Devang Patel ("we", "us")
Effective: 30 September 2026
This policy explains what personal data the Estimated Delivery Date Shopify app processes, why, and for how long. It covers two groups of people: the merchants who install the app, and the customers who shop on those merchants' stores.
We are the controller of merchant data and the processor of customer data — the merchant is the controller of their own customers' data. We process customer data only on the merchant's behalf, only to provide the app's features to them, and only in the ways this policy describes.
Estimated Delivery Date displays an estimated delivery date on a merchant's storefront and measures how accurate those estimates turn out to be. To measure accuracy, it records the delivery window shown at the time an order is placed, then compares it against the fulfilment and delivery dates reported by the carrier.
Collected when a merchant installs the app, via Shopify OAuth:
| Data | Purpose |
|---|---|
| Store domain and Shopify shop ID | Identifying the installation |
| Shopify access token | Calling the Shopify API on the store's behalf |
| Staff first name, last name and email address | Identifying the signed-in user of the app |
| Account owner, collaborator and locale flags | Rendering the admin correctly |
| Plan and entitlement state | Applying the subscription tier |
The in-app support chat (tawk.to) receives the store name, store contact email and store domain so we can tell which store a chat comes from, plus anything the merchant types into it. It runs only in the app's admin, never on the storefront.
We do not use merchant data for advertising and we do not sell it.
We do not store anything that directly identifies a shopper. No name, no email address, no phone number, no street address.
We do store the shopper's Shopify customer ID — a pseudonymous number issued by Shopify. It is a personal identifier, so we treat it as personal data. It exists for one reason: it is what proves a signed-in shopper is asking about their own order when the order status page reads back their delivery window. Without it, any signed-in shopper could read anyone else's.
What we store is order-linked:
| Data | Purpose |
|---|---|
| Order ID and order name | Linking an estimate to the order it was shown for |
| Shopify customer ID | Authorising a shopper to read back their own delivery window, and nobody else's. Absent for guest checkouts |
| Line item, product and variant IDs | Applying per-product rules |
| The delivery window we displayed, and the dispatch date | The record of what the shopper was promised |
| Order timestamp | Reproducing the estimate as it stood at order time |
| Fulfilment and delivery timestamps | Comparing the promise against reality |
| Carrier name and tracking URL | Distinguishing a delivered parcel from one in transit |
We also read the shipping country code of an order so that country-specific delivery rules resolve the same way on the server as they did in the shopper's browser. The country code is used to compute the estimate and is not stored.
This data is still linked to an order, and therefore to a person, so we treat it as personal data and honour deletion requests for it (section 7).
write_products — To save the delivery rules a merchant sets for individual products and collections, as metafields on those products and collections.read_themes — Read-only: to check whether the merchant's live theme supports app blocks, for the setup guide. The app never changes the theme.read_orders — To receive a notification when an order is placed or fulfilled, so the app can record the delivery window it promised and measure how accurate it was. The app does not read past orders.read_fulfillments — To receive a notification when a carrier updates a shipment, so the app knows when a parcel was delivered.app/uninstalled — Deletes everything the app holds for the store: sessions, settings, estimates, fulfilment records and accuracy figures.app/scopes_update — Records the permissions the merchant granted after they change.app_subscriptions/update — Tells the app the store changed plans, so paid storefront features switch off when a plan ends. Only the plan is stored.orders/create — Records the delivery window the shopper was shown for each line item, with the order ID, order name and Shopify customer ID (section 3).orders/fulfilled — Records when the order was dispatched.fulfillments/update — Records the carrier name, tracking URL and the time the parcel was delivered.customers/data_request — Compiles what the app holds about one shopper so the merchant can answer them (section 7).customers/redact — Deletes one shopper's records (section 7).shop/redact — Sent 48 hours after uninstall: deletes anything still held for the store.Application data is held in a PostgreSQL database on a server run by netcup in Germany (EU), managed with Dokploy. The database is backed up to Cloudflare R2, which encrypts everything it stores.
Sub-processors:
| Sub-processor | Role |
|---|---|
| Shopify Inc. | Platform; source of all data the app receives |
| netcup GmbH | Server hosting, Germany |
| Cloudflare, Inc. | Encrypted database backup storage (R2) |
| tawk.to Inc. | Merchant support chat in the app admin |
We do not send personal data to any analytics, advertising or profiling service. The storefront widget makes no network requests at all — it computes the delivery date in the shopper's browser from configuration already on the page.
A shopper exercises their rights through the merchant whose store they bought from, not through us. When Shopify forwards us a request:
Merchants may contact us directly at devangfour@gmail.com.
We limit personal data to the minimum the feature requires — the reason we store no shopper contact details at all, and store the customer ID only because authorising a shopper to read their own order is impossible without it. No interface in the app exposes customer data; reaching it requires direct database access on our infrastructure, which only we have. Data is encrypted in transit and at rest, and backups are encrypted too. Every read of order-linked data is recorded in an audit log.
Material changes will be notified to installed merchants by email at least 14 days before they take effect.
Devang Patel
devangfour@gmail.com