Meet PostcodePilot
Data protection

Processing on your behalf.

PostcodePilot merchant data processing terms. Last updated 20 September 2026.

1. Parties and scope

The merchant using PostcodePilot is the controller of its customer information. David Duff, trading as Studio 8022, is the processor when handling that information to provide the app. These terms apply for the period of that processing and supplement the service terms. They do not change either party’s independent responsibilities for its own account, support or legal records.

2. What is processed

The purpose is to calculate delivery prices and availability and operate the merchant’s Shopify integration. Shopify delivery-quote requests can contain origin and destination address details and cart-item information concerning shoppers and recipients. The app uses the destination country, postcode and currency to calculate the quote and does not persist the request. Merchant-supplied rules may themselves contain full postcodes. Processing includes receiving, reading, calculating, transmitting a quote and deleting transient request data. Configuration is stored for the installation period, subject to the deletion arrangements in the privacy notice.

3. Your instructions

We process this information only on documented merchant instructions, including installation, configuration and normal use of the app, unless applicable law requires otherwise. We will inform the merchant of a legal requirement unless prohibited and notify the merchant if we believe an instruction infringes applicable data-protection law. The merchant is responsible for lawful instructions, appropriate notices and the information it supplies.

4. Confidentiality and security

Access is limited to people who need it to operate or support the service and who are subject to confidentiality obligations. Measures include HTTPS, restricted server access, access controls for credentials, separation of public services and internal jobs, and encrypted recovery copies. We do not routinely log delivery-quote request bodies or store customer address books or orders. Measures may evolve while maintaining protection appropriate to the processing risks.

5. Service providers

The merchant authorises OVHcloud infrastructure for app hosting. Shopify supplies the merchant’s platform under its own relationship with the merchant. We will use written data-protection obligations with any appointed subprocessor, remain responsible for its performance under these terms, and give merchants advance notice of a proposed addition or replacement so they can raise reasonable data-protection objections before the change. If an objection cannot reasonably be resolved, the affected service may be ended and unused prepaid service refunded where applicable. We will not introduce a transfer of merchant personal data requiring safeguards without arranging the necessary protection.

6. Assistance and incidents

Taking account of the nature of the processing and information available to us, we will reasonably assist with individual rights requests, security obligations, breach notifications, impact assessments and regulator consultations. We will notify the merchant without undue delay after becoming aware of a personal data breach affecting information processed on its behalf, and provide available information to help it meet its obligations. We will refer customer requests to the relevant merchant unless legally required to respond directly.

7. Return and deletion

On ending the service, the merchant may request return or deletion of personal information processed on its behalf, unless retention is required by law. The app handles Shopify’s authenticated uninstall and redaction events as described in the privacy notice. Recovery copies remain restricted to recovery use until they expire; deletion instructions are reapplied if a copy is restored. Merchants should export rules they want to retain before removal.

8. Demonstrating compliance

We will make information reasonably necessary to demonstrate compliance available and allow and contribute to appropriate audits, including inspections by the merchant or its mandated auditor. Arrangements should protect other merchants’ information and security, with reasonable notice where possible; they do not restrict a regulator’s powers or urgent rights under applicable law.

9. Contact

Use our business contact address for data-protection requests. These terms take priority over conflicting service terms on the processing described here. The applicable data-protection law continues to apply.