Privacy Policy
Last updated: October 11, 2026
This Privacy Policy explains what data the Consentico: EU Withdrawal Shopify app ("the app", "we") accesses, how we use it, and how it is retained and deleted. The app is published by Consentico.
Data we access
To provide its functionality, the app requests the minimum Shopify access scopes:
- read_products — to show order and product context in the withdrawal flow and admin.
- read_themes — to verify, server-side, that the withdrawal button is actually live on your published theme (the store-health check). The app never writes to your theme.
The app stores the withdrawals submitted on your storefront (the consumer's name, order reference, contact address and the content and timestamp of the withdrawal) so you have an audit-ready log and can send the required receipt. It also stores shop-level settings you configure (button placement, wording, branding) and your plan status.
Optional, on-demand scopes
read_orders and write_returns are requested only if and when a merchant first uses the optional Shopify Returns hand-off (a Pro feature). These are Protected Customer Data and are subject to Shopify's review. They are never requested at install.
How we use data
Withdrawal records are used solely to render the acknowledgement (receipt) email on a durable medium, to notify you of new withdrawals, to maintain your withdrawals log and refund countdown, and — on Pro — to produce an evidence pack you request. We do not use withdrawal data for advertising or profiling.
Data sharing
We do not sell your data. Receipt and notification emails are delivered through our email provider. Infrastructure providers (hosting, database) process data on our behalf under their own security commitments. We share data only as needed to operate the app.
Data retention and deletion
Withdrawal records are retained so they remain audit-ready for the period you need them, and are removed on request or when you uninstall, per the webhooks below. We implement Shopify's mandatory GDPR webhooks:
- shop/redact — permanently purges your shop's data (approximately 48 hours after uninstall).
- customers/redact and customers/data_request — handled for any personal data contained in withdrawal records associated with the identified customer.
Security
All data is transmitted over TLS/HTTPS. Access to the app admin is authenticated via Shopify session tokens; the public withdrawal page is same-origin via Shopify's HMAC-signed app proxy.
Contact
Questions about this policy? Email support@consentico.com.