Privacy Policy — Traddal for Shopify
Last updated: 20 August 2026
Traddal ("we", "us") provides the Traddal app for Shopify (the "App"), which connects a merchant's Shopify store to their shipping provider's Traddal account to offer shipping rates at checkout, route orders for fulfilment, and return tracking information. This policy describes what data the App processes and how it is handled.
Data we process
- Order and customer data — when an order is routed for shipping, we process the recipient's name, shipping address, email address, phone number, and the ordered items (titles, SKUs, quantities, prices, weights). This is the minimum required to generate shipping labels, customs declarations and delivery notifications.
- Product data — product titles, SKUs, prices and weights, synced so items can be classified for customs.
- Store data — the store's name, address and contact details, used as the shipment sender.
Purpose and limitation
Personal data is processed solely to provide shipping and customs services on the merchant's instruction: booking carrier labels, preparing customs declarations, tracking delivery, and notifying the merchant's customers about their delivery. We do not use personal data for advertising, profiling or any other purpose, and we do not sell personal data.
Where data lives
Shipment data is stored in the merchant's shipping provider's Traddal account. The App itself stores only the link between the store and that account: session tokens, connection credentials, and order-to-shipment references. All data is encrypted in transit (TLS) and at rest, with encrypted backups, and test data is kept separate from production data.
Retention and deletion
- Uninstalling the App deletes its stored connection and credentials immediately.
- We honour Shopify's GDPR webhooks: shop data is purged on
shop/redact, and customer requests received viacustomers/data_request/customers/redactare forwarded to the merchant's shipping provider, who fulfils them as data controller. - Operational logs are retained for a limited period for security and debugging, then deleted automatically.
Access and security
Access to personal data is restricted to personnel who need it to operate the service, protected by single sign-on with strong authentication. API access is logged. We maintain a security incident response process; affected merchants are notified without undue delay if their data is involved in an incident.
Contact
Questions or requests about this policy: info@traddal.com.