Privacy Policy. This page is ready

Privacy Policy

Last updated: October 6, 2026

Data we process

ETADeliverPickup stores merchant configuration needed to provide delivery availability checks, including shop domain, country and postal code coverage, delivery-day rules, COD availability, cutoff time, weekend settings, and holiday dates.

Shoppers provide a country and postal code for delivery checks. Lookup analytics store a shortened postal-code region, product and variant identifiers, availability results, and timestamps. They are not linked to a customer identifier. The app database does not store shopper names, full delivery addresses, emails, payments, or orders. Shopify authentication sessions can contain merchant account identity and access credentials needed to operate the app.

Import processing can retain failed CSV row values and error details. Merchant-created delivery messages, pickup instructions, targeting values, and other free-text settings are stored as configured. Headless API tokens are stored only as hashes with a safe prefix; token scopes, origins, status, expiry and usage metadata are stored, together with shop- and token-scoped rate-limit counters. Do not upload customer lists or put personal data in imports or custom messages.

When enabled, storefront blocks read a logged-in shopper's saved address from Shopify. The full delivery postal code and estimate can be written to Shopify cart attributes and carried to order attributes for post-purchase displays. These records remain in Shopify and are managed under the merchant's Shopify data policies.

How data is used

Merchant configuration is used only to show delivery availability, estimated delivery dates, COD availability, and stock-aware messages through the storefront theme app extension.

If a merchant configures a courier provider integration, postal codes can be sent to that provider to request delivery serviceability. If no courier provider is configured, checks use only the merchant's uploaded postal code records.

Retention and deletion

When a shop requests deletion or Shopify sends a shop redact webhook, shop-owned app data is deleted from the app database. The app also responds to Shopify mandatory privacy webhooks for customer data requests and customer redaction requests. There is no customer-linked dataset in the app database to export or delete for an individual shopper. Customer requests concerning Shopify cart or order records should be handled by the merchant in Shopify. Analytics cleanup targets records older than 90 days during lookup activity; inactive shops may retain older records until cleanup or shop deletion occurs.

Security

The app uses Shopify OAuth, session-token based embedded app authentication, App Bridge, HTTPS in production, and Shopify webhook verification. Headless API tokens are stored as hashes; private tokens should never be exposed in a shopper browser. Hosting access controls, backup retention, and restoration policies must be maintained by the app operator.

Hosting and database providers may retain operational error logs, backups, and request metadata under their configured policies. The app does not intentionally log request bodies, raw API tokens, or credentials. Shop deletion webhooks do not erase provider backups or third-party logs; the operator must maintain separate retention and redaction procedures.

Contact

Data controller: BM Consulting Pvt Lmt.

For privacy or support requests, contact [email protected].