Privacy policy
1. Who we are
Errie - EU Withdrawal Button (the "app") is a Shopify app made by Errie Studios, Markerkant 13-11, 1314 AL Almere, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 80513573 ("we", "us"). Contact: support@withdrawalform.com.
2. Our two roles
For data about the Shopify stores that install the app ("merchants"), we are the controller.
For data that customers of a merchant submit through the withdrawal form, the merchant is the controller and we are the processor. We process that data only to provide the withdrawal function for that merchant, under our data processing addendum. Customers who want to exercise their privacy rights should contact the store where they bought the goods; we will help that store.
3. What we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Merchant data: store domain, store name, store email and customer-facing email, time zone, published languages, primary domain, plan and app settings | Providing the app, sending withdrawal notifications, showing the right plan | Contract (Art. 6(1)(b) GDPR) |
| Shopify API access tokens | Reading orders and tagging them on behalf of the merchant | Contract |
| Withdrawal data from customers: name, email address, order number, chosen products and quantities, optional comment, the withdrawal statement, date and time of submission, reference and email delivery status. For withdrawals made from the customer account, the email address is the order's email address, read from Shopify. | Receiving and recording withdrawals and sending the acknowledgment of receipt, on behalf of the merchant | Determined by the merchant as controller; usually a legal obligation under consumer law (Art. 6(1)(c) GDPR) |
| Order data read from Shopify: order ID, order email, line items, product tags and line item property names | Checking that order number and email belong together (or, in the customer account, that the order belongs to the signed-in customer) before showing order details, and marking exempt products. Only the withdrawn lines are stored, plus the order email for withdrawals from the customer account. | On behalf of the merchant |
| Technical request data such as IP address, handled by our hosting provider | Security, abuse prevention and rate limiting | Legitimate interest (Art. 6(1)(f) GDPR) |
The app adds no cookies, analytics or advertising trackers of its own, on this website, in the app or on the withdrawal form. The withdrawal form is shown inside the merchant's store, where the merchant's own cookies and scripts apply. We do not sell data and do not use it for marketing.
4. Sub-processors
| Provider | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, sending of emails, network security | Database in the European Union; requests, rate-limit counters, logs and emails are handled in Cloudflare's global network |
| Shopify | The platform the app runs on; order data comes from the merchant's store | Under the merchant's own agreement with Shopify |
Where data is processed outside the European Economic Area, transfers rely on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
5. How long we keep data
Withdrawal records are kept while the app is installed, so the merchant can show when a withdrawal was received. When Shopify forwards a customer's erasure request, we remove the name, email address, comment and statement from that customer's records; the order reference, products and timestamps remain as proof of the withdrawal itself. After a merchant uninstalls the app, access tokens are deleted immediately and all data of that store is deleted when Shopify sends its store erasure request, 48 hours after uninstalling. Failed acknowledgment emails are retried for seven days. Database backups are kept for up to 30 days and then expire.
6. Security
All traffic is encrypted with TLS. Access tokens are encrypted at rest with AES-GCM, and the database is encrypted at rest by our hosting provider. The app asks Shopify only for the permissions it needs, requests are verified with Shopify signatures, and order details are only shown after both order number and email match.
7. Your rights
You can ask for access to, correction or erasure of your personal data, restriction of or objection to its processing, and a copy of your data. Merchants can contact us directly. Customers of a store should contact that store, which controls the data; we assist the store with the request. You can also file a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.
8. Changes
We update this policy when the app or the law changes. The date at the top shows the current version. Material changes are announced to merchants in the app or by email.