AWBCadabra

Privacy Policy

DPD Romania (AWB Cadabra) — Shopify application.
Last updated: 2026-07-29

This policy is not ready to publish. The following details are still placeholders and must be completed in CrmPrivacyController::COMPANY: legal_name, registration, address, email.

1. Who we are

[COMPANY LEGAL NAME] ([TRADE REGISTER / VAT NUMBER]), [REGISTERED ADDRESS] (“we”, “us”) operates DPD Romania (AWB Cadabra), an application that connects Shopify stores to the DPD Romania courier service.

Contact for privacy matters: [CONTACT EMAIL].

2. Our role: controller and processor

We act in two distinct capacities, and your rights differ accordingly:

If you are a shopper who bought from a store using this app, please direct requests to that store first. We will assist the merchant in answering them.

3. What we process

CategoryDataWhy
Merchant account Shopify store domain, contact email, country, currency, plan, and the access tokens Shopify issues to the app. To install and run the app, authenticate API calls, and apply the correct subscription tier.
Order data Order number, date, totals, currency, payment and fulfilment status, line items, and the shopper’s name, email, telephone number and shipping address. To display orders in the app and to build the shipping consignment.
Shipment data Recipient name, address, telephone, email, parcel weight and dimensions, any cash-on-delivery amount, the chosen DPD service, and the pickup point selected at checkout. To create the AWB with DPD, print labels, request courier collection and follow tracking status.
Diagnostic logs Requests we send to DPD and the responses received. These contain recipient details. Credentials and tokens are replaced with [masked] before the entry is stored. To investigate delivery and integration failures. Full request logging is off by default and only records while a merchant enables it.
DPD credentials The merchant’s own DPD API username and password, stored encrypted. To call DPD on the merchant’s behalf. We never use them for anything else.
Support staff accounts Username and hashed password for our back-office users. To control access to the support tools.

We do not process special categories of personal data, and we do not use any of this data for advertising, profiling or automated decision-making.

4. Legal bases

For shopper data, the merchant determines the legal basis; we rely on our data processing agreement with them.

5. Who we share data with

RecipientPurposeLocation
DPD RomaniaCreating consignments, labels, courier pickups and tracking.Romania (EU)
ShopifyThe platform the app runs on; source of order data and destination of fulfilment updates.Canada / EU, under Shopify’s own terms
Hetzner Online GmbHServer hosting.Germany (EU)
CloudflareDNS, TLS and protection against abusive traffic.EU / global edge network
Google MapsOnly if the merchant supplies a Maps API key: renders the pickup-point map during checkout. Loaded in the shopper’s browser.Global

We do not sell personal data, and we do not share it with anyone for their own purposes.

6. International transfers

Our servers are in the European Union. Where a provider listed above processes data outside the EEA, that transfer relies on the European Commission’s Standard Contractual Clauses or an adequacy decision.

7. How long we keep data

8. Requests from Shopify and from you

Shopify sends us the mandatory privacy webhooks — a customer data request, a customer redaction request, and a shop redaction request. We record every such request and act on it.

Because we hold shopper data only on a merchant’s behalf, these requests are fulfilled together with the merchant: we supply or erase the data we hold for the individual concerned and confirm completion. Requests are handled by our team rather than automatically, so please allow up to 30 days, the period GDPR Art. 12(3) permits.

9. Your rights

Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to [CONTACT EMAIL] and we will respond within one month.

You also have the right to lodge a complaint with your national supervisory authority. In Romania this is the ANSPDCP (dataprotection.ro).

10. Security

Traffic is encrypted with TLS. DPD credentials are stored encrypted, and passwords are hashed. Each merchant’s data is isolated so that one store can never read another’s. Access to our support back-office is restricted to named accounts and protected against brute-force attempts. Credentials and tokens are masked before any diagnostic entry is written.

11. Cookies

The merchant-facing part of the app runs inside the Shopify admin and authenticates with short-lived session tokens rather than tracking cookies. Our back-office uses a single session cookie, strictly necessary for keeping staff signed in. We set no advertising or analytics cookies.

12. Changes to this policy

If we change how we process personal data we will update this page and revise the date above. Material changes affecting merchants will also be announced inside the app.

13. Contact

[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
[CONTACT EMAIL]