Privacy Policy

1. Controller and contact

This Privacy Policy explains how Workflow Trigger Extensions ("the app") processes personal data. The app is operated by Code Creation Labs GmbH, Friedensstr. 1, 47647 Kerken, Germany (Yann Faulhaber; Amtsgericht Kleve, HRB 20472; VAT ID DE451671933).

For any data-protection question or to exercise your rights, contact us at [email protected].

2. Our role: processor for the merchant

The app is installed by a Shopify merchant (the "merchant") to extend Shopify Flow. For any personal data contained in the store data and Flow payloads the merchant routes through the app, the merchant is the data controller and we act as a processor on the merchant's behalf under Article 28 GDPR. Our Data Processing Agreement is available at dpa.

We are the controller only for the limited account and operational data we need to run the service and to communicate with the merchant (for example the merchant's contact email, shop domain and plan, and support correspondence).

3. What we process and why

Purpose of processing: Providing additional Shopify Flow trigger types, including detection of changes to customer and order data (for example 'Customer Email Changed' or 'Address Changed'), and - where the merchant switches them on - triggers based on visitor behaviour in the merchant's online store and checkout, collected through a Shopify web pixel.

Categories of personal data: Customer personal data read from the Shopify store to detect changes - in particular first and last name, billing and shipping address, and email address - together with related order, product and metafield data. Where the merchant enables storefront triggers, additionally: online-store behaviour of the merchant's visitors, namely the products, variants and collections viewed, cart and checkout events, search terms entered, error messages shown at checkout, a discount code that checkout rejected, the Shopify customer identifier when the visitor is signed in, the company and location identifiers for signed-in B2B buyers, any data the merchant chooses to publish through a Custom Storefront Trigger, and the IP address inherent in the request. The web pixel does not collect visitor names, email addresses, telephone numbers or postal addresses.

Categories of data subjects: The merchant's customers; visitors to the merchant's online store, including visitors who are not signed in and have not placed an order, where storefront triggers are enabled; the merchant's own staff who use the app.

Legal basis: performance of the contract with the merchant and our legitimate interest in providing and securing the service (Art. 6(1)(b) and (f) GDPR). For the personal data the merchant routes through the app, the merchant determines the legal basis towards its own customers.

4. Where your data is hosted

All processing takes place in the European Union on Google Cloud, region europe-west1 (Belgium). Databases, caches and file storage are region-local, with encryption at rest.

Personal data and secrets (such as credentials and tokens) are additionally encrypted at field level using Google Cloud KMS, with separate keys, and are decrypted only in memory for the moment a request runs.

Our public website and the documentation for the app are delivered through Cloudflare, Inc. (DNS, TLS termination and edge caching), which processes the visitor's technical connection data. The app itself and all merchant data stay on Google Cloud in the europe-west1 region.

5. Sub-processors

We engage the following sub-processors to provide the service. Each is bound by a data processing agreement with obligations equivalent to ours:

  • Google Cloud (Google Ireland Limited) - Compute, storage and Cloud KMS key management - European Union - Google Cloud region europe-west1 (Belgium) - DPA: https://cloud.google.com/terms/data-processing-addendum
  • Shopify International Limited - The Shopify platform - the app receives triggers from and returns data to Shopify Flow; that data may contain personal data the merchant routes through it - Ireland (EU); Shopify operates globally, third-country transfers safeguarded under Chapter V GDPR (SCC / EU-U.S. DPF) - DPA: https://www.shopify.com/legal/dpa

6. Storefront behaviour data (web pixel)

If the merchant switches on one or more storefront triggers, the app installs a Shopify web pixel in the merchant's online store. The pixel lets a Shopify Flow workflow react to what a visitor does - for example viewing a product, adding an item to the cart, searching for something the store does not sell, or seeing an error at checkout. Without those triggers switched on, no pixel is installed and nothing described in this section takes place.

Consent decides whether anything is collected at all. The pixel honours the store's customer privacy settings, and where a visitor has not given consent for analytics the event is discarded in the visitor's own browser and never reaches us. The merchant, as controller, is responsible for obtaining that consent and for its lawful basis towards its visitors.

What the pixel sends us is commercial context, not identity: the products, variants and collections viewed, cart and checkout events, the search term entered, error messages shown at checkout and a discount code the checkout rejected, plus the Shopify customer identifier if the visitor happens to be signed in and the company identifier for a signed-in B2B buyer. The IP address is transmitted as part of the request itself, as with any web request.

The pixel does not collect visitor names, email addresses, telephone numbers or postal addresses. It runs inside the sandbox Shopify provides, with no access to page content, so it reads only the fields of the Shopify events it subscribes to. It sets no advertising cookies, performs no cross-site or cross-device tracking, builds no advertising profiles, and we do not sell or share this data with any third party for their own purposes.

Where the merchant defines a Custom Storefront Trigger, the merchant chooses which data their own theme publishes to it. That data is under the merchant's control and the merchant is responsible for keeping personal data out of it.

Storefront events are stored with the merchant's other event history and are deleted on the same 30-day schedule described below.

7. Data retention and deletion

We keep personal data only as long as needed to provide the service. All processing history (send, run and webhook history) is automatically cleared after 30 days, and operational logs are retained no longer than 30 days.

Uninstalling the app deletes the merchant's data; on termination we delete or return all personal data processed on the merchant's behalf within 30 days, unless Union or Member State law requires storage. We honour Shopify's mandatory data-protection webhooks (customers/data_request, customers/redact and shop/redact) within the timelines Shopify specifies.

Merchants can request deletion at any time by contacting [email protected].

8. International transfers

Our own infrastructure is in the EU. Where a sub-processor - in particular Shopify - processes personal data outside the EEA, the transfer is safeguarded under Chapter V GDPR, in particular the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

9. Your rights

Subject to the applicable conditions, you have the right of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with a supervisory authority. Our lead authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

Because we usually act as the merchant's processor, requests about a merchant's customer data are best directed to that merchant; we will assist the merchant in responding.

10. No tracking on this site

This website sets no third-party advertising or analytics cookies and embeds no third-party trackers.

11. Changes to this policy

We may update this Privacy Policy to reflect changes to the service or the law. The current version and its date are shown at the top of this page; material changes to sub-processors are notified in accordance with our DPA.

12. Our other apps

We operate other Shopify apps, each with its own privacy policy:

  • Workflow Webhooks: https://workflow-webhooks.app
  • Workflow Transactional Email: https://workflow-transactional-email.app
  • Workflow Functions: https://workflow-functions.app