Data Protection & Security
It's your money and your customers' data. Here's exactly how ShipOps handles both, and how requests to access or erase data are fulfilled.
Our data-protection principles
- Collect the minimum. We store only what's needed to run COD delivery operations, and we keep a PII-minimized copy of Shopify order data (city only, no street address on that record).
- Read-only where possible. Courier tracking data is accessed read-only using your own token; we write back to Shopify only what you explicitly enable.
- No selling, no profiling. We never sell personal data and never use it for advertising or profiling.
- Delete on request. Erasure requests are honored promptly and completely, including the raw courier payloads that contain personal data.
- Consent and opt-out. Marketing messages go only to customers who opted in at checkout; every channel honours a "stop" permanently, as WhatsApp's Business Messaging Policy and Pakistan's electronic-communications law require. Transactional messages relate to an order the customer placed.
Protected Customer Data
To run a COD delivery, ShipOps processes the customer's name, phone number, and shipping address. These are classed as Protected Customer Data under Shopify's requirements. We access them only to identify and act on parcels — showing the action inbox, confirming orders and updating customers by automated call, SMS and WhatsApp in the merchant's name, answering their replies, and matching payout receipts to orders. We do not collect customer email addresses, and we do not transmit customer PII to the courier (the courier already holds it as the delivering carrier). The content of messages exchanged with a customer is stored encrypted and erased with the customer.
Security measures
- Encryption in transit: all traffic is served over TLS.
- Encryption at rest: customer name, phone, address, message content and every API token are encrypted with AES-256-GCM; the key lives outside the database and the app fails closed without it.
- Embedded in Shopify: the app runs inside the Shopify admin using Shopify's session and authentication.
- Access control: access to production data is limited to authorized operators.
- Tenant isolation: each store's data is scoped to that store; uninstalling immediately stops background syncing.
Mandatory data-request webhooks
ShipOps implements the three Shopify compliance webhooks:
customers/data_request— we compile the data we hold about a customer and make it available to the store owner within 30 days.customers/redact— we erase that customer's name, phone, and address, plus the raw courier payload containing them.shop/redact— sent by Shopify about 48 hours after uninstall; on receipt we permanently delete all data we hold for that store, except a minimal installation record (store domain + first-install / last-uninstall dates, no customer or order data) kept so plan limits stay consistent across a reinstall — see the privacy policy.
Sub-processors
- Shopify — the platform ShipOps is embedded in and the source of order data.
- Your courier partner (e.g. PostEx) — tracking data and delivery instructions, called with your token.
- Contabo (Germany, European Union) — hosting and database, where data is stored.
- WhatsApp / Meta Platforms — when you connect your WhatsApp Business Account: customer phone numbers and message content, sent and received on your number through the WhatsApp Business Platform. (Click-to-chat from a staff member's own phone involves no ShipOps processing.)
- SMS gateway (Pakistan) — customer phone numbers and the text of SMS sent in your name.
- Automated-call provider (Pakistan) — customer phone numbers and the prompt played in your name; keypress results returned.
- AI providers (Anthropic; OpenAI as fallback) — only for the optional AI features: the address check and reply suggestions (names, phone numbers, emails and long digit strings redacted before sending) and, if you enable payment verification, customer-posted payment screenshots and the redacted text of your bank-alert emails. No retention and no training on your data.
- Zoho ZeptoMail — email notifications to the merchant only.
Making a data request
Customers should direct access or deletion requests to the merchant (the data controller). Merchants can trigger deletion automatically by removing a customer in Shopify (which fires customers/redact), or email us at support@shipops.app to request assistance at any time.
Contact
Security or data-protection questions: support@shipops.app. For full detail on what we collect and why, see the Privacy Policy.