This Privacy Policy explains how CODcheck ("CODcheck", "we", "us") handles personal data in connection with the CODcheck Shopify application (the "App") and the marketing website at codcheck.ro (the "Site"). CODcheck helps Shopify merchants reduce cash-on-delivery (COD) fraud by scoring orders for refusal/fraud risk.
| Marketing site | With your consent, anonymised analytics (Google Analytics) — pages viewed, approximate region, device/browser type. Essential cookies keep the site working. We do not run analytics until you accept them; see cookie preferences on the Site. |
|---|---|
| Merchant account | Your .myshopify.com domain, shop currency and
locale, the offline access token issued by Shopify (stored encrypted),
and your plan / billing status. Billing itself is handled by Shopify — we never receive
or store card details. |
| Shopper data (via the App) | Order identifiers and order value; and — only where the merchant enables it — a shopper's name, phone, email and shipping address. Identity fields are never stored in clear text: they are converted to irreversible cryptographic fingerprints (keyed HMAC-SHA-256 with a secret server-side pepper) used only to match risk signals. Contact details shown inside the App are fetched live from Shopify on each view and are not retained by CODcheck. |
When a merchant opts in, CODcheck contributes anonymised failure signals (for example, a refused delivery) to a network shared across stores, so other merchants are protected from the same fraudulent buyers. Only irreversible hashes are shared — never names, phone numbers, emails or addresses. A merchant can leave the network at any time from the App's settings.
| Shopify | The platform the App runs on; the source of order and shop data, and the billing provider. |
|---|---|
| Amazon Web Services | Hosting and database, in the EU region
(Frankfurt, eu-central-1). |
| Google Analytics | Site analytics, only with your consent. |
We do not sell personal data, and we do not use it for advertising.
Data is stored within the European Union (AWS eu-central-1, Frankfurt). Where any
processor transfers data outside the EEA, it is done under appropriate safeguards such as the
European Commission's Standard Contractual Clauses.
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal
data, and to object to processing. Because a shopper's data is controlled by the merchant, a
shopper should direct requests to the merchant (the controller); CODcheck will assist the
merchant in responding. CODcheck honours Shopify's mandatory privacy webhooks —
customers/data_request, customers/redact and
shop/redact — to surface or delete data on request. To exercise rights against
CODcheck as a controller, or to raise a concern, contact us at
hello@codcheck.ro. You may also lodge a complaint with
your local data protection authority.
The Site uses essential cookies to function and, only with your consent, Google Analytics cookies. You can accept, decline or change your choice at any time via the cookie-preferences control on the Site. The embedded App uses Shopify session tokens rather than cookies, so it works even when third-party cookies are blocked.
The App and Site are intended for businesses and are not directed at children.
We may update this policy as the Service evolves. Material changes will be reflected by a new version number and effective date at the top of this page.
CODcheck — hello@codcheck.ro.
Respectăm confidențialitatea ta
Folosim cookie-uri de analiză (Google Analytics) doar cu acordul tău, pentru a înțelege cum este folosit site-ul. Cookie-urile esențiale rămân mereu active. Află mai multe