revokerie

Privacy policy

Effective 23 September 2026

1. Who we are

Revokerie - EU Withdrawal Form (the "app") is a Shopify app made by Errie Studios, Markerkant 13-11, 1314 AL Almere, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 80513573 ("we", "us"). Contact: support@revokerie.com.

2. Our two roles

For data about the Shopify stores that install the app ("merchants"), we are the controller.

For data that customers of a merchant submit through the withdrawal form, the merchant is the controller and we are the processor. We process that data only to provide the withdrawal function for that merchant, under our data processing addendum. Customers who want to exercise their privacy rights should contact the store where they bought the goods; we will help that store.

3. What we process and why

DataPurposeLegal basis
Merchant data: store domain, store name, store email and customer-facing email, time zone, published languages, primary domain, plan and app settingsProviding the app, sending withdrawal notifications, showing the right planContract (Art. 6(1)(b) GDPR)
Shopify API access tokensReading orders and tagging them on behalf of the merchantContract
Withdrawal data from customers: name, email address, order number, chosen products and quantities, optional comment, the withdrawal statement, date and time of submission, reference and email delivery status. For withdrawals made from the customer account, the email address is the order's email address, read from Shopify.Receiving and recording withdrawals and sending the acknowledgment of receipt, on behalf of the merchantDetermined by the merchant as controller; usually a legal obligation under consumer law (Art. 6(1)(c) GDPR)
Order data read from Shopify: order ID, order email, line items, product tags and line item property namesChecking that order number and email belong together (or, in the customer account, that the order belongs to the signed-in customer) before showing order details, and marking exempt products. Only the withdrawn lines are stored, plus the order email for withdrawals from the customer account.On behalf of the merchant
Pro options the merchant turns on: a webhook address, and the login for the merchant's own mail server (the password is stored encrypted)Sending a short summary of each withdrawal (reference, order, name, email, products, optional reason) to the webhook the merchant chose, for example Slack, and sending customer emails through the merchant's own mail serverOn behalf of the merchant, only when the merchant turns it on
Technical request data such as IP address, handled by our hosting providerSecurity, abuse prevention and rate limitingLegitimate interest (Art. 6(1)(f) GDPR)

The app adds no cookies, analytics or advertising trackers of its own, on this website, in the app or on the withdrawal form. The withdrawal form is shown inside the merchant's store, where the merchant's own cookies and scripts apply. We do not sell data and do not use it for marketing.

4. Sub-processors

ProviderServiceLocation
Cloudflare, Inc.Hosting, database, sending of emails, network securityDatabase in the European Union; requests, rate-limit counters, logs and emails are handled in Cloudflare's global network
ShopifyThe platform the app runs on; order data comes from the merchant's storeUnder the merchant's own agreement with Shopify
Services the merchant chooses (Pro)The merchant's own mail server and webhook receiver, when turned onChosen and controlled by the merchant

Where data is processed outside the European Economic Area, transfers rely on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.

5. How long we keep data

Withdrawal records are kept while the app is installed, so the merchant can show when a withdrawal was received. When Shopify forwards a customer's erasure request, we remove the name, email address, comment and statement from that customer's records; the order reference, products and timestamps remain as proof of the withdrawal itself. After a merchant uninstalls the app, access tokens are deleted immediately and all data of that store is deleted when Shopify sends its store erasure request, 48 hours after uninstalling. Failed acknowledgment emails are retried for seven days. Database backups are kept for up to 30 days and then expire.

6. Security

All traffic is encrypted with TLS. Access tokens are encrypted at rest with AES-GCM, and the database is encrypted at rest by our hosting provider. The app asks Shopify only for the permissions it needs, requests are verified with Shopify signatures, and order details are only shown after both order number and email match.

7. Your rights

You can ask for access to, correction or erasure of your personal data, restriction of or objection to its processing, and a copy of your data. Merchants can contact us directly. Customers of a store should contact that store, which controls the data; we assist the store with the request. You can also file a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.

8. Changes

We update this policy when the app or the law changes. The date at the top shows the current version. Material changes are announced to merchants in the app or by email.