTUALLY BEHAVES