Privacy notice
Pre-launch draft. Controller identity, contact details and commercial terms must be completed before accepting merchants.
What we process
Merchant account details, customer names and email addresses, order identifiers, tracking events, shipment tickets and associated communications. We avoid collecting full delivery addresses unless required for a specific investigation.
Why we process it
To monitor shipments, identify issues, prepare and deliver permitted communications, manage subscriptions and maintain service security. Merchants remain responsible for their customer notices and lawful instructions.
Service providers
Supabase provides authentication and database hosting; Shopify supplies order details; Shippo supplies tracking; OpenAI processes minimized shipment context; Resend handles email; and Vercel hosts the application. Stripe processes payment data only after paid plans are enabled. Provider agreements and international transfer arrangements must be reviewed before launch.
Retention and deletion
Processed webhook bodies are cleared. Merchant account deletion removes organisation records and linked case data. Shopify redaction requests anonymize customer identity and remove associated messages and AI records. Backup expiry follows the database provider’s retention settings.