1. Compliance summary
| Question | Answer |
|---|---|
| Do you sell personal data? | No. Never, to anyone, for any purpose. |
| Is there a shared blacklist across merchants? | No. All risk data is scoped to a single store and never queried across stores. |
| Do you store buyers' phone numbers for fraud checks? | No — only irreversible keyed hashes of them. |
| Is buyer contact data encrypted at rest? | Yes for order contacts and locker shipments. Abandoned-checkout records are currently plain text. |
| Can an order be automatically refused by the system? | No. The strongest automated outcome is requiring card prepayment. |
| Data request turnaround | 30 days, free of charge. |
| Deletion after uninstall | Automatic, triggered by Shopify 48 hours after uninstall. |
| Are Shopify's mandatory privacy webhooks implemented? | Yes — all three. |
| Is a DPA available? | Yes, on request. See section 9. |
2. Who controls what
Hybrid sits between two relationships, and GDPR treats them differently.
| Data | Controller | Our role |
|---|---|---|
| Shoppers who submit a COD form | The merchant | Processor, acting on the merchant's instructions |
| The merchant's own account and billing | Hybrid | Controller |
As a processor we act only on documented merchant instructions, do not use buyer data for our own purposes, and do not combine one merchant's buyer data with another's.
3. Fraud prevention & profiling
This is the part of Hybrid with the highest privacy impact, so here it is in full.
Cash on delivery lets anyone order goods with no payment commitment. Merchants lose money on undeliverable parcels, which is why COD apps screen orders. Screening means profiling, and profiling engages GDPR. Our approach is to keep the fraud signal while removing as much identifiability as possible.
Stored: a keyed HMAC-SHA256 hash of each identifier, a score, the matched signal types, and the ruleset version that produced the decision.
Not stored: the phone number, email address, street address or IP itself. These are hashed on arrival. The risk database contains nothing readable — there is no view, export or query that returns a shopper's contact details from it, for us or for anyone who obtained the database.
No cross-merchant blacklist
Some COD fraud tools pool shopper data across all their merchants. Hybrid does not. Every risk record carries the store it originated from, and is only ever read back within that store. A shopper flagged at one store starts clean at every other store. This is enforced in the data model, not by policy.
This matters legally: pooling would make us a controller of a cross-merchant profiling database in our own right, with a far heavier justification burden. Keeping data shop-scoped keeps us a processor acting for one merchant at a time.
Article 22 position
GDPR Art. 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. Our position:
- The strongest automated outcome is requiring card prepayment — the purchase can still proceed. No order is automatically refused or cancelled.
- Thresholds are set by the merchant, not imposed by us.
- Merchants can allowlist any shopper, overriding the score entirely.
- Every decision records its contributing signals and ruleset version, so it is explainable and contestable after the fact.
- A shopper can request human review via the merchant or via us.
Legitimate interests balancing
We rely on Art. 6(1)(f) for fraud prevention. The balancing test, in short:
- Our interest: preventing losses from undeliverable COD orders — a purpose GDPR Recital 47 explicitly recognises as legitimate.
- Necessity: there is no less intrusive way to detect repeat undeliverable orders than comparing against prior orders at that store.
- Impact on the shopper: reduced by pseudonymisation, shop-scoping, a capped outcome that never blocks a purchase outright, and automatic expiry.
4. Sub-processors
The complete list of third parties that may process personal data on our behalf:
| Sub-processor | Purpose | Data | When |
|---|---|---|---|
| Shopify | The platform the app runs on | Orders, customers, products | Always |
| Hostinger International Limited | Application hosting and database | All stored records | Always |
| FOXPOST | Parcel locker delivery | Recipient name, phone, locker, COD amount | Only if locker shipping is enabled |
| The merchant's own SMTP provider | Sending the merchant's configured emails | Recipient address and email content | Only if email automations are enabled |
We notify merchants before adding a sub-processor that handles buyer data. To be told of changes, email info.hybridcodform@gmail.com.
5. Retention schedule
| Data | Retained | Basis |
|---|---|---|
| Risk identifiers, events, decisions | 24 months | Pseudonymised and shop-scoped; needed across seasonal COD fraud cycles |
| Device signals | Until expiry timestamp | Short-lived by design |
| Order contacts, locker shipments | Life of the installation | Needed to fulfil and support orders |
| Abandoned checkouts | Life of the installation | Merchant's own recovery workflow |
| Merchant account and settings | Life of the installation | Contract |
| Everything, after uninstall | Erased on Shopify's 48-hour signal | No longer necessary |
The 24-month risk window is longer than a typical contact-data retention period, and deliberately so. What is retained is not contact data: it is a set of one-way hashes tied to one store, which cannot identify or reach anybody. Retaining it across two seasons is what allows a merchant to recognise a repeat undeliverable order. Raw contact details are never kept for this purpose.
6. Making a data request
Any person whose data Hybrid holds can request access, correction, erasure, restriction, portability, or object to processing.
If you are a shopper
Contact the store you ordered from — they are the controller. Or come to us directly and we will action it.
info.hybridcodform@gmail.com →If you are a merchant
Email us, or trigger the request through Shopify — the customer privacy tools in your admin reach us automatically.
info.hybridcodform@gmail.com →The store domain, and the email or phone used on the order. We need these because our risk records hold no readable contact details — locating a specific person means re-hashing the details you give us and matching. Without them we genuinely cannot find your records rather than merely declining to.
We respond within 30 days, free of charge. We may ask you to verify your identity first, so we do not disclose your data to someone claiming to be you.
7. Shopify compliance webhooks
Shopify requires every App Store app to implement three privacy webhooks. Hybrid implements all three, verifies each by HMAC signature, and acts on them automatically:
| Topic | Our action |
|---|---|
customers/data_request | Record the request and compile what we hold for that shopper, within 30 days. |
customers/redact | Delete that shopper's order contacts, locker shipments, abandoned checkouts and risk decisions; re-hash the supplied identifiers and delete every matching risk row; prune any risk profile left with no identifiers. |
shop/redact | Erase every record tied to that store, across every table holding shop-scoped data. |
8. What merchants must do
Installing Hybrid does not make a store GDPR compliant. As the controller of your shoppers' data, you remain responsible for:
- Your own privacy notice, telling shoppers what you collect through the checkout form and why.
- A lawful basis for collecting it — normally contract performance for order fulfilment.
- Disclosing fraud screening if you enable it, since shoppers should know their order may be scored.
- Cookie and tracking consent where your storefront or marketing pixels require it.
- Answering your shoppers' data requests — we support you, but they are addressed to you.
This page describes how Hybrid works so you can assess it. It is not legal advice, and your obligations depend on your jurisdiction and how you operate. Consult a qualified adviser for your own compliance position.
9. Data Processing Agreement
Merchants who need a signed Data Processing Agreement covering Art. 28 — subject matter and duration, nature and purpose, categories of data and data subjects, sub-processor terms, security measures, audit rights and deletion on termination — can request one at info.hybridcodform@gmail.com.
10. Breach notification
If a personal data breach occurs, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the breach presents a risk to people's rights, and inform affected merchants without undue delay so they can meet their own notification duties toward their shoppers.
Contact
Data protection: info.hybridcodform@gmail.com
Controller: Benjámin Márk, Hungary, 7562 Segesd, Dózsa tér 5
See also: Privacy Policy · Terms of Service · Contact