ShipCue

Privacy policy — technical draft

Owner and legal review required before merchant launch. Last updated: 14 September 2026.

Controller and contact

[LEGAL ENTITY / CONTROLLER NAME], [BUSINESS ADDRESS], [PRIVACY CONTACT EMAIL]. These details must be completed by the owner.

What ShipCue processes

We process your Shopify shop identifier and domain, timezone, settings, subscription state and the notification email you explicitly enter. For order monitoring we retain order identifiers, display names, payment observation time, financial and fulfillment statuses, cancellation, amount, currency, relevant exclusion tags and monitoring/alert timestamps. We do not request or store customer names, email addresses, telephone numbers or billing/shipping addresses. Order identifiers and merchant-entered names or tags can still constitute personal data.

Purpose and legal basis

Data is used to detect delayed fulfillment of paid orders, show the merchant a dashboard, send merchant alerts when enabled, manage the subscription, support the service and handle privacy requests. [OWNER: confirm applicable contractual and other legal bases and controller/processor roles.] No external advertising or analytics trackers are included.

Processors and hosting

Shopify supplies order and installation data. The application and PostgreSQL database run on a dedicated project deployment on a shared VPS. [OWNER: hosting provider, processing country, DPA and international transfer arrangements.] Resend is the initially supported production email provider and receives only the merchant destination and minimal order notification content. [OWNER: confirm Resend contract, region, subprocessors and transfers before enabling.]

Retention and deletion

Terminal order details are retained for up to 30 days; all order details expire within 59 days of creation. Completed jobs and webhook delivery identifiers are retained for seven days; failed jobs for 30 days. Aggregate usage and non-identifying analytics are retained for 13 months. Privacy export files expire after seven days. On uninstall, monitoring and pending notifications stop and credentials are deleted. Remaining live shop data is deleted on Shopify shop/redact or the 48-hour cleanup fallback. Hashed order suppression records prevent deleted orders being reimported for up to 60 days. Daily local backups expire after seven rotations; restoration procedures must reapply deletions before service resumes.

Security and rights

Traffic uses HTTPS when the production domain is active. Offline tokens and merchant notification addresses are encrypted at rest with application-managed keys. We restrict database exposure and avoid personal data in logs. Contact [PRIVACY CONTACT EMAIL] for access, correction, deletion and other applicable privacy rights. Merchants receive minimum-data exports in the authenticated application and must deliver them through their verified privacy-request process. [OWNER: add supervisory authority and jurisdiction-specific rights after legal review.]