01THE1STSALE
Create yours →

THE1STSALE

Privacy Policy

This page describes what we collect, what we deliberately refuse to keep, and what does and does not reach a printed sheet.

LAST UPDATED 19 August 2026 · THE1STSALE.COM

THE SHORT VERSION

  • When you connect a store, we hold the access token for a few seconds, use it once, and discard it. It is never written to disk.
  • From your orders we keep twelve fields. Your customer’s name, email, phone number and street address are not among them.
  • That list is cached in a single-use file that expires after fifteen minutes and is deleted the moment it is read.
  • A person never appears on a printed sheet as a name. They appear as a city and a country, if you choose to include one.
  • We do not sell anything about anyone, and we run no advertising or tracking pixels.

1. Two people, two relationships

Almost every privacy policy describes one relationship. This product has two, and keeping them apart is the honest way to explain it.

YOU

The founder. You came here deliberately, gave us an email address, and asked us to print something. Your data is handled the way any shop handles a customer’s.

YOUR FIRST CUSTOMER

A stranger to us. They bought something from you, possibly years ago, and never agreed to anything with us. They get the most conservative treatment we can give them: they are reduced to a place.

Where this policy says your customer, it means the person in the record you are framing — not you.

2. Who we are

The1stSale (“we”, “us”) operates the1stsale.com and is the data controller for the information described here. Reach us at hello@the1stsale.com.

For the record you import from a connected store, you are the controller of your own customer’s data and we act as your processor — see section 12.

3. What we collect from you

Email address
To send your order confirmation, proof and tracking, and to let you recover an unfinished poster by link.
Name and delivery address
Only when you order a physical print. Passed to our print partner so they can post it to you.
Order and payment record
What you configured, what you were charged, and the fulfilment state. We never see or store your full card number.
Unfinished builder sessions
Your poster configuration, so a half-built record survives a closed tab.

4. Connecting a store

Connecting Shopify, Stripe, Square, Etsy, PayPal, BigCommerce or eBay grants us read-only access for a few seconds. We ask for the narrowest permission each platform offers — the ability to read orders, and nothing else. We cannot alter, refund or create anything in your store, and we cannot see your products, staff, payouts or settings.

Concretely, one connection does this and then stops:

  1. You approve the connection on the platform’s own screen.
  2. We exchange the resulting code for an access token.
  3. We read your earliest orders — one request.
  4. We reduce each order to twelve fields.
  5. The token goes out of scope and is gone. It is never stored.

The twelve fields are: order number, amount, currency, date, time, product name, quantity, customer city, customer country, order status, and two flags recording whether the order looks like a test. Your customer’s name, email address, phone number and street address are never among them — they are not stored, not logged, and not printed.

That list is written to a single-use file, expires after fifteen minutes, and is deleted the moment the builder reads it. If you walk away, it expires on its own.

5. Uploading proof, or typing it in

You can attach a screenshot, invoice or confirmation email instead of connecting a store, or simply type the details yourself. Anything you upload is used once to read the order details out of it and is not kept afterwards.

Automated screenshot reading is not currently enabled. If we enable it in future, this page will say so, and will name the provider, before it processes anything.

A record you type in yourself is marked Founder recorded. A record read directly from a store over a read-only connection is marked as verified. Editing a verified record removes that mark, because the mark describes where the data came from rather than how it looks.

6. What reaches the printed sheet

The printed record can carry your business name, the order number, the amount, the date and time, the product, and a city and country. It never carries your customer’s name, email address, phone number or street address. This is a deliberate constraint in the product, not a setting you have to find: a person on a wall for decades should be a place, not a mailing address.

7. Payment

Payments are processed by Stripe and PayPal. Card details are entered on their systems and never reach our servers — we receive only the outcome, the amount, and a reference. Their handling of your data is governed by their own privacy policies.

8. Printing and delivery

Prints are produced and shipped by Gelato, which receives the finished artwork and the delivery details needed to post it to you. It does not receive anything about your business beyond what the artwork itself shows, and we send it no separate customer records.

9. Who else sees anything

Only the parties named above: the commerce platform you choose to connect, Stripe or PayPal for payment, Gelato for printing, our email provider for transactional messages, and our hosting provider.

We do not sell personal data. We do not share it for advertising. There are no advertising pixels, no analytics profiling and no third-party trackers on this site.

10. Cookies

We use only what the site needs to work: a session cookie to keep you signed in where relevant, and a token that lets you return to an unfinished poster. No advertising or cross-site tracking cookies are set, which is why this site does not ask you to accept any.

11. How long we keep things

Store access tokens
Not retained at all. Used once within a single request, then discarded.
Imported candidate list
Fifteen minutes, single use, deleted on read.
Uploaded proof
Read once, then discarded.
Unfinished builder sessions
Kept so you can return to them, and removed when stale.
Completed orders
Retained as long as tax and accounting law requires, then deleted.

12. If you are a merchant

When you import an order, the details of your customer are your responsibility under your own privacy policy and your agreement with your commerce platform. We act as your processor: we use that data only to build the record you asked for, we keep it for the periods above, and we do not use it for anything else.

Because the printed record reduces a person to a city and country, and because their name and contact details are never retained, printing one does not publish anything that identifies your customer.

13. Your rights

Depending on where you live — including under the UK and EU GDPR, the Australian Privacy Act, and California law — you may have the right to access the personal data we hold about you, correct it, have it deleted, object to or restrict how we use it, receive a portable copy, and complain to your data protection authority.

Write to hello@the1stsale.com and we will respond within one month. There is no charge, and asking costs you nothing else.

There is no “do not sell my personal information” link on this site because there is nothing to opt out of: we do not sell it.

14. Security

Traffic is encrypted in transit. Credentials are held outside the public web root and are never committed to source control. Passwords are stored only as hashes. The strongest protection here is structural rather than procedural: the data we never keep cannot be exposed, and access tokens, customer names and street addresses are all in that category.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and the relevant authority as the law requires.

15. International transfers

Our providers operate internationally, so your data may be processed outside your country. Where that happens we rely on the safeguards those providers maintain, including standard contractual clauses where they apply.

16. Children

This is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.

17. Changes

If we change how data is handled, we will update this page and the date at the top of it. Material changes will be notified by email where we hold an address for you.

18. Contact

Questions, requests and complaints: hello@the1stsale.com.

EVERY CLAIM ON THIS PAGE DESCRIBES HOW THE SOFTWARE ACTUALLY BEHAVES

01THE1STSALE

Founder artifacts for the leap from zero to one.

Privacy
© The1stSale