Privacy Policy

Fast COD Form — last updated 7 September 2026

This policy explains what personal data the Fast COD Form app (“the App”) collects, why, how long it is kept and who can access it. It applies to merchants who install the App and to shoppers who submit the cash-on-delivery order form on a merchant’s storefront.

Data controllerMoussa Seddik, Aïn Témouchent, Algeria
Contactademyaniceines@gmail.com
AppFast COD Form (Shopify App Store)

1. Roles

For shopper data collected through the order form, the merchant is the data controller and we act as a data processor on the merchant’s behalf, under the Data Processing Agreement available at /dpa. For merchant account data (installation, billing, support), we are the controller.

2. What we collect

2.1 Shopper data (processor)

DataSourceWhyLegal basis
Full nameOrder formCreate the Shopify orderContract
Phone numberOrder formDelivery confirmationContract
Email (optional)Order formOrder confirmationContract
Address, wilaya, communeOrder formDelivery and shipping costContract
Order lines and amountsOrder formCreate the orderContract
IP address, browser user agentAutomaticAnti-spam and abuse prevention onlyLegitimate interest
Tracking consent stateShopify Customer Privacy APIRecorded with the submissionConsent

We collect only the fields the merchant has enabled on their form. We do not read the merchant’s existing customer database: the App does not request the read_customers scope.

2.2 Merchant data (controller)

Shop domain, shop currency and locale, the Shopify access token issued at installation, the App configuration you create, and monthly order counts used for billing.

3. What we never do

4. Where data is stored

WhereWhat
ShopifyThe order itself, once created
Our server (Contabo, Germany)Form configuration, submissions, sessions
Encrypted daily backups on the same serverA copy of the above

5. How long we keep it

DataRetentionThen
Submissions with no order created90 daysPermanently deleted
Submissions with an order created24 monthsAnonymised (name, phone, email and address erased)
IP address and user agent30 daysErased
Access and action logs12 monthsDeleted

These rules run automatically every night. On uninstall, we delete the merchant session immediately; on Shopify’s shop/redact request we delete all data for that shop.

6. Security

Encryption at rest, in detail: every personal field — name, phone, email, address, IP address and browser user agent — is encrypted with AES-256-GCM before it is written to disk, and decrypted only in memory when it is displayed to the merchant. The encryption key is held in the server environment and never leaves it, and it is included in the encrypted backups so that a restore stays readable. Non-identifying fields, such as the wilaya and the order lines, are stored as-is.

7. Your rights

Shoppers may ask the merchant whose store they ordered from to access, correct or delete their data. We support Shopify’s mandatory customers/data_request, customers/redact and shop/redact webhooks and act on them within 30 days, in practice immediately. Requests can also be sent directly to ademyaniceines@gmail.com.

Depending on where you live you may also have rights under the GDPR, the CCPA, or Algerian Law No. 18-07 on the protection of personal data.

8. Sub-processors

ProviderRoleLocation
ShopifyPlatform and destination of ordersCanada / global
ContaboServer hostingGermany
CloudflareDNS and traffic protectionGlobal

We will inform merchants before adding any new sub-processor that handles personal data.

9. Changes

Material changes are announced to merchants inside the App before they take effect. The date at the top of this page always reflects the current version.


Politique de confidentialité

Fast COD Form — mise à jour le 7 septembre 2026

Cette page explique quelles données personnelles l’application Fast COD Form collecte, pourquoi, combien de temps elles sont conservées et qui peut y accéder.

1. Rôles

Pour les données des acheteurs collectées via le formulaire, le marchand est le responsable du traitement et nous agissons comme sous-traitant pour son compte, dans le cadre de l’accord de traitement des données disponible sur /dpa.

2. Données collectées

DonnéeFinalitéBase légale
Nom completCréer la commande ShopifyExécution du contrat
TéléphoneConfirmation de livraisonExécution du contrat
E-mail (facultatif)Confirmation de commandeExécution du contrat
Adresse, wilaya, communeLivraison et frais de portExécution du contrat
Adresse IP, navigateurAnti-spam uniquementIntérêt légitime

Nous ne lisons pas la base clients du marchand : l’application ne demande pas l’autorisation read_customers.

3. Ce que nous ne faisons jamais

Nous ne vendons ni ne louons aucune donnée. Nous n’utilisons pas les données des acheteurs pour notre propre marketing. Nous ne les transmettons à personne en dehors de Shopify et du marchand propriétaire de la boutique.

4. Durées de conservation

DonnéeDuréeEnsuite
Soumission sans commande90 joursSuppression définitive
Soumission avec commande24 moisAnonymisation
Adresse IP et navigateur30 joursEffacement
Journaux d’accès12 moisSuppression

5. Sécurité

HTTPS obligatoire, accès administrateur par clé SSH uniquement, sauvegardes chiffrées dont la clé privée n’est pas sur le serveur, journalisation des consultations, surveillance horaire de l’intégrité du serveur, et politique écrite de réponse aux incidents.

Chiffrement au repos : chaque champ personnel — nom, téléphone, e-mail, adresse, adresse IP et navigateur — est chiffré en AES-256-GCM avant d’être écrit sur le disque, et n’est déchiffré qu’en mémoire au moment de l’affichage. Le fichier de base de données ne contient donc aucun nom, numéro ni adresse en clair.

6. Vos droits

Accès, rectification et suppression sur demande à ademyaniceines@gmail.com, ou via le marchand. Les webhooks obligatoires de Shopify sont implémentés et traités sous 30 jours, en pratique immédiatement.

7. Sous-traitants

Shopify (plateforme), Contabo (hébergement, Allemagne), Cloudflare (DNS).