⚠ Before publishing

Every HIGHLIGHTED field below must be replaced with real details. A privacy policy that names no identifiable controller does not satisfy GDPR Art. 13, and publishing it in this state is worse than publishing nothing.

Contents
  1. Who we are
  2. Controller and processor
  3. What we collect
  4. Legal bases
  5. The risk engine
  6. How long we keep it
  7. Who else sees it
  8. International transfers
  9. Security
  10. Your rights
  11. Deletion & uninstall
  12. Hybrid Workspace & social accounts
  13. Changes

1. Who we are

Hybrid — COD & Checkout Form ("Hybrid", "we", "us") is a Shopify application operated as a sole trader by Benjámin Márk, trading from Hungary, 7562 Segesd, Dózsa tér 5, TAX / VAT REG. NO. IF APPLICABLE.

The same operator also runs Hybrid Workspace (team.hybridcod.com), a team workspace with a social scheduler that can connect a Facebook Page or Instagram account. It handles different data in a different way, so it has its own section: section 12. Sections 2 to 11 describe the Shopify app.

For privacy matters, contact info.hybridcodform@gmail.com. We are not required to appoint a Data Protection Officer, and have not appointed one.

2. Controller and processor

Hybrid handles two different kinds of people's data, in two different legal roles. The distinction matters, because it determines who you ask for what.

If you are a shopper and want your data accessed or erased, the fastest route is to contact the store you ordered from. They control it, and we act on their instruction. You can also contact us directly and we will action it — see Your rights.

It is the merchant's responsibility to establish a lawful basis for collecting buyer data through the form, and to present their own privacy notice to their shoppers.

3. What we collect

From the merchant's Shopify store

On install, Hybrid requests these Shopify scopes. Each maps to a feature; we do not request scopes we do not use.

AccessWhy we need it
Orders & draft orders (read/write)Create the COD order or prefilled card checkout from the form, apply bundle and card-payment discounts, tag orders placed through Hybrid.
Products (read)Render buy buttons, bundle tiers and upsell offers with real titles, images, variants and prices.
Protected customer dataBuyer name, email, phone and address, so the order can be created and fulfilled.
Fulfilments (write)Attach a real tracking number when a locker parcel is created.
Cart transformsApply bundle and card-payment discounts in the Shopify cart and checkout.
WebhooksOrder and fulfilment events that drive delivery emails and keep in-app analytics accurate.
Theme app extensionRenders the form on the storefront. Only active once the merchant enables it in their theme.

Product catalogue data is fetched live from Shopify when needed. It is not duplicated into our database.

From shoppers using the form

When a shopper submits a Hybrid checkout form, we store the following on the merchant's behalf:

RecordContainsProtection at rest
Order contactBuyer name and email, against the Shopify order IDEncrypted
Locker shipmentRecipient name, phone, email, chosen pickup point, COD amountEncrypted
Abandoned checkoutBuyer name and email, cart totals, recovery linkStored in plain text
Risk identifiersPhone / email / address / device / IPIrreversible keyed hash only — never the raw value
Device signalsCoarse, non-reversible browser and device summaryHashed, with a hard expiry timestamp
Accuracy note for the operator — remove before publishing

Abandoned-checkout name and email are genuinely stored unencrypted, while order contacts and locker shipments use the EncryptedOrPlaintext cast. The table above states that truthfully rather than over-claiming. Applying the same cast to abandoned_checkouts would let you delete this note and mark the row encrypted.

Merchant-supplied credentials

If a merchant configures email sending or locker shipping, we store the SMTP and carrier credentials they enter. These are encrypted at rest, are never displayed back in plain text, and are used only to act on that merchant's behalf.

4. Legal bases

PurposeBasis (GDPR Art. 6)
Operating the app for a merchant who installed itContract — Art. 6(1)(b)
Creating and fulfilling a buyer's orderProcessed for the merchant, on their basis, as their processor
COD fraud prevention and risk scoringLegitimate interests — Art. 6(1)(f): preventing losses from undeliverable cash-on-delivery orders
Service emails to merchants about their accountContract — Art. 6(1)(b)
Responding to legal and regulatory obligationsLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have weighed that interest against the rights of the people involved. The outcome of that balancing is described in the next section, and in more detail on our GDPR page.

5. The risk engine

Hybrid includes COD fraud prevention. Because this involves profiling, we describe it in full rather than burying it.

Three design choices that limit the impact

Identifiers are never stored raw. Phone numbers, emails, addresses, device and IP identifiers are converted to a keyed one-way hash (HMAC-SHA256) before storage. The database holds no readable contact details for risk purposes — not to us, and not to anyone who obtained a copy of it.

Every record is scoped to a single store. Risk data carries the shop it came from, and is only ever queried within that shop. There is no shared or cross-merchant blacklist. A shopper flagged at one store is not flagged at another, and merchants cannot see each other's risk data.

Device signals expire by design. Device and browser signals are stored with a hard expiry timestamp and are pruned automatically.

How a decision is made

When an order is placed, Hybrid re-hashes the submitted details, looks for matches within that store's own history, and produces a score. The score maps to one of three outcomes, configured by the merchant: allow, warn the merchant, or require_card — asking the shopper to prepay by card instead of cash on delivery.

Each decision is stored with the ruleset version that produced it, so any outcome can be explained after the fact.

