Deluxe Customer Accounts

    Privacy Policy

    Last updated: September 5, 2026

    1. Introduction

    This Privacy Policy ("Policy") describes how Deluxe Customer Accounts ("we," "us," "our," or the "Company") collects, uses, discloses, and safeguards personal data in connection with the Customer Accounts Deluxe application (the "App"), a Shopify-integrated application that provides customer account, loyalty, store credit, wishlist, and related features to merchants operating on the Shopify platform.

    This Policy applies to personal data we process both on behalf of merchants who install the App ("Merchants") and, where applicable, on our own behalf as an independent controller (for example, in relation to Merchant staff accounts and billing records).

    We are committed to processing personal data lawfully, fairly, and transparently, in accordance with the EU General Data Protection Regulation ("GDPR") and other applicable data protection laws.

    Page 1 of 6

    2. Definitions

    • "Personal Data" means any information relating to an identified or identifiable natural person.
    • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
    • "Data Controller" means the entity that determines the purposes and means of Processing Personal Data. In the context of customer data processed through the App, the Merchant is the Data Controller.
    • "Data Processor" means the entity that Processes Personal Data on behalf of a Data Controller. In the context of customer data processed through the App, we act as Data Processor.
    • "Subprocessor" means any third party engaged by us to Process Personal Data on our behalf in connection with the App.

    3. Scope and roles

    Where the App processes Personal Data of a Merchant's customers (order history, loyalty activity, account details, and similar), the Merchant determines the purposes and means of that processing and acts as the Data Controller. We act as a Data Processor with respect to that data, and our processing is governed by the Data Processing Agreement ("DPA") entered into with the Merchant, which forms part of this Policy by reference.

    Where we collect data directly for our own purposes — such as Merchant staff account details, billing, and subscription information — we act as an independent Data Controller for that specific data.

    4. Categories of personal data we process

    We process the following categories of Personal Data through the App:

    a) Merchant account and staff data

    Name, email address, locale, and authentication credentials associated with Merchant staff who access the App's administrative interface, together with billing and subscription details (plan tier, usage, billing status).

    b) Customer account data

    Where a Merchant enables customer-facing features, we process: contact details (name, email, phone number), account authentication identifiers (including identifiers issued by third-party social login providers, where the customer opts to use them), date of birth, gender (where voluntarily provided), profile image, language preference, order and purchasing history, loyalty program status and points balance, store credit balance and transaction history, wishlist contents, and any additional custom fields a Merchant elects to configure.

    Page 2 of 6

    c) Data stored within the Merchant's Shopify environment

    Certain categories of the data described above (including loyalty status, store credit history, wishlist contents, date of birth, gender, profile image, language preference, and referral tracking information) are stored directly within the Merchant's own Shopify customer records, rather than in our internal systems. We access this data via the Shopify Admin API in order to provide the App's functionality.

    d) Data accessed but not retained

    In order to render certain features (such as order history displays, saved addresses, or gift card balances), the App retrieves data directly from Shopify at the time it is needed. This data is used transiently to generate the relevant view and is not separately stored by us.

    e) Usage and diagnostic data

    We collect limited technical and usage information relating to how the App's features are used, in order to maintain, secure, and improve the App.

    5. Legal basis for processing

    Where we act as an independent Data Controller (Section 3), we process Personal Data on the following legal bases under the GDPR:

    • Performance of a contract (Art. 6(1)(b)) — to provide the App and associated services to Merchants;
    • Legitimate interests (Art. 6(1)(f)) — to maintain and secure the App, prevent fraud, and improve our services;
    • Legal obligation (Art. 6(1)(c)) — to meet accounting, tax, and regulatory requirements.

    Where we act as a Data Processor on behalf of a Merchant, the applicable legal basis is determined by the Merchant as Data Controller.

    6. How we use personal data

    We use Personal Data to:

    • Provide and operate the features of the App, including account management, order history, loyalty programs, store credit, wishlists, and returns/exchanges;
    • Facilitate account authentication, including via third-party social login providers where selected by the customer;
    • Send transactional communications, such as one-time passcodes and password reset notifications;
    • Provide technical support to Merchants;
    • Maintain, secure, and improve the App's functionality and reliability;
    • Comply with applicable legal, regulatory, and contractual obligations.

    We do not sell Personal Data, and we do not use customer Personal Data for third-party advertising purposes.

