Version 1.3. Effective from 20 September 2026. Earlier versions remain applicable to processing undertaken under those versions.
This policy explains how EUWithdraw processes personal data when merchants install and use the app and when customers submit withdrawal or privacy requests.
1. Operator and contact
EUWithdraw is operated by LAUDATUS LTD, registered in England and Wales, company number 17453960. Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. Privacy and support enquiries: support@euwithdraw.eu. References to EUWithdraw, we or us in this policy mean Laudatus Ltd.
2. Our privacy roles
For customer, order, withdrawal and related workflow data processed on a merchant’s instructions, the merchant normally acts as controller and EUWithdraw as processor. The merchant decides the lawful basis, notices, retention settings and substantive response to customer requests. EUWithdraw may act as an independent controller for its own merchant-account administration, billing records, security, fraud prevention, support and legal compliance. The exact role depends on the processing activity.
3. Data we process
- Merchant and authorised-user data: shop domain and identifiers, Shopify user identifier, settings, permissions, subscription state and security records.
- Customer and order data: name, email, order/customer identifiers, relevant order and product details, withdrawal statement, selected items, dates, status and communications.
- Privacy and review data: request type, verification and handling history, exports, erasure/correction actions, eligibility decision, appeal and merchant review.
- Technical data: IP-derived short-lived rate-limit keys, timestamps, request/webhook identifiers, delivery events, errors, administrative actions and audit records.
EUWithdraw is not designed to require special-category data, passwords or payment-card data. Merchants and customers should not submit sensitive information unless necessary and lawful.
4. Purposes and legal bases
When EUWithdraw acts as processor, it processes data on the merchant’s documented instructions to provide withdrawal intake, order matching, evidence, communication, configured Shopify actions, privacy-request assistance and service security. When EUWithdraw acts as controller, processing may be necessary to perform the merchant contract, comply with law, or pursue legitimate interests in security, reliability, fraud prevention, support and legal claims. Consent is used only for optional processing that actually requires it.
5. Shopify and service providers
EUWithdraw receives data through authorised Shopify APIs, app-proxy requests and webhooks. Depending on the operation, Shopify acts under its direct relationship with the merchant and is not automatically an EUWithdraw subprocessor. EUWithdraw uses Vercel for application hosting, Supabase for the PostgreSQL database and Resend for transactional email. Render is a suspended former host; deletion or expiry of any remaining copies has not yet been confirmed. Details are listed in the Subprocessor Register.
6. International transfers
The primary database region is Paris, France. European hosting does not mean all processing stays in the EEA or UK: Vercel permits US and global processing, Supabase may use international support and subprocessors, and Resend stores customer data, including message content and delivery logs, in the United States even when emails are sent from Ireland. Where international-transfer rules apply, an applicable adequacy decision, Standard Contractual Clauses with the UK Addendum where necessary, or another lawful mechanism is required, together with supplementary safeguards where required. Contact support@euwithdraw.eu for information or a copy of applicable safeguards.
7. Retention and deletion
- Withdrawal and customer data is retained while the merchant account is active and for only as long afterwards as needed to provide the service, follow the merchant’s documented instructions, resolve disputes or meet legal obligations. Merchants can delete individual records where the app provides that control.
- Temporary privacy exports: three days by default.
- Processed webhook payloads: thirty days by default.
- Security, audit and failed-job records are retained only while reasonably needed for service security, troubleshooting, accountability and legal claims, with payloads minimised or removed when no longer needed.
- After uninstall, EUWithdraw deletes merchant data when Shopify sends the authenticated shop-redaction request and in all cases within the period required by Shopify’s API terms, unless continued retention is legally permitted and documented.
Deleted production data can remain temporarily in protected provider backups until the provider’s applicable backup lifecycle expires. It is isolated from ordinary use. If a backup is restored, applicable deletion requests are reapplied before the restored data is returned to ordinary use.
8. Privacy requests
Subject to applicable conditions, individuals may request access, correction, erasure, restriction, portability, objection, withdrawal of consent and safeguards for qualifying automated decisions. Identity verification may be required. When the merchant is controller, EUWithdraw routes or coordinates the request with that merchant. Requests may be submitted through the merchant’s EUWithdraw privacy-request page or by email.
Where the California CCPA/CPRA or another US state privacy law applies, additional rights may include knowing, correcting or deleting personal information and opting out of qualifying sale, sharing or targeted advertising. EUWithdraw does not use merchant customer data for sale or cross-context behavioural advertising in the reviewed service. Applicability, exemptions and roles depend on the merchant and processing context.
9. Automated checks and human review
Merchant-configured rules can check dates, order evidence and other objective conditions. A blocking outcome can be submitted to the merchant for human review and authorised override. EUWithdraw does not determine the legal validity of a withdrawal and does not use this data for unrelated advertising, credit or employment decisions.
10. Cookies, analytics and security
The embedded app uses Shopify authentication and strictly necessary session mechanisms. No application-level behavioural advertising or product analytics was identified in the reviewed code. Hosting providers may maintain operational logs. If non-essential analytics or advertising technology is added, this policy and any required consent flow will be updated before activation.
Security measures include tenant separation, least privilege, encrypted transport, secret protection, input validation, authenticated webhooks, audit trails, retention controls and incident-response procedures. No internet service can guarantee absolute security.
11. Complaints and changes
Individuals may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or another competent supervisory authority under applicable law. Material policy changes will be communicated where required. The version date above identifies the current public text.
