Privacy Policy — Trackable
Last updated: August 20, 2026 · Effective: August 20, 2026
Trackable ("we", "us", the "App") is a Shopify application operated by Jins Mathew (trading as WorkFlicks), Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513, that provides branded order tracking, customer self-service order lookup, and shipping notifications to Shopify merchants ("Merchants"). This policy explains what personal data we process, why, and the rights available to Merchants and to the shoppers who use a Merchant's store ("Customers").
For Merchants' Customers, the Merchant is the data controller and Trackable is a data processor acting on the Merchant's instructions. Our processing terms are in the Data Processing Agreement.
1. Data we process
From the Merchant (controller / account data)
- Shopify store domain, store name, currency, locale, plan, install/uninstall timestamps.
- App configuration you set (branding, notification settings).
From the Merchant's store, about Customers (processed on the Merchant's behalf)
- Order data: order number, order line items, fulfillment status.
- Fulfillment data: carrier, tracking number, tracking URL, shipment status, checkpoints.
- Customer email — used to (a) match a self-service lookup and (b) send shipping notifications (shipped / delivered / delivery exception). We store it in two forms: a salted HMAC-SHA256 hash for lookup matching, and, when notifications are enabled, an AES-256-GCM encrypted copy so later status updates can be emailed. We never store the email in plaintext.
From store visitors (tracking page)
- When a Customer opens the branded tracking page or performs a lookup, we record an aggregate deflection event (event type + timestamp, and the associated order id). We do not set advertising cookies or build cross-site profiles.
We do not process: passwords, payment card numbers, government IDs, or Customer
names/phone numbers/addresses. Our Shopify access scopes are read-only
(read_orders, read_fulfillments); the App never writes to the store.
2. Why we process it (purposes & legal bases)
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide order tracking & self-service lookup | order, fulfillment, hashed email | Performance of contract / legitimate interest of Merchant |
| Send transactional shipping notifications | order, fulfillment, email (transient) | Performance of contract / legitimate interest |
| Measure ticket-deflection value for the Merchant | aggregate event counts | Legitimate interest |
| Billing & account management | Merchant account data | Performance of contract |
| Security, fraud prevention, legal compliance | the above | Legal obligation / legitimate interest |
We process the minimum personal data required and use it only for these purposes. Shipping notifications are transactional (not marketing); we do not use Customer data for advertising and we do not sell personal data.
3. Sharing & sub-processors
We share personal data only with the sub-processors needed to run the App:
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Source platform / hosting of store data | Global |
| Hetzner Online GmbH | Application & database hosting | Helsinki, Finland (EU) |
| Resend (only if shipping emails enabled) | Sending transactional emails | EU / US |
We do not sell personal data or share it for advertising. We may disclose data if required by law or to protect rights and safety.
4. International transfers
Application data is hosted in the EU (Helsinki, Finland). The App operator is located in India. Where personal data is transferred across borders (including EU/UK to India, or to a sub-processor), we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
5. Retention
- Customer/order data: retained while the App is installed and needed for tracking.
Deleted on the Shopify
shop/redactrequest (48 hours after uninstall) and on acustomers/redactrequest for the specific Customer. - Merchant account data: retained for the life of the account; deleted on uninstall
and
shop/redact, subject to legal retention requirements. - Email send logs: minimal metadata (event type, timestamp) retained for audit and deleted with the shop record.
6. Security
- In transit: TLS/HTTPS for all connections.
- At rest: Customer email is stored hashed (for lookup) and AES-256-GCM encrypted (for notifications), never in plaintext; the database runs on an encrypted volume.
- Least-privilege, read-only Shopify scopes; secrets held in environment/secret storage, never in source control.
- Idempotent, verified webhooks (HMAC signature validation on every Shopify webhook).
7. Your rights
Depending on your location (GDPR / UK GDPR / CCPA-CPRA, India's DPDP Act, and similar),
you may have rights to access, correct, delete, restrict, or port your personal data, and
to object to processing. Customers should contact the Merchant (the controller).
Merchants may contact us at hello@workflicks.online. We honor Shopify's mandatory
data-subject webhooks (customers/data_request, customers/redact, shop/redact).
8. Children
The App is not directed to children and does not knowingly process children's data.
9. Changes
We may update this policy; material changes will be communicated to Merchants. Continued use after the effective date constitutes acceptance.
10. Contact
Jins Mathew (trading as WorkFlicks) Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513 Email: hello@workflicks.online Data protection contact: hello@workflicks.online Governing law: Kottayam, Kerala, India