Trackable

Privacy Policy — Trackable

Last updated: August 20, 2026 · Effective: August 20, 2026

Trackable ("we", "us", the "App") is a Shopify application operated by Jins Mathew (trading as WorkFlicks), Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513, that provides branded order tracking, customer self-service order lookup, and shipping notifications to Shopify merchants ("Merchants"). This policy explains what personal data we process, why, and the rights available to Merchants and to the shoppers who use a Merchant's store ("Customers").

For Merchants' Customers, the Merchant is the data controller and Trackable is a data processor acting on the Merchant's instructions. Our processing terms are in the Data Processing Agreement.

1. Data we process

From the Merchant (controller / account data)

  • Shopify store domain, store name, currency, locale, plan, install/uninstall timestamps.
  • App configuration you set (branding, notification settings).

From the Merchant's store, about Customers (processed on the Merchant's behalf)

  • Order data: order number, order line items, fulfillment status.
  • Fulfillment data: carrier, tracking number, tracking URL, shipment status, checkpoints.
  • Customer email — used to (a) match a self-service lookup and (b) send shipping notifications (shipped / delivered / delivery exception). We store it in two forms: a salted HMAC-SHA256 hash for lookup matching, and, when notifications are enabled, an AES-256-GCM encrypted copy so later status updates can be emailed. We never store the email in plaintext.

From store visitors (tracking page)

  • When a Customer opens the branded tracking page or performs a lookup, we record an aggregate deflection event (event type + timestamp, and the associated order id). We do not set advertising cookies or build cross-site profiles.

We do not process: passwords, payment card numbers, government IDs, or Customer names/phone numbers/addresses. Our Shopify access scopes are read-only (read_orders, read_fulfillments); the App never writes to the store.

2. Why we process it (purposes & legal bases)

Purpose Data Legal basis (GDPR Art. 6)
Provide order tracking & self-service lookup order, fulfillment, hashed email Performance of contract / legitimate interest of Merchant
Send transactional shipping notifications order, fulfillment, email (transient) Performance of contract / legitimate interest
Measure ticket-deflection value for the Merchant aggregate event counts Legitimate interest
Billing & account management Merchant account data Performance of contract
Security, fraud prevention, legal compliance the above Legal obligation / legitimate interest

We process the minimum personal data required and use it only for these purposes. Shipping notifications are transactional (not marketing); we do not use Customer data for advertising and we do not sell personal data.

3. Sharing & sub-processors

We share personal data only with the sub-processors needed to run the App:

Sub-processor Purpose Location
Shopify Inc. Source platform / hosting of store data Global
Hetzner Online GmbH Application & database hosting Helsinki, Finland (EU)
Resend (only if shipping emails enabled) Sending transactional emails EU / US

We do not sell personal data or share it for advertising. We may disclose data if required by law or to protect rights and safety.

4. International transfers

Application data is hosted in the EU (Helsinki, Finland). The App operator is located in India. Where personal data is transferred across borders (including EU/UK to India, or to a sub-processor), we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

5. Retention

  • Customer/order data: retained while the App is installed and needed for tracking. Deleted on the Shopify shop/redact request (48 hours after uninstall) and on a customers/redact request for the specific Customer.
  • Merchant account data: retained for the life of the account; deleted on uninstall and shop/redact, subject to legal retention requirements.
  • Email send logs: minimal metadata (event type, timestamp) retained for audit and deleted with the shop record.

6. Security

  • In transit: TLS/HTTPS for all connections.
  • At rest: Customer email is stored hashed (for lookup) and AES-256-GCM encrypted (for notifications), never in plaintext; the database runs on an encrypted volume.
  • Least-privilege, read-only Shopify scopes; secrets held in environment/secret storage, never in source control.
  • Idempotent, verified webhooks (HMAC signature validation on every Shopify webhook).

7. Your rights

Depending on your location (GDPR / UK GDPR / CCPA-CPRA, India's DPDP Act, and similar), you may have rights to access, correct, delete, restrict, or port your personal data, and to object to processing. Customers should contact the Merchant (the controller). Merchants may contact us at hello@workflicks.online. We honor Shopify's mandatory data-subject webhooks (customers/data_request, customers/redact, shop/redact).

8. Children

The App is not directed to children and does not knowingly process children's data.

9. Changes

We may update this policy; material changes will be communicated to Merchants. Continued use after the effective date constitutes acceptance.

10. Contact

Jins Mathew (trading as WorkFlicks) Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513 Email: hello@workflicks.online Data protection contact: hello@workflicks.online Governing law: Kottayam, Kerala, India

Privacy · DPA · hello@workflicks.online