Privacy Policy for the App. This page is ready

Privacy Policy for the App

1. Controller

The controller responsible for data processing in connection with the use of this app is:

the node
Oliver Lindenlauf
Salmstraße 91
51105 Köln
Germany
E-Mail: [email protected]

2. Nature of the app and roles under data protection law

(1) The “Warehouse Rocket” app is installed by Shopify merchants (“Merchants”) in their stores to support shipping processes (e.g., creation of shipping labels, fulfillments, shipping notifications).

(2) With regard to personal data of end customers (buyers in the store), the Provider typically acts as a processor on behalf of the Merchant. The Merchant remains the controller under the GDPR for processing customer data in their store.

(3) With regard to the Merchant’s own data (e.g., contact details, configuration data, app usage data), the Provider acts as the controller under the GDPR.

3. Data processed

When using the app, the following data may be processed in particular:

a) Store and order data (via Shopify API)
• Shop domain, shop ID, currency, language
• Order data (order ID, order number, line items, prices, shipping method, payment status)
• Shipping addresses (name, street, postal code, city, country, optionally phone number, email)
• Fulfillment information and tracking numbers

b) Warehouse and shipping configuration
• Warehouse information (name, address, email)
• App settings (e.g., shipping mode auto/manual, DHL EKP, DHL billing number, DHL username/password, preferred language)

c) Log / request data
• Timestamps and contents of dispatch requests
• Status changes (e.g., “approved”, “fulfilled”)
• technical logs (error messages, API responses, server IP address, user agent)

d) Communication data
• Email addresses of warehouses or contacts to which shipping labels or status emails are sent
• Content of notifications sent (e.g., order number, tracking information)

4. Purposes of processing

Processing is carried out in particular for the following purposes:

• Providing the app’s functions within the Merchant’s Shopify store,
• Creating and managing shipping labels (e.g., DHL),
• Transmitting tracking information to Shopify and/or the Merchant,
• Sending notifications to warehouses / fulfillment partners,
• Logging shipping events for troubleshooting and traceability,
• Ensuring technical stability and security of the app.

5. Legal bases

(1) For processing customer data on behalf of the Merchant, processing is based on Art. 28 GDPR (processing) and—typically from the Merchant’s perspective—on Art. 6(1)(b) GDPR (performance of a contract) and/or Art. 6(1)(f) GDPR (legitimate interest in efficient shipping and logistics).

(2) For processing the Merchant’s own data (e.g., configuration, login information, support), processing is based on Art. 6(1)(b) GDPR (performance of a contract) and, where applicable, Art. 6(1)(f) GDPR (legitimate interest in operating, securing, and improving the app).

6. Recipients of data

(1) To fulfill the purposes stated above, the Provider may use the following categories of recipients:

• Shopify Inc. / Shopify International Ltd. (hosting the store platform, providing APIs),
• Shipping carriers (e.g., DHL) where data is transmitted for label creation and shipment data,
• Email providers / transactional email services for sending notifications,
• IT service providers and hosting providers for operating the app (e.g., EU-based hosting).

(2) Where data is transferred to third countries outside the EU/EEA, this will only take place in compliance with applicable legal requirements (e.g., adequacy decision, standard contractual clauses).

7. Retention periods

(1) Log data (logs, shipping events) is stored only as long as necessary to fulfill the purposes stated and is then deleted or anonymized. Typical retention periods may be, for example, [X days / X months].

(2) Configuration data (e.g., DHL credentials, settings) is stored for as long as the Merchant has the app installed. When the app is uninstalled, this data is generally deleted within a reasonable period, unless statutory retention obligations require otherwise.

(3) The Merchant may request deletion of certain data, provided no statutory obligations conflict with this.

(4) Data stored in connection with the use of the app for shipping and logistics processes (in particular order data in the “Order” model, line items in the “OrderItem” model, dispatch requests in the “DispatchRequest” model, and related event logs in the “RequestEvent” model) is generally retained only as long as necessary for the respective shipping and documentation purposes. Typically, this data is deleted or anonymized no later than 90 days after completion of the respective shipping process, unless longer statutory retention periods apply.

(5) Shop-related configuration data (the “ShopConfig” model), in particular settings for shipping handling and stored credentials for carriers, is deleted at the latest after uninstalling the app or upon receipt of a deletion request via Shopify privacy webhooks (e.g., shop/redact), unless statutory retention obligations apply.

8. Rights of data subjects

Data subjects (in particular end customers and Merchants) have the following rights under the GDPR:

• Right of access (Art. 15 GDPR),
• Right to rectification (Art. 16 GDPR),
• Right to erasure (Art. 17 GDPR),
• Right to restriction of processing (Art. 18 GDPR),
• Right to data portability (Art. 20 GDPR),
• Right to object (Art. 21 GDPR).

Requests may be addressed to [email protected]. End customers are typically referred to the respective Merchant, as the Merchant is the primary controller for store data.

9. Security of processing

(1) The Provider implements appropriate technical and organizational measures to protect processed data against loss, misuse and unauthorized access (e.g., access restrictions, encryption, regular updates).

(2) The specific measures are regularly reviewed and adapted to the state of the art.

10. Shopify-specific aspects

(1) The app accesses store and order data via Shopify’s APIs. Use of these interfaces is subject to Shopify’s API terms and policies.

(2) Further information on Shopify’s own data processing can be found in Shopify’s privacy policy.

11. Changes to this privacy policy

The Provider may update this privacy policy if required due to technical changes to the app, changes in law, or other reasons. The current version is available at Privacy.

12. Deletion upon app uninstall and Shopify data deletion requests

(1) If the app is uninstalled in the Merchant’s Shopify admin, the Provider receives the Shopify webhook “app/uninstalled”. In this case, all shop-related data stored in the app database is generally deleted. This includes in particular:

• Configurations in the “ShopConfig” model (e.g., shipping mode, language, carrier credentials),
• Order data in the “Order” model,
• Line items in the “OrderItem” model,
• Dispatch requests in the “DispatchRequest” model,
• Event logs in the “RequestEvent” model associated with these orders and dispatch requests.

(2) In addition, the Provider participates in Shopify’s privacy and deletion mechanisms. In particular, the following webhooks are processed:

• “customers/redact”: Deletion of order and shipping data that can be associated with a data subject (e.g., via Shopify-provided order IDs or email address),
• “shop/redact”: Deletion of all shop-related data in the app database (as described in paragraph 1) when requested by Shopify.

(3) If the Provider cannot independently identify the data subject beyond the information transmitted by Shopify and does not store additional personal data, implementation of the deletion requests is limited to the order, shipping, and configuration data stored in the app database.

(4) Warehouse data (“Warehouse”, “WarehouseInventory”) is processed only insofar as it does not relate to an identifiable natural person. Where a personal reference exists, the respective records are also removed or anonymized as part of the deletion processes described above.