Privacy Policy
Last updated: 5 September 2026
This policy explains what the Depozy app (“the app”) accesses, what it stores, and for how long. The app is operated by Mveb. For any question about this policy, write to the address at the bottom of this page.
What the app stores
In its own database the app stores only what it needs to do its job, and nothing that identifies a shopper:
- An authentication session for each store that installs the app — the store domain and the access token issued by Shopify. This is required to call the Shopify API on the merchant’s behalf.
- The merchant’s own settings: whether balances are charged or only authorised, whether retries and reminder emails are on, and the plan chosen.
- The position of the nightly run — which store and which page of orders it reached last — so a store is never skipped. It holds a store domain and a page marker, nothing about a shopper.
- Whether a shopper agreed to a shipping delay, when the merchant moves a charge date more than 30 days out: the order ID, the length of the delay and the answer. Until the shopper answers, the app charges nothing further on that order.
- A request to cancel a pre-order, if a shopper makes one from the link in their email: the order ID, the time of the request and, optionally, the reason the shopper typed. It holds no name, email or card details. The request stops further charges on that order straight away and shows the merchant that a shopper asked to cancel.
- Service records that reference an order by its Shopify ID: attempts to charge a balance, reminders already sent, and a monthly count of deposit orders used for plan limits. These hold an order ID, a date and an outcome — no names, emails, addresses or order contents.
The app does not store any customer personal data. Names, emails, addresses, order contents and payment details are read from Shopify when a page is opened and are never written to our database.
Payment data
The app never sees, handles or stores card numbers. When a customer pays a deposit, Shopify stores the payment method on its own side and gives the app a reference (a payment mandate). The app uses that reference to ask Shopify to collect the remaining balance according to the schedule the merchant configured. All money movement is performed by Shopify and the store’s payment provider.
What the app reads from Shopify
- Products and selling plans — to create and attach deposit plans.
- Orders with an outstanding balance — to show them to the merchant and collect the remaining payment.
- Payment mandates and payment terms — to charge the balance that the customer already authorised at checkout, and to move a due date when the merchant asks.
- The customer record attached to an order — only to address the balance email Shopify sends on the merchant’s behalf, and to pass the order and customer reference to Shopify Flow when the merchant has built an automation. It is read at the moment it is needed and never written to our database.
Emails to customers
The app can ask Shopify to send a shopper the standard invoice email for an unpaid balance. Every such email is sent by Shopify, from the merchant’s store, using the store’s own templates — the app operates no mail server and never holds a shopper’s address.
This happens in two cases. Scheduled reminders before or after a due date are off by default and are switched on by the merchant. Separately, when a balance charge fails repeatedly, the app sends one invoice so the shopper can pay with another card; automatic retries are on by default and the merchant can switch them off in the app’s settings. A shopper receives at most one email of each kind per order. Reminders stop once a balance is more than 30 days overdue; the payment link that follows a failed charge is part of the retry ladder and is sent once, whatever the delay.
Sharing
No data is sold, rented or shared with third parties. The app uses no advertising networks and no analytics that identify individuals.
Retention and deletion
When the app is uninstalled, the store session is deleted. Shopify also sends mandatory data-deletion requests 48 hours after uninstall (shop/redact), and on receipt the app deletes everything belonging to that store: sessions, settings, the record of balance charge attempts, the log of reminders sent, the count of deposit orders, and any cancellation requests and delay answers shoppers of that store left. On a customer deletion request (customers/redact) the app deletes every service record that references the orders named in the request — charge attempts, reminders, the order count, and that shopper's cancellation request with whatever note they typed. The app stores no customer names, addresses, emails or card details at any point.
If a store never sends those requests — an uninstall notice can be missed, and a deletion request arrives only once — the app does not keep the data anyway: a store with no session left is treated as gone, and its records are deleted on the same 90-day schedule.
Service records that reference an order — charge attempts and the reminder log — are kept for at most 90 days after the balance is settled, and are then deleted automatically. Unsettled balances are kept until they are resolved: deleting them early would make the app charge the same customer twice, or send them the same reminders from scratch. A cancellation request is kept as long as the order it belongs to, for the same reason — it is what stops the charges.
Two records are kept longer, for up to 400 days, and only because deleting them sooner would harm the customer. A balance the merchant has given up on stays marked as abandoned: without that mark the app would start collection again from scratch and email the customer the same notices every few months. A record that an order used a deposit is kept for the same period, because pre-orders can run for a year and the app must still recognise the order after the merchant deletes the payment plan. Both records hold an order identifier and dates — no names, addresses, emails or card details.
Security
- All traffic runs over TLS. The app is served only over HTTPS.
- The app runs on Google Compute Engine, where disk storage is encrypted at rest by the platform. Database backups are written to the same encrypted disk, are never copied off it, and are rotated after 14 days.
- Access to the production server is limited to the app operator, over SSH key authentication only; password login is disabled.
- Development uses a separate local database. Production data is never copied into it.
- Requests to Shopify made on a merchant’s behalf are logged with the store domain and the order affected.
Data processing agreement
For personal data belonging to a merchant’s customers, the merchant is the data controller and the app is the data processor. By installing the app the merchant accepts this policy as the data processing agreement between us. The app processes that data only to provide the functionality described above, only on the merchant’s instructions, and it engages no sub-processors other than the hosting provider named in the Security section. A merchant who needs a separately signed agreement can request one at the address below.
Security incidents
If personal data is exposed or lost, affected merchants are notified by email within 72 hours of discovery, together with what happened, what data was involved and what was done about it. Shopify is notified in parallel. Access is revoked and credentials rotated first, before any investigation continues.
Contact
Questions, data requests and complaints: support@mveb.org. We reply within two business days.