Privacy Policy

Last updated: February 22, 2026

1. Introduction

CODShield is a Shopify application that helps merchants analyze and manage Cash on Delivery (COD) orders.

CODShield acts as a data processor on behalf of the merchant (data controller).

This Privacy Policy explains how we collect, process, and protect data.

2. Data We Process

When installed, CODShield processes the following Shopify store data:

Order Data

  • Order number
  • Order amount
  • Order status
  • Order date

Customer Data

  • First name
  • Last name
  • Email address
  • Shipping address
  • Phone number (if required for risk analysis)

Store Data

  • Store name
  • Store domain
  • App configuration settings

We only process data strictly necessary for fraud risk analysis and dashboard functionality.

3. Purpose of Processing

We process data exclusively to:

  • Analyze Cash on Delivery (COD) orders
  • Calculate fraud risk scores
  • Automatically tag high-risk orders
  • Display analytics in the CODShield dashboard

We do not use data for advertising, marketing, or profiling.

4. Data Sharing

We share data only with:

  • Shopify, as required for app integration

We do not sell, rent, or trade merchant or customer data.

We do not share data with advertising platforms.

5. Data Retention

  • Data is retained only while the app is installed.
  • When a merchant uninstalls CODShield, all associated store data is permanently deleted within 30 days.

CODShield complies with Shopify's mandatory data deletion webhooks:

  • customers/data_request
  • customers/redact
  • shop/redact

Upon receiving these requests, relevant data is securely deleted in accordance with Shopify requirements.

6. Data Security

We implement appropriate technical and organizational measures:

  • HTTPS/TLS encryption in transit
  • Secure cloud infrastructure
  • Restricted server access
  • Principle of least privilege
  • Compliance with Shopify API security standards

7. Merchant and Customer Rights

Merchants and their customers have the right to:

  • Access their data
  • Correct inaccurate data
  • Request deletion
  • Object to processing

Requests can be submitted to: contact@funkydev.io

8. International Transfers

If applicable, data may be processed in secure cloud infrastructure located outside the merchant's country. All transfers comply with applicable data protection regulations.

9. Contact

For privacy-related questions:

© 2026 CODShield. All rights reserved.

Need help?

Our team is here to answer your questions about data protection.

Contact us