Every HIGHLIGHTED field below must be replaced with real details. A privacy policy that names no identifiable controller does not satisfy GDPR Art. 13, and publishing it in this state is worse than publishing nothing.
1. Who we are
Hybrid — COD & Checkout Form ("Hybrid", "we", "us") is a Shopify application operated as a sole trader by Benjámin Márk, trading from Hungary, 7562 Segesd, Dózsa tér 5, TAX / VAT REG. NO. IF APPLICABLE.
The same operator also runs Hybrid Workspace (team.hybridcod.com), a team workspace with a social scheduler that can connect a Facebook Page or Instagram account. It handles different data in a different way, so it has its own section: section 12. Sections 2 to 11 describe the Shopify app.
For privacy matters, contact info.hybridcodform@gmail.com. We are not required to appoint a Data Protection Officer, and have not appointed one.
2. Controller and processor
Hybrid handles two different kinds of people's data, in two different legal roles. The distinction matters, because it determines who you ask for what.
- Merchant data — the person who installs Hybrid on their Shopify store. For this we act as the data controller: we decide why and how it is processed.
- Buyer data — the shoppers who submit a Hybrid checkout form on a merchant's storefront. For this we act as a data processor acting on the merchant's documented instructions. The merchant is the controller.
If you are a shopper and want your data accessed or erased, the fastest route is to contact the store you ordered from. They control it, and we act on their instruction. You can also contact us directly and we will action it — see Your rights.
It is the merchant's responsibility to establish a lawful basis for collecting buyer data through the form, and to present their own privacy notice to their shoppers.
3. What we collect
From the merchant's Shopify store
On install, Hybrid requests these Shopify scopes. Each maps to a feature; we do not request scopes we do not use.
| Access | Why we need it |
|---|---|
| Orders & draft orders (read/write) | Create the COD order or prefilled card checkout from the form, apply bundle and card-payment discounts, tag orders placed through Hybrid. |
| Products (read) | Render buy buttons, bundle tiers and upsell offers with real titles, images, variants and prices. |
| Protected customer data | Buyer name, email, phone and address, so the order can be created and fulfilled. |
| Fulfilments (write) | Attach a real tracking number when a locker parcel is created. |
| Cart transforms | Apply bundle and card-payment discounts in the Shopify cart and checkout. |
| Webhooks | Order and fulfilment events that drive delivery emails and keep in-app analytics accurate. |
| Theme app extension | Renders the form on the storefront. Only active once the merchant enables it in their theme. |
Product catalogue data is fetched live from Shopify when needed. It is not duplicated into our database.
From shoppers using the form
When a shopper submits a Hybrid checkout form, we store the following on the merchant's behalf:
| Record | Contains | Protection at rest |
|---|---|---|
| Order contact | Buyer name and email, against the Shopify order ID | Encrypted |
| Locker shipment | Recipient name, phone, email, chosen pickup point, COD amount | Encrypted |
| Abandoned checkout | Buyer name and email, cart totals, recovery link | Stored in plain text |
| Risk identifiers | Phone / email / address / device / IP | Irreversible keyed hash only — never the raw value |
| Device signals | Coarse, non-reversible browser and device summary | Hashed, with a hard expiry timestamp |
Abandoned-checkout name and email are genuinely stored unencrypted, while order contacts and locker shipments use the EncryptedOrPlaintext cast. The table above states that truthfully rather than over-claiming. Applying the same cast to abandoned_checkouts would let you delete this note and mark the row encrypted.
Merchant-supplied credentials
If a merchant configures email sending or locker shipping, we store the SMTP and carrier credentials they enter. These are encrypted at rest, are never displayed back in plain text, and are used only to act on that merchant's behalf.
4. Legal bases
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Operating the app for a merchant who installed it | Contract — Art. 6(1)(b) |
| Creating and fulfilling a buyer's order | Processed for the merchant, on their basis, as their processor |
| COD fraud prevention and risk scoring | Legitimate interests — Art. 6(1)(f): preventing losses from undeliverable cash-on-delivery orders |
| Service emails to merchants about their account | Contract — Art. 6(1)(b) |
| Responding to legal and regulatory obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed that interest against the rights of the people involved. The outcome of that balancing is described in the next section, and in more detail on our GDPR page.
5. The risk engine
Hybrid includes COD fraud prevention. Because this involves profiling, we describe it in full rather than burying it.
