Privacy Policy
How Pickadoodl handles information when you use it with your Shopify store.
Last updated: October 8, 2026
Pickadoodl is built and operated by DrippinCode LLC ("I", "me"). Your privacy is important to me. This policy covers the Pickadoodl Shopify app and this website. My other apps are covered by the DrippinCode privacy policy.
How Pickadoodl works
Pickadoodl helps you filter, group, and print pick lists, guides picking and packing through to fulfillment, optionally buys shipping labels, and handles returns and restocking. It operates within your Shopify store through Shopify's APIs. I do not use advertising trackers or analytics cookies in the app.
What Pickadoodl stores
To run a pick and pack batch (build the pick list, track picking and packing progress, let you reprint or look back at a past batch), Pickadoodl saves a record of that batch in its own database. The record includes order-level details needed to do the job: product, SKU, quantity, and bin location, plus, for the orders in the batch, the shipping and billing name and address and the order note. If your staff leave a note on an order in Pickadoodl (for example, "double-box this one"), that is stored too, tied to the order number.
Pickadoodl also stores what it needs for the rest of its workflow:
- your settings, such as bin-location fields, barcode aliases, and ship-by rules;
- a staff roster of names, with an optional PIN stored only as a one-way hash;
- records of any shared picker links you create, stored as a one-way hash and never as the raw link;
- if you use Returns, each return's items, quantities received and restocked, the reason you chose, any note you add, and a history of restocks written back to Shopify inventory;
- your usage count for the month, to apply your plan's order limit.
Packing photos. If you turn on photo capture while packing, the photos your packers take are stored in encrypted cloud storage on Amazon Web Services, tied to the batch and order, and are deleted automatically 90 days after they are taken. You or your staff can delete a photo sooner from within the app.
Shipping labels (Pro plan). If you connect an EasyPost account, Pickadoodl stores your EasyPost API key encrypted, and it is never shown again after you save it. It also stores your optional ship-from address, your box sizes, and, for orders in a batch, the weight and box you entered, the shipping rates returned, and the purchased label's tracking number, carrier, and label link. Postage is billed to you by EasyPost; Pickadoodl does not handle payment for postage.
Slack alerts. If you set up Slack alerts, the Incoming Webhook URL you provide is stored encrypted.
This data stays in Pickadoodl's own database. I do not sell it, and I do not use it for anything other than running the app for your store. It persists until it is deleted under the rights below or until you uninstall the app.
Third parties
I do not sell your data or your customers' data. A few services process data to run the app:
- Amazon Web Services stores packing photos (if you turn that feature on) and delivers the alert and digest emails you opt into.
- EasyPost, only if you connect your own account and choose to buy a label. To get rates and buy a label, Pickadoodl sends EasyPost the recipient's name, address, and, if the order has them, phone number and email, along with your ship-from address and the parcel's weight and dimensions. EasyPost's own privacy policy governs what it does with that information, and your relationship with EasyPost is your own.
- Slack, only if you configure alerts. Alerts that Pickadoodl posts to your Slack channel include batch names and status, and are governed by Slack's policies and your workspace settings.
- Shopify. Shopify's privacy policy governs how your store's data is handled within their platform, including any Shopify Flow workflows you build using Pickadoodl's triggers.
Your rights and data requests
Pickadoodl supports Shopify's standard data-request and redaction webhooks:
- If a shopper asks for their data to be deleted, I remove their identifying details (shipping and billing address, order note, and any stored shipping label link and rates) from that order's stored records. Operational details not tied to them personally, such as SKU, quantity, and bin, stay, since they describe legitimate fulfillment history.
- If you uninstall Pickadoodl, your store's stored records (batches, notes, returns, restock history, shipping data, sessions) are deleted within about 48 hours, and your EasyPost key is cleared on uninstall. Any packing photos are removed automatically within 90 days of when they were taken.
- If a shopper asks for a copy of their data, I check what is stored for their orders and follow up through you, the merchant, because I do not have a direct relationship with your customers.
You can also contact me any time if you would like your store's data removed sooner.
Security
The records Pickadoodl keeps live in databases I control and do not share access to. Sensitive values such as your EasyPost API key and Slack webhook URL are encrypted at rest, and packing photos are kept in private, encrypted cloud storage. No system is perfectly secure, but I take reasonable steps to protect the information the app holds.
Changes to this policy
If I change how I handle data, I will update this page and provide notice within the app.
Contact
Questions about this policy, or want your store's data removed? Email support@drippincode.com.