Privacy Policy — ComplianceKit
This policy explains what personal data ComplianceKit processes, why, on what legal basis, and what rights you and your customers have. It applies to:
- Merchants — the store owners who install the app, and
- Customers of those merchants — whose order, contact, and consent data the app processes on the merchant's behalf.
ComplianceKit is a processor of customer data on behalf of the merchant (controller). For merchant account data, the app is a controller. This split is reflected throughout.
1. Who we are
ComplianceKit is a Shopify app developed and operated by Kashif Khan ("we", "us"). Our app URL is https://compliance-kit-gules.vercel.app. You can reach us at kuka7466@gmail.com for any privacy request.
2. What we process and why
2.1 Merchant data (controller role)
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Store name/domain, Shopify shop ID, email of installing staff | Account setup, support, billing | 6(1)(b) contract performance |
| Billing/subscription status via Shopify Billing API | Plan management, invoicing | 6(1)(b) contract |
| SMTP/Resend credentials, sender address | Email delivery of statutory notices | 6(1)(b) contract; stored encrypted (AES-256-GCM, per-shop PBKDF2 key) |
| Admin locale preference | Localized dashboard | 6(1)(f) legitimate interest |
| IP address, user agent, timestamps | Security audit trail, abuse prevention | 6(1)(f) legitimate interest |
2.2 Customer data (processor role — on behalf of the merchant)
| Data | Purpose | Notes |
|---|---|---|
| Order number, order line items, totals, order dates | Enabling the EU right of withdrawal (Directive 2023/2673 Art. 11a): order lookup, withdrawal deadlines, receipts | Retrieved from Shopify only after the customer proves ownership (email match + one-time code) |
| Customer name and email | Delivering OTP codes, statutory confirmation-of-receipt emails, approval/return emails | Supplied by the customer in the withdrawal or DSAR form |
| Withdrawal declaration details (items, timestamps, reference number) | Statutory record-keeping and fulfillment | Durable receipt required by EU law |
| DSAR request data (requested data, export file) | Fulfilling GDPR Art. 15 access requests | Export delivered via a one-time, expiring download token; stored in private object storage |
| Consent choices (cookie/TCF v2.3 consent, TC string) | Demonstrating valid consent under ePrivacy/GDPR | Stored with timestamp, IP hash, user agent |
| IP hash (not raw IP), user agent | Fraud/abuse prevention on the public withdrawal form | Non-reversible hash, never used for profiling |
The app never stores payment card numbers, bank details, or any PCI data — payment processing is handled entirely by Shopify.
3. Legal bases summary
- Contract (6(1)(b)): providing the app and its features.
- Legal obligation (6(1)(c)): maintaining withdrawal/DSAR records required by EU law.
- Legitimate interest (6(1)(f)): security logging, rate limiting, abuse prevention, product improvement.
- Consent (6(1)(a)): where a storefront banner collects cookie consent (with TCF v2.3 support for programmatic advertising), consent is recorded and can be withdrawn anytime via the banner or cookie settings page.
4. Who we share data with (processors / sub-processors)
| Processor | What they see | Why |
|---|---|---|
| Shopify Inc. | Standard app connection data | App platform, order/customer API, billing, hosting of the app's storefront embed |
| Vercel Inc. | Server logs, hosted app code | Hosting and serverless functions |
| Neon (Postgres) | Database contents | Production database |
| Inngest | Job payloads (withdrawal/DSAR events) | Background jobs (PDF receipts, price snapshots, recall polling) |
| Merchant's email provider (Resend or their SMTP server) | Recipient address + email content | Sending statutory emails (configured by the merchant) |
| Upstash (optional) | Rate-limit counters only | Distributed rate limiting, if enabled |
| Sentry (optional) | Error messages and stack traces | Error monitoring, if a DSN is configured — no customer PII by design |
We do not sell personal data. We do not share data with third parties for their own advertising.
5. Retention
- Withdrawal declarations: kept for the merchant's statutory retention period (EU consumer-contract rules; at minimum the merchant's tax/record-keeping obligation, typically 6–10 years). The merchant controls deletion.
- DSAR exports: retained for the statutory download window, then deleted; the underlying DSAR record is retained per merchant policy.
- Consent logs: retained per merchant policy (min 6 months) to evidence consent.
- Audit logs (IP hash, user agent): at least 6 months.
- Merchant account data: until the app is uninstalled; then deleted within 30 days (except records the merchant is legally required to keep, e.g. open withdrawal cases).
6. Security
- All traffic is HTTPS/TLS; Shopify tokens are expiring offline tokens with auto-refresh, stored encrypted in the database.
- Merchant email secrets are encrypted at rest (AES-256-GCM, per-shop key derived via PBKDF2); never stored in plaintext.
- Public endpoints are rate-limited (per shop + IP) with fail-closed declaration submissions and fail-open lookups by design.
- Withdrawal lookups require email-match + one-time code (OTP) verification.
- DSAR exports are one-time token-gated downloads with expiry and a download counter.
- An incident response policy is in place; S1 breaches are reported to Shopify and the relevant authorities within applicable legal timeframes.
7. Your rights (customers)
If you are a customer of a merchant using ComplianceKit, you exercise your rights (access, rectification, erasure, restriction, portability, objection) through the merchant — they are the controller of your order data. The app provides the merchant the tooling (e.g. the DSAR module) to fulfill those requests. You can always contact the merchant directly; if they use our DSAR tool, they can export and deliver your data to you.
8. Your rights (merchants)
You may request access to, correction, or deletion of your account data at any time via kuka7466@gmail.com. Uninstalling the app triggers data deletion as described in §5.
9. International transfers
Primary processing is in the EU/US via the processors listed in §4. Transfers rely on standard contractual clauses / the processors' DPA commitments (Vercel, Neon, Shopify, Inngest). No data is transferred to non-adequacy jurisdictions without appropriate safeguards.
10. Cookies and similar technologies
The app's storefront widget sets only the minimal cookies required for consent management and displays a configurable cookie banner (with IAB TCF v2.3 support where the merchant enables it). The banner lets visitors accept/decline and review vendors. Detailed vendor lists are fetched from the IAB Europe GVL. Merchants control banner text, colors, and TCF settings in the app.
11. Children
The app is not directed at children under 16 and does not knowingly process their data.
12. Changes
We will notify merchants of material changes via the app dashboard or email at least 14 days before they take effect.
13. Contact & supervisory authority
Privacy questions: kuka7466@gmail.com. You also have the right to lodge a complaint with your local data protection authority.