Who is responsible
Studio 8022 is the trading name used for this service. The legal provider and business contact address appear on our business details page. Privacy requests can be sent to our business contact address.
Information used by PostcodePilot
When a merchant installs the app, we store the Shopify shop domain and identifier, app access credentials, granted permissions, session information and subscription status. Depending on the Shopify session, this may include the authorised staff user’s name, email, account identifier, language and account role.
We store delivery rules, draft and published configuration history, integration identifiers and operational status so the app can work and recover from errors. A rule may contain a full postcode supplied by the merchant.
When Shopify requests a delivery quote, it sends origin and destination address details and cart-item information to our server. We use only the destination country, postcode and currency to calculate a price, and do not persist or log the request. Shopify Functions also apply checkout restrictions within Shopify. The storefront checker runs in the customer’s browser without sending its entered postcode to our server. We do not retain customer address books or order records, and do not collect payment-card details through the app.
Website and support
This brochure website does not use advertising trackers or analytics cookies. Hosting infrastructure necessarily processes connection data such as IP addresses to deliver and protect the service. We do not enable routine HTTP access logging for the public site or app proxy. Shopify and your own storefront may use their own cookies and services.
If you email us, we receive your email address and whatever you include in your message. Please minimise customer information in support requests. We use support messages to answer your enquiry and maintain a record of its resolution.
Why we process information
We use merchant account and configuration information to provide the contracted service, manage access and subscriptions, and give support. We rely on legitimate interests to secure and maintain the service and diagnose faults, balancing these purposes against individuals’ privacy. We may retain information where a legal obligation requires it.
We act as controller for our merchant relationship and support records. Where we process personal information on a merchant’s behalf to operate their store integration, the merchant remains responsible for its customer notices and lawful instructions.
Service providers and transfers
The app and website are hosted using OVHcloud. Shopify supplies the platform, authentication, checkout execution and subscription facilities. A public support mailbox is not yet active. Until it is available, contact us at the postal address on our business details page. We will update this notice with the support provider before the mailbox is used for app support. We do not sell personal information or use merchant or customer information to train AI models.
The operator is based in Cyprus. Hosting and Shopify platform services may involve processing outside Cyprus or the European Economic Area. Shopify describes its handling and transfer arrangements in its privacy policy; OVHcloud describes its services in its data-protection information. An encrypted recovery copy is currently held on the operator’s computer. No additional automated offsite backup provider is currently configured. Before adding providers or opening paid merchant access, we will assess the relevant processing terms and any required international-transfer arrangements and update this notice.
Retention and deletion
App access sessions are removed when Shopify sends an authenticated uninstall event. Shop configuration and integration records are removed when Shopify sends its authenticated shop-redaction request. Customer-data requests do not return address or order records because the app does not keep those records.
Routine support correspondence is kept only while needed to resolve an enquiry and handle related follow-up, normally no longer than 12 months after resolution. Records required for an ongoing dispute or a legal obligation may be kept longer for that purpose. We review recovery copies and delete or replace them within 30 days unless a specific incident requires longer retention. Backups are restricted to recovery use; if restored, applicable deletion requests are reapplied before normal service resumes.
Choices and automated processing
Installation and account information are needed to provide the app. If you do not provide the required Shopify permissions, the app cannot operate. Postcode rules calculate delivery availability and prices using the merchant’s settings; we do not use this information for profiling, advertising or unrelated automated decisions.
Your rights
Depending on the applicable law, you may request access, correction, deletion, restriction or a portable copy of your personal information, or object to certain processing. Contact our business contact address; we may need to verify your identity. Shopify customers should normally contact the merchant whose store they used. You may complain to the competent data-protection authority, including the Commissioner for Personal Data Protection in Cyprus.
Changes
We will update this notice when our service or handling of information changes. Material changes will be communicated where required.