Contents
  1. Compliance summary
  2. Who controls what
  3. Fraud prevention & profiling
  4. Sub-processors
  5. Retention schedule
  6. Making a data request
  7. Shopify compliance webhooks
  8. What merchants must do
  9. Data Processing Agreement
  10. Breach notification

1. Compliance summary

QuestionAnswer
Do you sell personal data?No. Never, to anyone, for any purpose.
Is there a shared blacklist across merchants?No. All risk data is scoped to a single store and never queried across stores.
Do you store buyers' phone numbers for fraud checks?No — only irreversible keyed hashes of them.
Is buyer contact data encrypted at rest?Yes for order contacts and locker shipments. Abandoned-checkout records are currently plain text.
Can an order be automatically refused by the system?No. The strongest automated outcome is requiring card prepayment.
Data request turnaround30 days, free of charge.
Deletion after uninstallAutomatic, triggered by Shopify 48 hours after uninstall.
Are Shopify's mandatory privacy webhooks implemented?Yes — all three.
Is a DPA available?Yes, on request. See section 9.

2. Who controls what

Hybrid sits between two relationships, and GDPR treats them differently.

DataControllerOur role
Shoppers who submit a COD formThe merchantProcessor, acting on the merchant's instructions
The merchant's own account and billingHybridController

As a processor we act only on documented merchant instructions, do not use buyer data for our own purposes, and do not combine one merchant's buyer data with another's.

3. Fraud prevention & profiling

This is the part of Hybrid with the highest privacy impact, so here it is in full.

Cash on delivery lets anyone order goods with no payment commitment. Merchants lose money on undeliverable parcels, which is why COD apps screen orders. Screening means profiling, and profiling engages GDPR. Our approach is to keep the fraud signal while removing as much identifiability as possible.

What we store, and what we deliberately do not

Stored: a keyed HMAC-SHA256 hash of each identifier, a score, the matched signal types, and the ruleset version that produced the decision.

Not stored: the phone number, email address, street address or IP itself. These are hashed on arrival. The risk database contains nothing readable — there is no view, export or query that returns a shopper's contact details from it, for us or for anyone who obtained the database.

No cross-merchant blacklist

Some COD fraud tools pool shopper data across all their merchants. Hybrid does not. Every risk record carries the store it originated from, and is only ever read back within that store. A shopper flagged at one store starts clean at every other store. This is enforced in the data model, not by policy.

This matters legally: pooling would make us a controller of a cross-merchant profiling database in our own right, with a far heavier justification burden. Keeping data shop-scoped keeps us a processor acting for one merchant at a time.

Article 22 position

GDPR Art. 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. Our position:

Legitimate interests balancing

We rely on Art. 6(1)(f) for fraud prevention. The balancing test, in short:

4. Sub-processors

The complete list of third parties that may process personal data on our behalf:

Sub-processorPurposeDataWhen
ShopifyThe platform the app runs onOrders, customers, productsAlways
Hostinger International LimitedApplication hosting and databaseAll stored recordsAlways
FOXPOSTParcel locker deliveryRecipient name, phone, locker, COD amountOnly if locker shipping is enabled
The merchant's own SMTP providerSending the merchant's configured emailsRecipient address and email contentOnly if email automations are enabled

We notify merchants before adding a sub-processor that handles buyer data. To be told of changes, email info.hybridcodform@gmail.com.

5. Retention schedule

DataRetainedBasis
Risk identifiers, events, decisions24 monthsPseudonymised and shop-scoped; needed across seasonal COD fraud cycles
Device signalsUntil expiry timestampShort-lived by design
Order contacts, locker shipmentsLife of the installationNeeded to fulfil and support orders
Abandoned checkoutsLife of the installationMerchant's own recovery workflow
Merchant account and settingsLife of the installationContract
Everything, after uninstallErased on Shopify's 48-hour signalNo longer necessary

The 24-month risk window is longer than a typical contact-data retention period, and deliberately so. What is retained is not contact data: it is a set of one-way hashes tied to one store, which cannot identify or reach anybody. Retaining it across two seasons is what allows a merchant to recognise a repeat undeliverable order. Raw contact details are never kept for this purpose.

6. Making a data request

Any person whose data Hybrid holds can request access, correction, erasure, restriction, portability, or object to processing.

If you are a shopper

Contact the store you ordered from — they are the controller. Or come to us directly and we will action it.

info.hybridcodform@gmail.com →

If you are a merchant

Email us, or trigger the request through Shopify — the customer privacy tools in your admin reach us automatically.

info.hybridcodform@gmail.com →
What to include

The store domain, and the email or phone used on the order. We need these because our risk records hold no readable contact details — locating a specific person means re-hashing the details you give us and matching. Without them we genuinely cannot find your records rather than merely declining to.

We respond within 30 days, free of charge. We may ask you to verify your identity first, so we do not disclose your data to someone claiming to be you.

7. Shopify compliance webhooks

Shopify requires every App Store app to implement three privacy webhooks. Hybrid implements all three, verifies each by HMAC signature, and acts on them automatically:

TopicOur action
customers/data_requestRecord the request and compile what we hold for that shopper, within 30 days.
customers/redactDelete that shopper's order contacts, locker shipments, abandoned checkouts and risk decisions; re-hash the supplied identifiers and delete every matching risk row; prune any risk profile left with no identifiers.
shop/redactErase every record tied to that store, across every table holding shop-scoped data.

8. What merchants must do

Installing Hybrid does not make a store GDPR compliant. As the controller of your shoppers' data, you remain responsible for:

Not legal advice

This page describes how Hybrid works so you can assess it. It is not legal advice, and your obligations depend on your jurisdiction and how you operate. Consult a qualified adviser for your own compliance position.

9. Data Processing Agreement

Merchants who need a signed Data Processing Agreement covering Art. 28 — subject matter and duration, nature and purpose, categories of data and data subjects, sub-processor terms, security measures, audit rights and deletion on termination — can request one at info.hybridcodform@gmail.com.

10. Breach notification

If a personal data breach occurs, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the breach presents a risk to people's rights, and inform affected merchants without undue delay so they can meet their own notification duties toward their shoppers.

Contact

Data protection: info.hybridcodform@gmail.com
Controller: Benjámin Márk, Hungary, 7562 Segesd, Dózsa tér 5
See also: Privacy Policy · Terms of Service · Contact