Privacy Policy
This Privacy Policy describes how All In One Courier (“we”, “us”, or “our”) collects, uses, stores, and protects information when merchants install and use our application through the Shopify platform. By installing or using the app, you agree to the practices described in this policy.
1. Who this policy applies to
This policy applies to merchants (store owners and staff) who use our app, and to customer data processed on a merchant’s behalf when the merchant uses the app for order fulfillment and courier booking. We do not sell personal information.
2. Information we collect
We collect and process the following categories of information:
- Merchant and store information: shop domain, store name, staff account identifiers used during OAuth, subscription and billing status, plan credits, and app settings you configure.
- Order and shipment data: order numbers, fulfillment status, COD amounts, weights, product details, booking status, tracking numbers, loadsheet records, and courier API responses needed to create and manage shipments.
- Customer data from orders: names, phone numbers, email addresses, and shipping addresses required to book courier deliveries on your behalf. We access this data only as permitted by Shopify and your app permissions.
- Courier credentials: API keys, usernames, passwords, tokens, and pickup location settings that you enter in Courier Settings. These are stored to connect with third-party courier services you choose.
- Technical data: server logs, IP addresses, timestamps, and error diagnostics used to operate, secure, and improve the app.
Our app only accesses the Shopify data necessary to provide the services requested by the merchant and only within the permissions granted during app installation.
3. How we use information
We use collected information to:
- Provide courier booking, tracking, label printing, loadsheets, and reporting features;
- Sync order and shipment data between your store and supported courier partners;
- Manage subscriptions, credits, and billing through Shopify’s billing APIs;
- Authenticate your store and maintain secure sessions;
- Respond to support requests and troubleshoot issues;
- Comply with legal obligations and Shopify platform requirements.
4. Legal basis and privacy compliance
We process merchant account data to perform our contract with you and to provide the app you install. Customer data is processed on your instructions as a data processor when you use the app to fulfill orders.
We support Shopify’s mandatory privacy compliance webhooks (customers/data_request, customers/redact, and shop/redact). When we receive these requests, we take appropriate action to provide, redact, or delete applicable data in line with Shopify’s requirements and applicable privacy laws, including GDPR where relevant.
5. Third-party services
We share data only as needed to operate the app:
- Shopify: for authentication, order data, billing, and embedded app functionality.
- Courier partners: such as Leopards Courier, TCS, M&P (MNP), and PostEx, when you book shipments through their APIs.
- Infrastructure providers: such as cloud hosting and database services used to run the application securely.
Each third party receives only the data required for its service. Courier partners process shipment data under their own privacy policies.
6. Cookies and analytics
The embedded app runs inside Shopify Admin and relies on Shopify session authentication. We do not use third-party advertising cookies. We may use essential session mechanisms and limited operational analytics (such as error logging and usage diagnostics) to keep the app reliable. Insights and reports shown in the app are generated from your store’s shipment and order data, not from cross-merchant advertising profiles.
7. Data retention
We retain merchant and shipment data for as long as your store uses the app and as needed to provide the service. Booking, loadsheet, and analytics data may be removed automatically after a configurable retention period (default 90 days) unless a longer period is required for legal, billing, or dispute resolution purposes. When you uninstall the app, we revoke access tokens promptly; shop data is deleted in accordance with Shopify’s shop/redact webhook and our data deletion procedures.
8. Security
We use industry-standard measures to protect data, including HTTPS encryption in transit, access controls, webhook HMAC verification, and encrypted storage for sensitive courier credentials where configured. No method of transmission or storage is completely secure; please use strong passwords and limit staff access in your Shopify admin.
9. Merchant rights
Depending on your location, you may have the right to:
- Access personal data we hold about you or your store;
- Request correction or deletion of certain data;
- Object to or restrict certain processing;
- Export data you have provided through the app.
To exercise these rights, contact us using the details below. You may also uninstall the app at any time from Shopify Admin.
10. Customer data requests
If you receive a customer privacy request, Shopify may send us a customers/data_request or customers/redact webhook. We will cooperate with you and Shopify to honor those requests within required timeframes.
11. International transfers
Data may be processed on servers located outside your country. Where required, we take steps designed to ensure appropriate safeguards for cross-border transfers.
12. Children
The app is intended for merchants and is not directed at children under 16.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version at this URL and update the “Last updated” date above. Continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact us
For privacy questions, data requests, or support regarding this policy, contact:
All In One Courier
Support Email: app.allinonecourier@gmail.com
Support Phone: +92 310 5555728