Morph

Legal · Privacy

Privacy Policy

Last updated September 3, 2026

Morph is a 3D product configurator for Shopify stores. This policy says plainly what data the app holds, why, where it lives, and how it is erased. Morph is operated by 8th Origin LLC.

What we hold about your store

  • Store & product data — your shop domain and product details (titles, variants, options, prices), read through Shopify's Admin API to build a configurator for each product.
  • 3D model and image files — models, textures and swatches you upload go into your own store's Shopify Files (Shopify's CDN). If your store is still on its Shopify trial, Shopify does not accept 3D files, so Morph hosts the model in its own Shopify Files instead; the file is named after your store so it can be traced back and removed.
  • Configurator settings — the parts, colors, options, prices and translations you set up in the app.
  • Authentication — a Shopify access token for your store so the app can act on your behalf. We never receive your Shopify password.
  • Usage counts — which product a shopper opened, configured or added to cart, as counts. No shopper identity is attached.

What we hold about your customers

When a shopper adds a configured product to the cart, Morph keeps a build record so the item can be priced correctly at checkout and produced exactly as ordered. A build record contains:

  • the options the shopper picked, and any text they typed or image they uploaded (an engraving, a logo — the image is stored in your store's Shopify Files);
  • a photo of the configured item, rendered in the browser and stored in your store's Shopify Files;
  • after purchase, the order number and line item it belongs to.

Morph does not store the shopper's name, email, address or payment details. Those stay in your Shopify admin. If you turn on factory build sheets, the email we send you contains the order number and the build — not the customer's details.

How data is used

Solely to provide the service: rendering the configurator in your storefront, saving your settings, pricing the configured item at checkout, and giving you a production record for each order. We do not sell data or use it for advertising. Photo-to-3D generation sends the product photo you choose to our model-generation provider (fal.ai) to produce the 3D model; nothing about your customers is sent.

Where data is stored (sub-processors)

  • Shopify — your store data and every uploaded or generated file (Shopify Files/CDN).
  • Vercel — application hosting (United States).
  • Neon — encrypted Postgres database (United States) for your settings, the app's session records and access tokens for your store, build records and usage counts.
  • fal.ai — photo-to-3D generation, only for photos you submit for that feature.
  • Resend — delivery of factory build-sheet emails to the address you set, if you turn that feature on.

Retention, deletion & your customers' rights

  • Uninstall — your store's settings, build records and usage counts are erased when Shopify sends its shop-redact notice, 48 hours after uninstall.
  • Customer erasure — when Shopify sends a customer-redact request for an order, Morph removes the shopper's typed text, uploaded-image link and build photo from every build record on that order. The picked options stay, as your production record.
  • Customer data requests — when Shopify sends a customer data request, Morph records which build records are involved so you can pass the customer what Morph holds; email us and we will assemble it with you.
  • Unordered builds — build records that never became an order (abandoned carts) are deleted after 90 days.
  • You can ask us to delete anything at any time by email.

Security

Data is transmitted over HTTPS. Access is scoped to the Shopify permissions the app needs (products, files, orders for the build record). Every configured build is signed so a cart cannot be altered to underpay. Database access is restricted and credentials are never exposed to the browser.

Changes

We may update this policy as the app evolves. Material changes will be reflected here with a new "last updated" date.


Questions? Email danny@8thorigin.com.