Shadow COD — Privacy Policy

App: Shadow COD  ·  Provider: Vaynox Studio (operating as an independent freelance business; not yet a registered company), India

Contact: vaynoxstudio@gmail.com  ·  Last updated: 16 July 2026

1. Who this policy is for

This policy explains how Shadow COD ("we", "the app") handles data when a Shopify merchant ("you", "the merchant") installs and uses the app, including limited personal data about the merchant's customers ("buyers"). We act as a data processor on behalf of the merchant (the data controller) with respect to buyer data.

2. What data we access and why

We request the minimum Shopify scopes needed to provide the service:

DataShopify scopePurpose
Orders (payment method, fulfilment/delivery status, tags, cancellation/refund status, order value, timestamps)read_ordersDetermine each COD order's outcome (delivered/returned) to build the per-store risk memory
Customer identifiers (name, email, phone) and customer idread_customersRecognise a returning buyer and match orders to a buyer
Customer tagswrite_customersAdd/remove the cod-blocked tag that drives checkout behaviour
Payment customizationswrite_payment_customizationsHide the COD option at checkout for risky buyers

We use Shopify Protected Customer Data at the level required for the above and for no other purpose.

3. What we store, and how it's protected

4. What we do NOT do

5. Sub-processors

We use the following infrastructure providers to run the service:

A current sub-processor list is available on request at vaynoxstudio@gmail.com.

6. Data retention and deletion

7. International transfers

Data is processed primarily in the United States (Render; Neon — AWS us-east-1; Upstash). Where required, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) with our sub-processors.

8. Buyer (data subject) rights

Buyers should direct requests to the merchant (the controller). We assist merchants in fulfilling access/erasure requests via Shopify's data-request/redaction webhooks and, if needed, on request to vaynoxstudio@gmail.com.

9. Security

Encryption at rest for PII, hashed blind-index matching, per-store isolation enforced in code, least-privilege scopes, and encrypted transport (TLS) to all providers. Report security concerns to vaynoxstudio@gmail.com.

10. Compliance

We support merchants' compliance with applicable data-protection law, including India's Digital Personal Data Protection Act, 2023 (DPDP), the EU/UK GDPR, and the CCPA, in our role as processor.

11. Changes

We may update this policy; material changes will be posted at this URL with a new "last updated" date.

12. Contact

Vaynox Studio, India — vaynoxstudio@gmail.com