Who controls your data
OrderFiles is operated by Far Horizons OÜ, Sepapaja 6, Tallinn, 15551, Estonia. You can contact us about privacy questions or data rights at privacy@farhorizons.io. Product support is available at support@orderfiles.app.
We do not sell personal information. We process data to provide the product, secure accounts, deliver files, bill customers, support users, understand product health, and comply with legal obligations.
What OrderFiles collects
OrderFiles collects the minimum data needed to let sellers host files, connect commerce channels, and give buyers access to purchased digital products.
Seller account and shop data
Email address, authentication identifiers, shop names, shop slugs, inbound delivery addresses, settings, brand colors, logos, product details, and onboarding or subscription state.
Uploaded content
Digital files, product images, thumbnails, file names, file sizes, MIME types, and S3 object keys needed to host and deliver seller products.
Buyer and order data
Order numbers, buyer emails, buyer usernames when present, product titles, and forwarded marketplace order email content used to match buyers with the files they purchased.
Download records
Download timestamps, order IDs, file IDs, user agents, and a salted SHA-256 hash of the buyer IP address. We store the hash instead of the raw IP in download analytics.
Billing and subscription records
Stripe customer and subscription identifiers, subscription status, trial dates, billing period dates, and cancellation state. Card details are handled by Stripe, not OrderFiles servers.
Diagnostics, analytics, and support
Error reports, performance traces, sampled session replays, product analytics, support messages, and operational logs used to keep OrderFiles reliable and secure. Product analytics record the pages you open, what you click, and a small set of named product events — signing up, starting a trial, creating a shop or a listing, delivering a file. While you are signed in as a seller, those events carry your account ID, email address, and name. Buyers are never identified this way.
Acquisition attribution and free-tool leads
A first-party cookie records how a visitor first found OrderFiles — campaign tags from the link they clicked, the referring site's hostname, the first page they landed on, and the ad platform's click identifier when the link was a paid advertisement — and is linked to an account only if that visitor signs up. If you ask a free tool (such as the Etsy file checker) to email you your results, we store that email address, the consent timestamp, and the check's summary counts (never your file names) until you unsubscribe.
Buyer downloads
Buyers reach OrderFiles through seller-provided download links or branded download pages. To verify and deliver a purchase, OrderFiles may process the buyer email, order number, buyer username when present, product title, selected files, download timestamp, browser user agent, and a salted hash of the buyer IP address.
Download records help sellers confirm delivery, troubleshoot customer support issues, detect abuse, and understand whether files were accessed.
Connected services and processors
OrderFiles uses third-party processors to run the product. The exact processors involved depend on which features a seller uses.
Clerk
human account authentication and sessions
Stripe
subscription billing, checkout, and payment records
Shopify
OAuth connections and order webhooks for connected shops
Mailgun
inbound marketplace order email forwarding
Resend
transactional emails such as download links
Amazon Web Services S3
file, image, and thumbnail storage
Neon
PostgreSQL application database hosting
Sentry
error monitoring, traces, and sampled Session Replay
Umami
website and product analytics
PostHog
product analytics, processed in the European Union
advertising measurement, only after you accept
Session replay and analytics
OrderFiles uses Sentry for error monitoring and sampled Session Replay so we can diagnose production bugs. Current replay sampling records a small share of normal sessions and sessions that hit errors. Replays may include page interactions, but rendered text and input values are masked and media is blocked by default. We use replays only for debugging, security, and product reliability work.
OrderFiles also uses self-hosted Umami analytics to understand product usage and page performance. Umami is cookieless: it sets no cookies, collects no personal information, and does not track you across other sites.
Product analytics run on PostHog, which can also capture session recordings — a replay of what happened on screen during a visit. Our own code masks every input value before it leaves your browser, so anything you type arrives as dots rather than text. That masking is set in the app itself, not in a dashboard someone could quietly change.
What PostHog does collect is the pages you open, the clicks and form interactions on those pages, and the named product events listed above. Your browser sends this to orderfiles.app/ingest, which passes it to PostHog's European Union region — the data is processed in the EU, not the United States. While you are signed in as a seller, PostHog links those events to your account ID, email address, and name, so we can tell whether a change actually helped real sellers. Buyers on download pages are counted, never identified. PostHog sets one cookie, which is described in the Cookies section below.
Analytics and diagnostics are not used to sell personal information.
Cookies
Sign-in cookies aside, nothing is set until you choose. The banner on your first visit asks once, your answer is remembered in a cookie named of_consent, and declining means the analytics and advertising cookies below are never written. You can change your mind by clearing your cookies for this site, which brings the banner back.
OrderFiles sets no third-party advertising or tracking cookies. Four kinds of first-party cookies exist:
- Authentication cookies from Clerk keep sellers signed in. These are strictly necessary to operate an account.
- One attribution cookie (of_attr, valid 90 days) remembers how a visitor first found OrderFiles: campaign tags from the link they clicked, the referring site's hostname, the first page they landed on, and — if they arrived by clicking an advertisement — the click identifier the ad platform put in that link. It does not follow you to other sites, is never shared, and is read once: to record the acquisition source if that visitor later creates an account. What it stores is only ever what was in the link you clicked.
- One consent cookie (of_consent, valid one year) records the choice you made on the banner. It holds nothing but that answer, and it is the only one of these written without asking, because remembering that you declined is the whole point of it.
- One product analytics cookie from PostHog (named ph_…_posthog, valid 365 days) holds the ID that ties your page views and clicks together into a single visit, the campaign tags from the link you clicked, and the site that referred you. While you are signed out that ID is anonymous; once you sign in as a seller it becomes your account ID. PostHog stores this on orderfiles.app rather than on a PostHog domain, and it does not follow you to other sites.
Retention and deletion
- Seller account, shop, product, and file data is retained while the account or shop is active and while needed for delivery, support, billing, security, or legal obligations.
- Sellers can request account deletion from OrderFiles settings. The request disables the account and shops immediately, cancels Stripe renewal at period end when a Stripe subscription exists, and schedules retained application database rows and stored files for hard deletion 30 days after subscription access ends.
- Sellers can download a JSON account export from OrderFiles settings before requesting deletion. The export includes account, shop, product, file metadata and download links, order, subscription, download event, and inbound email records associated with the seller's shops.
- Forwarded order emails, parsed order records, download records, and billing records may be retained as operational records while needed to provide the service, prevent abuse, resolve support issues, or meet legal obligations.
- Stripe, accounting, tax, fraud prevention, security, legal, backup, and processor records may follow the retention periods in the Far Horizons OÜ privacy policy or the relevant processor policy.
- Backups are purged on the schedules described in the Far Horizons OÜ privacy policy.
Your rights
Far Horizons OÜ applies privacy rights consistently, including access, correction, erasure, restriction, objection, portability, complaint, and non-discrimination rights where applicable. To exercise those rights for OrderFiles data, email privacy@farhorizons.io, or use the export and account deletion controls in OrderFiles settings.
For the full company policy, including international transfer, deletion, and request-verification details, read the Far Horizons OÜ privacy policy.