EnglishRomână

Privacy Policy

Last updated: 14 July 2026 · COD Fraud Guard

COD Fraud Guard ("the App", "we") is operated by SC COVERED SRL, trading as TrackWise ("the Operator"), CUI: RO47818139, registered office: Str. Principală nr. 98, Strei, Hunedoara county, Romania, contact: support@trackwise.studio. The App helps Shopify merchants reduce cash-on-delivery (COD) returns through risk scoring, checkout rules and shipment tracking.

This policy explains what personal data the App processes, why, for how long, and what rights merchants and their customers have. For personal data of a merchant's customers, the merchant is the data controller and the Operator acts as a data processor under the Data Processing Agreement available at /legal/dpa.

1. Data we process

Merchant account data (controller: the Operator):

  • Shop domain, shop name, contact details provided by Shopify during installation
  • App configuration (rules, settings, subscription plan)

Customer personal data from the merchant's store (controller: the merchant; processor: the Operator):

  • Name, phone number, email address, shipping/billing address
  • Order details: order number, value, currency, payment method type, order timestamps
  • Fulfillment and shipment data: tracking numbers (AWB), courier, delivery statuses
  • Derived data: COD risk score with its reasons, delivery/return history counters

We do NOT process payment card numbers, passwords or government identifiers, and we do not collect data about visitors who do not place orders.

2. Purposes and legal basis

  • Risk scoring of COD orders and checkout rules — performance of the contract with the merchant and the merchant's legitimate interest in preventing failed COD deliveries
  • Order confirmation by SMS with a signed link — the merchant's legitimate interest; the SMS is strictly transactional and related to the order placed
  • Shipment tracking correlation (Shopify status + tracking aggregator) — performance of the contract

We do not use personal data for advertising, we do not sell or rent personal data, and we do not perform automated decision-making producing legal or similarly significant effects: customers can always pay by card, confirm via the link, and merchants can review any order manually.

3. Sub-processors

  • Shopify International Ltd. — platform APIs and webhooks
  • Railway Corp. — application hosting and PostgreSQL database (encrypted at rest, TLS in transit)
  • Tracking aggregator (17TRACK or TrackingMore, depending on configuration) — receives tracking numbers only, no customer identity
  • SMS providers (SMSLink.ro and/or Twilio) — receive phone number and the confirmation message text

An up-to-date list is maintained in the DPA. We notify merchants before adding or replacing sub-processors.

4. Retention and deletion

  • Customer history and scoring data are kept while the App is installed, as needed for the scoring service
  • On uninstall, Shopify sends the shop/redact webhook and all shop data is deleted automatically
  • Customer redaction requests (customers/redact webhook) delete that customer's local history immediately
  • Merchants may request earlier deletion at any time at the contact address

5. Security

  • All traffic uses TLS (HTTPS); the database is encrypted at rest
  • Courier API credentials are additionally encrypted with AES-256-GCM
  • Confirmation links are HMAC-signed and expire automatically
  • Access to production systems is restricted to the Operator with strong authentication

Incidents are handled according to the Incident Response Policy at /legal/incident-response, including notification of affected merchants without undue delay.

6. Data subject rights

Customers should address requests (access, rectification, erasure, objection) to the merchant they bought from — the merchant is the data controller. We assist merchants in fulfilling such requests via the Shopify privacy webhooks and on request. Merchants and customers may also contact us directly at support@trackwise.studio. You have the right to lodge a complaint with your supervisory authority (in Romania: ANSPDCP).

7. Changes

We may update this policy as the App evolves. Material changes are announced to merchants by email or in-app notice. The date above reflects the latest revision.