Privacy Policy

Last modified 4 March, 2026

1. Overview

Handoff – Fulfillment Ops(“Handoff,” “we,” “us,” or “our”) is a Shopify application that helps merchantsmanage and track local pickup orders from a single dashboard. This PrivacyPolicy explains what data we collect, how we use it, with whom we share it, andwhat rights you have. By installing or using Handoff, you agree to thepractices described in this policy.

If you have questions, contact usat: hello@handoffops.com

 

2. Data We Collect

We collect only the data necessaryto deliver the app’s core functionality. We access your Shopify store throughthe following API scopes:

•      read_merchant_managed_fulfillment_orders– to read fulfillment orders assigned to your locations

•      write_merchant_managed_fulfillment_orders– to update fulfillment order statuses (e.g., ready for pickup, picked up)

•      read_orders – to displayorder details associated with each pickup fulfillment

•      read_locations – toidentify which of your store locations have pickup orders

 

2.1 Merchant Data

When you install and use Handoff,we collect and store:

•      Shopify shop domain andaccess token (required for API authentication)

•      Fulfillment order recordswith delivery method PICK_UP, including fulfillment order ID, status, and lineitems

•      Order metadata: order ID,order name/number, customer name, email address, and phone number as providedby Shopify

•      Location data: your storelocation names and IDs

•      Audit log entries:timestamped records of every status change made through the app (who performedthe action and when)

 

2.2 End-Customer Data

We do not directly collect personal data from your customers. Customer information (such as name, email,and phone number) is received indirectly from Shopify as part of order andfulfillment order records. This data is used solely to display order detailswithin your merchant dashboard and is not used for any independent purpose.

 

2.3 Usage and Technical Data

We may automatically collectlimited technical data when you use the app, including:

•      Browser type and deviceinformation

•      App feature usage logs fordebugging and product improvement

•      Error and crash reports

We do not use cookies for trackingor advertising purposes.

 

3. How We Use Your Data

We use the data described abovefor the following purposes:

•      Providing the service:syncing pickup fulfillment orders, enabling bulk status updates, and displayingorder timelines

•      Audit logging: recordingstatus changes for accountability and operational review

•      Technical support:diagnosing issues and responding to merchant support requests

•      Product improvement:understanding how features are used to improve reliability and performance

•      Legal compliance: meetingour obligations under applicable law and Shopify’s Partner requirements

We do not use your data foradvertising, profiling, or sale to third parties.

 

4. Data Sharing and Disclosure

We do not sell your personal dataor your customers’ personal data. We may share data only in the followinglimited circumstances:

•      Service providers: We mayuse trusted third-party infrastructure providers (e.g., cloud hosting, databaseservices) to operate Handoff. These providers process data only on our behalfand under contractual data protection obligations.

•      Shopify: The app operateson the Shopify platform. Your use of Shopify is governed by Shopify’s ownPrivacy Policy (shopify.com/legal/privacy).

•      Legal requirements: We maydisclose data if required by law, court order, or government authority, or ifnecessary to protect the rights and safety of Handoff, its users, or thepublic.

•      Business transfers: IfHandoff is acquired or merges with another entity, your data may be transferredas part of that transaction. We will notify you before your data becomessubject to a different privacy policy.

 

5. Data Retention

We retain your data for as long asyour store has Handoff installed and active. Upon uninstallation of the app:

•      We will delete or anonymizeyour store’s data within 30 days of uninstallation.

•      Audit logs may be retainedfor up to 90 days post-uninstallation for fraud prevention and legal compliancepurposes, after which they are permanently deleted.

You may request early deletion ofyour data by contacting hello@handoffops.com.

 

6. Data Security

We implement industry-standardsecurity measures to protect the data we collect, including:

•      Encryption of data intransit using TLS/HTTPS

•      Encryption of sensitivedata at rest (including Shopify access tokens)

•      Access controls thatrestrict data access to authorized personnel only

•      Regular review of securitypractices and dependencies

No method of transmission orstorage is 100% secure. In the event of a data breach that affects your data,we will notify affected merchants as required by applicable law.

 

7. GDPR – Rights of EEA and UK Residents

If you are located in the EuropeanEconomic Area (EEA) or the United Kingdom, the General Data ProtectionRegulation (GDPR) or UK GDPR may apply to the processing of your data. In thatcase, Handoff acts as a data processor on behalf of you, the merchant (who isthe data controller), with respect to your customers’ personal data.

As a data controller for merchantaccount data, you have the following rights:

•      Right of access: request acopy of the personal data we hold about you

•      Right to rectification:request correction of inaccurate data

•      Right to erasure: requestdeletion of your data (subject to legal retention requirements)

•      Right to restriction:request that we limit how we use your data

•      Right to data portability:request a machine-readable export of your data

•      Right to object: object toprocessing based on legitimate interests

To exercise any of these rights,contact us at hello@handoffops.com. We will respond within 30 days. Our legalbasis for processing merchant data is the performance of our contract with you(Art. 6(1)(b) GDPR). We do not transfer personal data outside the EEA/UKwithout appropriate safeguards (such as Standard Contractual Clauses).

 

8. CCPA – Rights of California Residents

If you are a California resident,the California Consumer Privacy Act (CCPA) may provide you with additionalrights regarding your personal data:

•      Right to know: requestdisclosure of the categories and specific pieces of personal information wehave collected about you

•      Right to delete: requestdeletion of personal information we have collected, subject to certainexceptions

•      Right to opt-out: we do notsell personal information, so there is no opt-out required

•      Right tonon-discrimination: we will not discriminate against you for exercising yourCCPA rights

To submit a California privacyrequest, contact us at hello@handoffops.com or visit handoffops.com/privacy.

 

9. Children’s Privacy

Handoff is a business-to-business application intended solely for use by merchants and their staff. We do notknowingly collect personal data from individuals under the age of 16. If webecome aware that we have collected data from a minor, we will delete itpromptly.

 

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this document. For material changes, we will notify you via the Shopify adminnotification system or by email to the address associated with your Shopifyaccount. Your continued use of Handoff after the effective date of any changeconstitutes your acceptance of the updated policy.

 

11. Contact Us

For privacy-related questions,data requests, or concerns, please contact:

Handoff – Fulfillment Ops
Email: hello@handoffops.com
Website: handoffops.com

Still need help? Reach out to our support team.