1. Who we are & our role
EU Withdrawly (“EU Withdrawly”, “we”, “us” or “our”) is a Shopify application that helps merchants operate the statutory EU right of withdrawal (Widerruf).
Our roles differ by data type. For personal data that shoppers submit through the withdrawal form on a merchant’s store, the merchant is the data controller and we act as a data processor on their behalf, under our Data Processing Agreement (DPA). For data about the merchant’s own account, billing and use of the app, and for the visitors to this website, we act as controller.
This policy is an integral part of the terms of use of our website and app, alongside the DPA provided to merchants. We may update it as described in section 14.
2. Data we collect
We practise data minimisation and collect only what is needed to handle a withdrawal request and run the service:
From shoppers (via the withdrawal form)
Order number, email address, an optional free-text withdrawal reason, the chosen language/locale, and technical metadata such as submission timestamp. Providing a reason is optional; the EU right of withdrawal does not require one.
From the merchant’s store (via Shopify APIs)
The store domain, and order, return and fulfilment metadata needed to link a request to its order and — where enabled — to sync with Shopify Returns and Flow. We do not collect payment card data.
Merchant account & billing
Store identifiers, staff contact details you provide, app settings and subscription/billing status. Billing is handled by Shopify; we do not store card details.
Technical & log data
Server logs, an internal audit trail of actions on each request, and an email delivery log (recipient, status, timestamp). Our website sets no advertising or analytics cookies.
3. How & why we use it (legal bases)
We use personal data for the following purposes, each with a GDPR legal basis:
- Handle the withdrawal — link the request to its order, record it and keep an audit trail. Basis: performance of the merchant’s contract with the shopper / the merchant’s legal obligation.
- Send emails — confirmation, status and merchant-notification emails in the shopper’s language. Basis: contract performance / legitimate interests.
- AI reason triage — categorise the withdrawal reason after redacting personal data (see section 4). Basis: legitimate interests.
- Analytics — aggregated, store-level KPIs and breakdowns; not used to profile individual shoppers. Basis: legitimate interests.
- Compliance & exports — audit PDF and DPA/compliance exports for the merchant. Basis: legal obligation / legitimate interests.
- Run & secure the service — authentication, billing, troubleshooting and abuse prevention. Basis: contract / legitimate interests / legal obligation.
4. AI & automated processing
To categorise withdrawal reasons and generate short summaries, we use a third-party AI service. Before any text is sent to the AI, we redact direct personal identifiers (such as the shopper’s name and email) from it. The AI receives only the minimised reason text.
No decision that produces legal or similarly significant effects is fully automated. The app can, if the merchant opts in, auto-approve a refund only within safe limits the merchant sets (inside the 14-day window, unfulfilled orders, under a value cap). Requests are never rejected automatically — a rejection is always a human decision.
6. International data transfers
Some of the service providers we use may process data on servers outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and/or an adequacy decision. You can request details of the safeguards in place.
7. Data retention
We keep personal data only as long as necessary for the purposes above, including statutory withdrawal and record-keeping periods that apply to the merchant. Withdrawal records support the merchant’s legal obligation to evidence a compliant withdrawal process.
When Shopify sends a customers/redact or shop/redact request, or when a merchant uninstalls the app, we delete or irreversibly anonymise the associated personal data within the timeframe Shopify requires (currently 30 days for redaction requests), except where a longer period is required by law. Stored access credentials are encrypted and expire automatically.
8. Your GDPR rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
Because for shopper data the merchant is the controller, please direct shopper requests to the store you purchased from; we will support that merchant in fulfilling your request.
9. Shopify mandatory data requests
As a Shopify app, we implement Shopify’s mandatory compliance webhooks and respond to them automatically:
customers/data_request— we compile the personal data we hold about the identified customer for the merchant to provide.customers/redact— we delete or anonymise that customer’s personal data.shop/redact— after a store uninstalls, we delete or anonymise that store’s data.
10. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), encryption of stored access credentials, access controls, PII redaction before AI processing, and an audit trail of actions on each request. No method of transmission or storage is completely secure, but we work to protect your data and to notify the relevant parties of a breach as required by law.
11. Cookies & tracking
This website sets no advertising or third-party analytics trackers. We use only strictly necessary storage — for example, a browser localStorage entry that remembers your language choice. As no uniform standard for Do-Not-Track (“DNT”) signals has been finalised, the website does not currently respond to them.
12. Merchant responsibilities
As the controller of shopper data, each merchant is responsible for having a lawful basis to process it, for providing shoppers with their own privacy information and Widerrufsbelehrung, and for using the app in line with our DPA and applicable law. EU Withdrawly provides the tooling to operate a compliant withdrawal process but does not provide legal advice.
13. Children
The app is intended for merchants and their adult customers. We do not knowingly collect personal data from children below the age of digital consent in their country. If you believe a child has provided us data, contact us and we will delete it.
14. Changes & contact
We update this notice as needed to stay compliant with applicable laws and to reflect changes to the service. The current version is indicated by the “Last updated” date and takes effect once published; material changes will be communicated to merchants where appropriate.
For questions or requests about your data, reach out through the store you purchased from or through your Shopify admin.
Have questions about your data?
Our team is here to help you understand your rights and available choices.