Identifiers are never stored raw. Phone numbers, emails, addresses, device and IP identifiers are converted to a keyed one-way hash (HMAC-SHA256) before storage. The database holds no readable contact details for risk purposes — not to us, and not to anyone who obtained a copy of it.
Every record is scoped to a single store. Risk data carries the shop it came from, and is only ever queried within that shop. There is no shared or cross-merchant blacklist. A shopper flagged at one store is not flagged at another, and merchants cannot see each other's risk data.
Device signals expire by design. Device and browser signals are stored with a hard expiry timestamp and are pruned automatically.
How a decision is made
When an order is placed, Hybrid re-hashes the submitted details, looks for matches within that store's own history, and produces a score. The score maps to one of three outcomes, configured by the merchant: allow, warn the merchant, or require_card — asking the shopper to prepay by card instead of cash on delivery.
Each decision is stored with the ruleset version that produced it, so any outcome can be explained after the fact.
Automated decision-making (Art. 22)
We have designed this to stay within the safeguards GDPR expects:
- No order is automatically cancelled or refused. The strongest automated outcome is asking for card prepayment, and the shopper can still complete the purchase.
- The merchant sets the thresholds and can allowlist any shopper, overriding the score.
- A human can intervene. Contact the store, or us, to have a decision reviewed.
- Decisions are explainable, because the contributing signals and ruleset version are recorded.
6. How long we keep it
| Data | Retained for |
|---|---|
| Risk identifiers, risk events, risk decisions | 24 months, then automatically pruned |
| Device signals | Until their expiry timestamp — far shorter than 24 months |
| Order contacts and locker shipments | While the app is installed; erased on uninstall or on request |
| Abandoned checkouts | While the app is installed; erased on uninstall or on request |
| Merchant account, settings and credentials | While the app is installed; erased after uninstall |
| All shop data after uninstall | Erased when Shopify notifies us, 48 hours after uninstall |
Why 24 months for risk data
Cash-on-delivery fraud is seasonal and repeats slowly; a shorter window lets repeat offenders age out of a merchant's own history and re-order. We consider 24 months proportionate because of what is actually retained: not names, numbers or addresses, but irreversible hashes scoped to one store, which cannot be read back or used to contact, identify or profile anyone outside that store's own order history. Raw contact details are not kept for this purpose at any point.
7. Who else sees it
We do not sell, rent, or share personal data for anyone else's marketing. Data reaches a third party only where a feature the merchant switched on requires it:
| Recipient | What they receive | When |
|---|---|---|
| Shopify | The order and customer details, written into the merchant's own store | Always — this is the app's core function |
| FOXPOST (locker carrier) | Recipient name, phone, chosen locker, COD amount | Only if the merchant enables locker shipping |
| The merchant's own SMTP provider | The emails the merchant configured, and their recipients | Only if the merchant enables email automations |
| Hostinger International Limited | Stores the encrypted records described above | Always |
| Meta Platforms (Facebook, Instagram) | The posts a Hybrid Workspace user scheduled — image and caption — and the requests needed to publish them and read their counts. Nothing about shoppers. See section 12 | Only if a workspace user connects a Facebook Page or Instagram account |
We may also disclose data where legally compelled to, or to establish or defend legal claims.
8. International transfers
Hybrid's servers are located in Frankfurt, Germany (EU), and the records described above stay there — they are not transferred outside the EEA by us. Shopify, FOXPOST and any SMTP provider a merchant chooses to enable are separate controllers or processors under their own terms, and any transfer they make outside the EEA rests on their own safeguards.
9. Security
- Buyer contact details and locker recipient details are encrypted at rest.
- Risk identifiers are stored only as keyed one-way hashes and cannot be reversed.
- Merchant credentials are encrypted and never rendered back in plain text.
- All traffic between the storefront, our servers and Shopify is encrypted in transit over HTTPS.
- Every inbound Shopify webhook is verified by HMAC signature before it is acted on.
- Backend access is limited to authorised personnel.
No system is perfectly secure. If a breach affects your personal data and presents a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected people where the law requires it.
10. Your rights
If you are in the UK, EEA, or another region with comparable law, you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent was the basis.
To exercise any of these, email info.hybridcodform@gmail.com. Include the store domain you ordered from and, if you have it, an order number — without these we often cannot locate records, since we hold no readable contact details for risk data.
We respond within 30 days. There is no charge. We may ask you to verify your identity before acting, to avoid disclosing your data to someone else.
If you are unhappy with our response you can complain to your local data protection authority. In the UK that is the ICO (ico.org.uk).