Automated decision-making (Art. 22)

We have designed this to stay within the safeguards GDPR expects:

6. How long we keep it

DataRetained for
Risk identifiers, risk events, risk decisions24 months, then automatically pruned
Device signalsUntil their expiry timestamp — far shorter than 24 months
Order contacts and locker shipmentsWhile the app is installed; erased on uninstall or on request
Abandoned checkoutsWhile the app is installed; erased on uninstall or on request
Merchant account, settings and credentialsWhile the app is installed; erased after uninstall
All shop data after uninstallErased when Shopify notifies us, 48 hours after uninstall

Why 24 months for risk data

Cash-on-delivery fraud is seasonal and repeats slowly; a shorter window lets repeat offenders age out of a merchant's own history and re-order. We consider 24 months proportionate because of what is actually retained: not names, numbers or addresses, but irreversible hashes scoped to one store, which cannot be read back or used to contact, identify or profile anyone outside that store's own order history. Raw contact details are not kept for this purpose at any point.

7. Who else sees it

We do not sell, rent, or share personal data for anyone else's marketing. Data reaches a third party only where a feature the merchant switched on requires it:

RecipientWhat they receiveWhen
ShopifyThe order and customer details, written into the merchant's own storeAlways — this is the app's core function
FOXPOST (locker carrier)Recipient name, phone, chosen locker, COD amountOnly if the merchant enables locker shipping
The merchant's own SMTP providerThe emails the merchant configured, and their recipientsOnly if the merchant enables email automations
Hostinger International LimitedStores the encrypted records described aboveAlways
Meta Platforms (Facebook, Instagram)The posts a Hybrid Workspace user scheduled — image and caption — and the requests needed to publish them and read their counts. Nothing about shoppers. See section 12Only if a workspace user connects a Facebook Page or Instagram account

We may also disclose data where legally compelled to, or to establish or defend legal claims.

8. International transfers

Hybrid's servers are located in Frankfurt, Germany (EU), and the records described above stay there — they are not transferred outside the EEA by us. Shopify, FOXPOST and any SMTP provider a merchant chooses to enable are separate controllers or processors under their own terms, and any transfer they make outside the EEA rests on their own safeguards.

9. Security

No system is perfectly secure. If a breach affects your personal data and presents a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected people where the law requires it.

10. Your rights

If you are in the UK, EEA, or another region with comparable law, you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent was the basis.

To exercise any of these, email info.hybridcodform@gmail.com. Include the store domain you ordered from and, if you have it, an order number — without these we often cannot locate records, since we hold no readable contact details for risk data.

We respond within 30 days. There is no charge. We may ask you to verify your identity before acting, to avoid disclosing your data to someone else.

If you are unhappy with our response you can complain to your local data protection authority. In the UK that is the ICO (ico.org.uk).

11. Deletion and uninstall

Hybrid implements all three of Shopify's mandatory privacy webhooks, and acts on them automatically:

WebhookWhat happens
customers/data_requestWe record the request and compile what we hold for that shopper, within 30 days.
customers/redactWe delete that shopper's order contacts, locker shipments, abandoned checkouts and risk decisions, and delete their risk identifiers by re-hashing the supplied details and removing every match.
shop/redactSent 48 hours after uninstall. We erase every record tied to that store — settings, credentials, contacts, shipments, analytics and risk data.

Because risk identifiers are hashes rather than raw values, erasing a specific person means re-hashing the details they supply and deleting the matching rows. This is why an erasure request needs the store domain and, ideally, the email or phone used on the order.

12. Hybrid Workspace and connected social accounts

This section is about Hybrid Workspace, not the Shopify app. A signed-in member of a workspace can connect a Facebook Page or an Instagram business account, schedule posts to it from their own content library, and see how those posts performed. Nothing in it touches shoppers or orders, and the Shopify app never contacts Facebook or Instagram.

For the account data below we are the controller. The images and captions people schedule are their own work, which we process for them in order to publish.

What you are asked to allow, and what we use each permission for

Connecting uses Facebook Login. You choose which Pages and accounts to share, and we receive nothing about any you did not select. We ask for these permissions and use each one for exactly one purpose:

PermissionWhat we use it for
pages_show_listShow you the Pages you manage so you can pick which to connect.
pages_manage_postsPublish the posts you scheduled to the Page you connected.
pages_read_engagementRead the Page's name and picture, and the share and reaction counts of posts we published.
pages_read_user_contentCount the comments on posts we published. Only the number is kept; the comments themselves are never stored.
read_insightsRead the insight counts for posts we published to a Page.
instagram_basicIdentify the Instagram account linked to the Page: its ID, username and profile picture.
instagram_content_publishPublish the posts you scheduled to that Instagram account.
instagram_manage_insightsRead the like, comment, save and reach counts of posts we published to Instagram.
business_managementLet Facebook's account picker offer Pages that belong to a business portfolio. We never read or change your business settings.

What we store

The counts are totals handed to us by Meta. They identify nobody, and we have no route to the people behind them.

What we do not do

Legal basis, and how long we keep it

We process this to provide the scheduler the workspace member asked for (Art. 6(1)(b)), on the permissions they chose to grant in Facebook's own dialog. They can withdraw at any time by disconnecting.

Everything above is kept only while the account stays connected. Disconnecting deletes it immediately — the tokens, the account record, every scheduled post for it, every publishing log, and every count and reading. There is no soft-delete or retention window. Routine database backups are overwritten on their normal cycle and are not used to restore a deleted connection. The member's own images and captions are not deleted, because they are their work and not Facebook or Instagram data.

How to delete it

Disconnect the account under Social accounts in team.hybridcod.com/settings, or ask us to do it. The full steps, and exactly what each route removes, are on our data deletion page. You can also remove Hybrid from Facebook's side under Business integrations, which stops us publishing but does not by itself delete what we hold.

What Meta does with your data is governed by Meta's own privacy policy.

13. Changes to this policy

We update this policy when the app's data handling changes. The date at the top always reflects the current version. Material changes affecting merchants will be communicated in-app or by email.

Contact

Privacy requests and questions: info.hybridcodform@gmail.com
General support: contact page
See also: GDPR & data protection · Terms of Service