Privacy Policy — Scandicommerce Apps for Shopify
Last updated: August 14, 2026
Last updated: 14 August 2026
1. Who we are
Scandicommerce (org. no. 933 434 346), Drammensveien 167, 0277 Oslo, Norway ("Scandicommerce", "we", "us") develops apps for the Shopify platform, including our checkout app. This privacy policy explains what personal data our apps collect, why we collect it, and how it is handled. It applies to all Shopify apps published by Scandicommerce unless an app has its own dedicated policy.
For questions about this policy or our data practices, contact us at post@scandicommerce.no.
2. Our role: processor and controller
When our apps process personal data belonging to a merchant's customers (for example checkout, cart, and order data), we act as a data processor on behalf of the merchant, who is the data controller. When we process data about the merchant itself (store owner contact details, billing information, support correspondence), we act as the data controller.
3. Information we collect
When a merchant installs one of our apps, we receive information from Shopify through the permissions (API scopes) the merchant grants during installation. Depending on the app, this may include:
- Store information: store name, myshopify domain, store owner name and email address, store address, currency, and plan.
- Checkout and order data: cart contents, product and pricing information, shipping and billing addresses, customer name, email address, and phone number — only to the extent required for the app's functionality.
- Technical data: app configuration, log data, and diagnostic information generated when the app runs.
We do not collect or store payment card details. Payment processing is handled by Shopify and the merchant's payment providers.
4. How we use the information
We use collected data solely to provide, operate, support, and improve our apps. This includes rendering checkout functionality, applying merchant configuration, troubleshooting, and providing merchant support. We do not sell personal data, use it for advertising, or share it with third parties for their own purposes.
5. Legal basis for processing (GDPR)
Where the GDPR applies, we process merchant data on the basis of performance of a contract (Article 6(1)(b)) and our legitimate interest in operating and improving our services (Article 6(1)(f)). Processing of merchants' customer data is carried out on documented instructions from the merchant in accordance with Article 28.
6. Sharing and subprocessors
We share data only with service providers that help us operate our apps, such as cloud hosting and infrastructure providers, and only to the extent necessary. We aim to process and store data within the EU/EEA. Where a transfer outside the EU/EEA occurs, we ensure appropriate safeguards under Chapter V of the GDPR, such as the EU Standard Contractual Clauses. We may also disclose data where required by law.
7. Data retention and deletion
We retain data only for as long as the app is installed and as needed to provide the service. Our apps implement Shopify's mandatory privacy webhooks: when we receive a customers/data_request, customers/redact, or shop/redact webhook, we respond by providing or deleting the relevant data within 30 days. When a merchant uninstalls an app, associated store data is deleted within 30 days of the shop/redact notification, except where retention is required by law (for example bookkeeping obligations).
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls, and the principle of least privilege for API scopes — our apps request only the permissions they need to function.
9. Your rights
Under the GDPR you have the right to access, rectify, delete, and receive a copy of your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority — in Norway, Datatilsynet (www.datatilsynet.no). If you are a customer of a store using one of our apps, please direct requests to the store you purchased from; as their processor, we will assist the merchant in fulfilling your request. Merchants and other data subjects can contact us directly at post@scandicommerce.no.
10. Changes to this policy
We may update this policy from time to time. The most recent version will always be available on this page, with the date of the last revision shown at the top. Material changes will be communicated to affected merchants.
11. Contact
Scandicommerce, Drammensveien 167, 0277 Oslo, Norway. Org. no. 933 434 346. Email: post@scandicommerce.no. Phone: +47 333 94 000.