11. Deletion and uninstall
Hybrid implements all three of Shopify's mandatory privacy webhooks, and acts on them automatically:
| Webhook | What happens |
|---|---|
customers/data_request | We record the request and compile what we hold for that shopper, within 30 days. |
customers/redact | We delete that shopper's order contacts, locker shipments, abandoned checkouts and risk decisions, and delete their risk identifiers by re-hashing the supplied details and removing every match. |
shop/redact | Sent 48 hours after uninstall. We erase every record tied to that store — settings, credentials, contacts, shipments, analytics and risk data. |
Because risk identifiers are hashes rather than raw values, erasing a specific person means re-hashing the details they supply and deleting the matching rows. This is why an erasure request needs the store domain and, ideally, the email or phone used on the order.
12. Hybrid Workspace and connected social accounts
This section is about Hybrid Workspace, not the Shopify app. A signed-in member of a workspace can connect a Facebook Page or an Instagram business account, schedule posts to it from their own content library, and see how those posts performed. Nothing in it touches shoppers or orders, and the Shopify app never contacts Facebook or Instagram.
For the account data below we are the controller. The images and captions people schedule are their own work, which we process for them in order to publish.
What you are asked to allow, and what we use each permission for
Connecting uses Facebook Login. You choose which Pages and accounts to share, and we receive nothing about any you did not select. We ask for these permissions and use each one for exactly one purpose:
| Permission | What we use it for |
|---|---|
pages_show_list | Show you the Pages you manage so you can pick which to connect. |
pages_manage_posts | Publish the posts you scheduled to the Page you connected. |
pages_read_engagement | Read the Page's name and picture, and the share and reaction counts of posts we published. |
pages_read_user_content | Count the comments on posts we published. Only the number is kept; the comments themselves are never stored. |
read_insights | Read the insight counts for posts we published to a Page. |
instagram_basic | Identify the Instagram account linked to the Page: its ID, username and profile picture. |
instagram_content_publish | Publish the posts you scheduled to that Instagram account. |
instagram_manage_insights | Read the like, comment, save and reach counts of posts we published to Instagram. |
business_management | Let Facebook's account picker offer Pages that belong to a business portfolio. We never read or change your business settings. |
What we store
- The Page's or Instagram account's numeric ID, name and profile picture URL, and the list of permissions you granted.
- An access token, and a longer-lived token used to renew it, encrypted at rest (AES-256-GCM). Neither is shown in the interface, returned by our API or written to a log.
- Which of your own images are scheduled, to which account and when, and for posts we published, the post's ID and public link and a record of each publishing attempt, including any error Meta returned.
- Five counts per published post — reach (where Meta provides it), likes, comments, shares and saves — and repeated readings of those same counts over time, so a curve can be drawn.
- Which workspace member connected the account.
The counts are totals handed to us by Meta. They identify nobody, and we have no route to the people behind them.
What we do not do
- We do not copy your existing Facebook or Instagram posts, photos or videos; the only images involved are ones you uploaded to Hybrid yourself.
- We do not store the text of comments, replies or direct messages, follower lists, or anything about the individuals who see, like or comment on a post.
- We do not sell this data, use it for advertising or profiling, or use it to train AI models.
- We do not share it with anyone other than Meta, to publish your posts and read their counts, and our hosting provider, which stores the records.
Legal basis, and how long we keep it
We process this to provide the scheduler the workspace member asked for (Art. 6(1)(b)), on the permissions they chose to grant in Facebook's own dialog. They can withdraw at any time by disconnecting.
Everything above is kept only while the account stays connected. Disconnecting deletes it immediately — the tokens, the account record, every scheduled post for it, every publishing log, and every count and reading. There is no soft-delete or retention window. Routine database backups are overwritten on their normal cycle and are not used to restore a deleted connection. The member's own images and captions are not deleted, because they are their work and not Facebook or Instagram data.
How to delete it
Disconnect the account under Social accounts in team.hybridcod.com/settings, or ask us to do it. The full steps, and exactly what each route removes, are on our data deletion page. You can also remove Hybrid from Facebook's side under Business integrations, which stops us publishing but does not by itself delete what we hold.
What Meta does with your data is governed by Meta's own privacy policy.
13. Changes to this policy
We update this policy when the app's data handling changes. The date at the top always reflects the current version. Material changes affecting merchants will be communicated in-app or by email.
Contact
Privacy requests and questions: info.hybridcodform@gmail.com
General support: contact page
See also: GDPR & data protection · Terms of Service