Started COD Order Editor

Legal

Privacy Policy

How Started COD Order Editor handles merchant, order, and customer information.

Last updated: July 26, 2026

This Privacy Policy describes how STARTED DIGITAL SRL, located at Str. Floreiului, nr. 566, Valea Doftanei, Prahova, Romania (“we”, “us”, or “our”), processes information when merchants install or use COD Order Editor (the “App”) with a Shopify store.

Information the App processes

The App processes only the information required to display and replace eligible Cash on Delivery orders, including:

  • Shopify shop domain and installation credentials;
  • order identifiers, order status, products, quantities, prices, shipping, and order notes;
  • customer name, email, phone number, and shipping or billing address when present on the selected order;
  • an audit record linking an original order to its replacement order;
  • a security access log containing the shop, Shopify staff identifier, order identifier, action, result, and timestamp; the log does not store the customer's name, email, phone number, or address;
  • monthly plan usage, including an aggregate edit count and the original order identifier used to prevent duplicate counting;
  • privacy request metadata needed to satisfy Shopify data requests and redaction webhooks.

The App does not collect payment-card information and does not process the customer's Cash on Delivery payment.

How information is used

Information is used to:

  • authenticate the merchant and provide the App in Shopify Admin;
  • verify whether an order is eligible for editing;
  • create the replacement order requested by the merchant;
  • cancel and restock the original order after successful replacement;
  • prevent duplicate replacements and diagnose failed operations;
  • provide support, maintain security, and comply with legal obligations.
We do not sell personal information or use order and customer data for advertising.

Legal basis

We process merchant and customer information as necessary to provide the App under our agreement with the merchant, comply with legal obligations, and pursue legitimate interests such as security, fraud prevention, and service reliability.

Service providers and international transfers

The App is hosted using Railway and stores production data in managed PostgreSQL infrastructure. Shopify provides the commerce platform and order data. These providers may process information in countries other than the merchant's or customer's country and apply their own contractual and security safeguards.

We disclose information only to service providers that help operate the App, to comply with law, or to protect legal rights. We do not disclose information for independent marketing purposes.

Retention and deletion

Installation sessions are retained while the App is installed. Completed, failed, or rolled-back replacement audit records are retained for 180 days after their last update. Completed privacy request records are retained for 30 days after completion. Personal data access logs are retained for 365 days for security monitoring and compliance. Monthly usage and free-edit reservation records are retained for up to 365 days.

When Shopify sends an app-uninstalled or shop-redaction request, the App deletes the shop's sessions, replacement records, privacy-request records, access logs, and plan-usage records. Customer redaction requests delete records, access logs, and order-level usage reservations associated with that customer's orders. These deletion events take precedence over the standard periods. Backups, if applicable, expire under the infrastructure provider's retention schedule.

Security

We use encrypted HTTPS connections, encrypted production secrets, access controls, restricted database access, personal-data access logging, and operational monitoring. No method of transmission or storage is completely secure, but we maintain safeguards appropriate to the information processed.

Merchant and customer rights

Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing of personal information. Customers should normally contact the Shopify merchant that collected their information. We support merchants and Shopify when responding to verified privacy requests.

Changes

We may update this policy to reflect changes to the App, legal requirements, or our service providers. The “Last updated” date identifies the current version.

Contact

STARTED DIGITAL SRL

Str. Floreiului, nr. 566, Valea Doftanei, Prahova, Romania

office@started.ro