GDPR Compliance

Last updated: June 28, 2026

1. Introduction

The General Data Protection Regulation (GDPR) and UK GDPR protect the privacy rights of individuals in the European Economic Area (EEA) and United Kingdom. Appziot is committed to GDPR compliance when processing personal data of merchants, authorized users, and end customers whose data we process on behalf of merchants.

This page supplements our Privacy Policy and describes how we meet GDPR-related obligations for our Shopify app and related services.

2. Roles Under GDPR

Depending on the context:

  • Appziot acts as a controller for merchant account data, website visitors, and direct communications with us
  • Appziot acts as a processor for personal data we process on behalf of merchants through their Shopify stores and mobile applications
  • Merchants are controllers of their customer data and are responsible for lawful bases and customer-facing disclosures

3. Your Rights Under GDPR

Where GDPR applies, you may have the following rights:

Right to Access

Request a copy of personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of personal data, subject to legal exceptions.

Right to Restrict Processing

Request limitation of processing in certain circumstances.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Data Portability

Receive personal data you provided in a structured, commonly used, machine-readable format where applicable.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.

4. Legal Basis for Processing

We process personal data under the following legal bases:

  • Contract: Processing necessary to provide the Service under our agreement with merchants
  • Legitimate interests: Securing, maintaining, and improving the Service, fraud prevention, and internal analytics
  • Legal obligation: Compliance with applicable laws, tax requirements, and Shopify platform obligations
  • Consent: Optional marketing communications and non-essential cookies where required

5. Data We Collect

Categories of personal data we may process include:

  • Identity and contact data (name, email, phone)
  • Account and authentication data
  • Store and business configuration data
  • Transaction and billing metadata (processed via Shopify)
  • Technical data (IP address, device identifiers, logs)
  • Usage data (feature interactions, app analytics)
  • Customer data synced from Shopify or mobile apps, where merchants enable those features
  • Push notification tokens and messaging preferences

6. Shopify Mandatory Webhooks

Appziot implements Shopify’s mandatory GDPR webhooks to support merchant compliance obligations:

  • customers/data_request: We compile relevant customer data stored by Appziot and make it available to the merchant to fulfill the customer’s request
  • customers/redact: We delete or anonymize customer personal data linked to the redaction request
  • shop/redact: After uninstall, we delete or anonymize shop-associated data in accordance with Shopify timelines and our retention policy

Merchants must still respond to their customers within applicable legal timeframes. Appziot assists by processing these webhooks on the merchant’s behalf.

7. Data Retention

We retain personal data only as long as necessary for the purposes described in our Privacy Policy, including providing the Service, meeting legal obligations, and resolving disputes. Data associated with uninstalled shops is deleted or anonymized following shop/redact processing, subject to backup retention cycles and legal holds.

8. Data Security

We implement appropriate technical and organizational measures, including encryption in transit, access controls, and secure authentication. See our Data Security page for more information.

9. International Data Transfers

Personal data may be transferred outside the EEA/UK to countries such as India and the United States. Where required, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission or UK authorities, and supplementary measures where appropriate.

10. Subprocessors

We use subprocessors to deliver the Service, including:

  • Shopify (commerce platform and billing)
  • Cloud hosting and database providers
  • Push notification providers
  • Analytics and monitoring providers

Subprocessors are bound by contractual obligations to protect personal data consistent with GDPR requirements.

11. Data Protection Officer

For GDPR-related inquiries, contact our Data Protection contact at:

Email: support@appziot.com

12. Exercising Your Rights

To exercise GDPR rights:

  • Email support@appziot.com with “GDPR Request” in the subject line
  • Include information to verify your identity
  • Clearly state which right(s) you wish to exercise

We respond within one month. Complex or numerous requests may take up to three additional months, with notice where permitted.

If you are an end customer of a merchant using Appziot, please contact the merchant first. Merchants control most customer data processed through their stores and apps.

13. Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concerns.

14. Contact Information

Appziot

Email: support@appziot.com
Address: India