Privacy Policy
EU Shield GDPR — Shopify app · Last updated: 15 July 2026
EU Shield GDPR (“the App”, “we”, “us”) is a Shopify application provided by
SC COVERED SRL, Str. Principala nr. 98, Strei, Hunedoara, Romania. This Privacy Policy explains
what personal data the App processes when a merchant installs and uses it, and how we protect it. For the data
the App handles on a merchant’s behalf, the App acts as a data processor and the merchant
is the data controller.
1. Data we process
- Store data: shop domain, subscription plan, and the settings you configure in the App.
- Order data: order numbers and line items, read from the Shopify Admin API when a customer
looks up an order to request a return or withdrawal. We do not store more than the request needs.
- Customer personal data (on the merchant’s behalf): email address, name, and — where the
merchant enables it — a bank account/IBAN for refunds, submitted through the return/withdrawal and DSAR portals.
Sensitive fields (emails, bank details) are encrypted at rest with AES-256-GCM.
- Consent records: a log of cookie-consent choices. These contain no raw identifiers
— a visitor is identified only by a salted one-way hash; we never store IP addresses or fingerprints in the clear.
- Detected third-party scripts: technical signatures of scripts/pixels found on the storefront
by the cookie scanner.
The App does not sell personal data and does not use it for advertising.
2. Why we process it
- To provide the App’s features (cookie consent, returns & right of withdrawal, DSAR, legal pages, GPSR, health check).
- To send transactional emails tied to those features (e.g. return confirmations, DSAR verification links).
- To comply with legal obligations and Shopify’s platform requirements.
3. Where data is stored & security
- Data is stored in a PostgreSQL database hosted on Railway.
- In transit: all traffic uses HTTPS/TLS.
- At rest: the database is encrypted by the hosting infrastructure, and the most sensitive fields
(customer emails, bank details) are additionally encrypted at the application layer (AES-256-GCM).
- Access is limited to the App’s operators.
4. Sub-processors
- Shopify — the platform the App runs on (store, order, and customer data).
- Railway — application hosting and database.
- Resend — delivery of transactional emails.
5. Data retention & deletion
- Consent logs: kept for the retention period the merchant configures (3, 12, or 36 months), then purged.
- Return/withdrawal & DSAR records: retained while needed to handle the request and to meet legal obligations, then deleted.
- Mandatory GDPR webhooks: the App honours Shopify’s
customers/data_request,
customers/redact, and shop/redact webhooks. On customers/redact the
customer’s stored personal data is deleted/redacted; on uninstall and shop/redact the store’s data is removed.
6. Data subject rights
Because the App processes personal data on the merchant’s behalf, customers should exercise their rights
(access, rectification, erasure, restriction, portability, objection) with the merchant (data controller).
The App provides a built-in DSAR portal to help merchants handle these requests, and a self-service data-request page for customers.
7. International transfers
Where a sub-processor processes data outside the European Economic Area, we rely on Standard Contractual Clauses
or another safeguard recognised under the GDPR.
8. Changes
We may update this Policy from time to time; the “Last updated” date above reflects the latest version.
9. Contact
For any privacy question or request regarding the App, contact SC COVERED SRL at
xpapion@gmail.com.
This policy describes the EU Shield GDPR application. It is not legal advice.