This policy explains how Shadow COD ("we", "the app") handles data when a Shopify merchant ("you", "the merchant") installs and uses the app, including limited personal data about the merchant's customers ("buyers"). We act as a data processor on behalf of the merchant (the data controller) with respect to buyer data.
We request the minimum Shopify scopes needed to provide the service:
| Data | Shopify scope | Purpose |
|---|---|---|
| Orders (payment method, fulfilment/delivery status, tags, cancellation/refund status, order value, timestamps) | read_orders | Determine each COD order's outcome (delivered/returned) to build the per-store risk memory |
| Customer identifiers (name, email, phone) and customer id | read_customers | Recognise a returning buyer and match orders to a buyer |
| Customer tags | write_customers | Add/remove the cod-blocked tag that drives checkout behaviour |
| Payment customizations | write_payment_customizations | Hide the COD option at checkout for risky buyers |
We use Shopify Protected Customer Data at the level required for the above and for no other purpose.
We use the following infrastructure providers to run the service:
us-east-1).A current sub-processor list is available on request at vaynoxstudio@gmail.com.
customers/redact we erase the identified buyer's records.shop/redact (sent by Shopify ~48 hours after uninstall) we erase all of that store's buyer data.shop/redact.customers/data_request we provide the merchant the data we hold about the identified buyer.Data is processed primarily in the United States (Render; Neon — AWS us-east-1; Upstash). Where required, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) with our sub-processors.
Buyers should direct requests to the merchant (the controller). We assist merchants in fulfilling access/erasure requests via Shopify's data-request/redaction webhooks and, if needed, on request to vaynoxstudio@gmail.com.
Encryption at rest for PII, hashed blind-index matching, per-store isolation enforced in code, least-privilege scopes, and encrypted transport (TLS) to all providers. Report security concerns to vaynoxstudio@gmail.com.
We support merchants' compliance with applicable data-protection law, including India's Digital Personal Data Protection Act, 2023 (DPDP), the EU/UK GDPR, and the CCPA, in our role as processor.
We may update this policy; material changes will be posted at this URL with a new "last updated" date.
Vaynox Studio, India — vaynoxstudio@gmail.com