    Page 3 of 6

    7. Categories of recipients and subprocessors

    To provide the App, we engage third-party service providers ("Subprocessors") who process Personal Data on our behalf, strictly limited to what is necessary for their function. We categorize our Subprocessors as follows:

    CategoryPurposeData involved
    Transactional email deliverySending password reset and account verification emailsRecipient email address, message content
    SMS / OTP deliveryDelivering one-time passcodes for phone-based verificationPhone number, verification code
    Social authentication providersEnabling customer sign-in via third-party accounts, at the customer's electionProvider-issued identifier; name/email where made available by the provider
    Reviews platform integration (optional, Merchant-enabled)Synchronizing product reviews with loyalty rewardsCustomer email, order identifier, review content
    AI-assisted support toolingPowering an in-admin assistant used by Merchant staffSupport queries submitted by Merchant staff
    Product analytics (admin interface only)Understanding how Merchant staff interact with the App's administrative dashboardAdmin interface interaction data
    Billing and subscription managementProcessing Merchant subscription and billing statusShop identifier, plan, subscription status
    Cloud infrastructure and hostingHosting our application and database infrastructureAll Personal Data processed by the App

    If a Merchant configures their own email delivery service, transactional emails are sent via that Merchant-controlled service directly, rather than through our Subprocessor.

    A current, named list of our Subprocessors is available upon written request to [email protected]. We will notify Merchants at least 7 days before engaging a new Subprocessor to process Personal Data on our behalf, giving Merchants the opportunity to object on reasonable, documented data protection grounds. New Subprocessors may begin processing during this notice period; if a Merchant raises a valid objection, the Merchant's remedy is to terminate the affected feature or service.

    8. International data transfers

    Our infrastructure is hosted within the European Union. Certain Subprocessors identified in Section 7 may, in connection with their specific function, process Personal Data outside the European Economic Area ("EEA"). Where this occurs, we ensure that appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses, or reliance on an adequacy decision, as required under applicable data protection law.

    Page 4 of 6

    9. Data retention

    We retain Personal Data only for as long as necessary to fulfil the purposes described in this Policy, subject to the following:

    • Merchant staff session and access credentials are deleted immediately upon uninstallation of the App.
    • Customer account records maintained within our own systems, including loyalty and store credit balances recorded there, are deleted immediately upon uninstallation of the App.
    • Personal Data stored within the Merchant's Shopify environment (as described in Section 4(c)) is not automatically deleted upon App uninstallation, as this data resides on the Shopify platform under the Merchant's own account. Merchants seeking removal of this data should contact us using the details in Section 13, or manage it directly within their Shopify administration panel.
    • Verification codes (one-time passcodes, password reset tokens) expire automatically within a short window (10–15 minutes) and are not retained thereafter.
    • Billing and subscription records are retained for the period required to meet applicable accounting, tax, and legal obligations.

    10. Security measures

    We implement technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including:

    • Encrypted (TLS/SSL) connections between the App and its database infrastructure;
    • HTTPS encryption for all data transmitted to and from the App;
    • Authentication of Merchant staff via Shopify's OAuth authentication framework;
    • Customer account credentials are never stored by us — authentication is managed entirely by Shopify's own systems;
    • Cryptographic verification (HMAC signature validation) of all incoming Shopify webhook communications, to prevent tampering or spoofing.

    We continue to invest in the ongoing enhancement of our security practices, including expanding the scope of encryption applied to stored data.

    Page 5 of 6

    11. Your data protection rights

    Where you are an individual whose Personal Data is processed through the App, and subject to applicable law, you may have the right to:

    • Request access to the Personal Data we hold about you;
    • Request correction of inaccurate or incomplete Personal Data;
    • Request erasure of your Personal Data;
    • Request restriction of, or object to, certain processing activities;
    • Request portability of your Personal Data, where technically feasible;
    • Lodge a complaint with your local data protection supervisory authority.

    If you are a customer of a Merchant using the App, we recommend contacting the Merchant directly in the first instance, as they act as the Data Controller for your information. You may also contact us directly at [email protected]. Given that certain relevant data is stored across multiple systems (including the Merchant's own Shopify environment), such requests are currently reviewed and fulfilled manually to ensure completeness. In line with Article 12 GDPR, we aim to respond to verified requests within one month, extendable by a further two months where the request is complex, in which case we will inform you of the extension and the reason for it within the first month.

    12. Children's privacy

    The App is not directed at, and we do not knowingly collect Personal Data from, individuals under the age of 16. If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take steps to delete such information.

    13. Contact us

    For questions regarding this Policy, or to exercise any of the rights described above, please contact us at:

    Deluxe Customer Accounts

    14. Governing law

    This Policy, and any dispute arising in connection with it, shall be governed by the laws of Italy, the jurisdiction in which Deluxe Customer Accounts is established.

    15. Changes to this policy

    We may update this Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. Material changes will be reflected by an updated "Last updated" date at the top of this Policy. We encourage Merchants and their customers to review this Policy periodically.

    Page 6 of 6