Privacy Policy
MyCozy Courier Manager for ACS
Effective date: 2 September 2026
1. Who operates the app
MyCozyApps is a brand operated by Kleanthis Sidiropoulos – Sole Proprietorship, Zagkliveri, Thessaloniki 57012, Greece. This Privacy Policy applies to MyCozy Courier Manager for ACS, a Shopify application that connects a merchant’s Shopify store with the merchant’s own ACS Courier account.
MyCozy Courier Manager for ACS is an independent integration and is not affiliated with or endorsed by ACS Courier. Privacy questions and requests can be sent to support@mycozyapps.com.
2. Our privacy roles
The Shopify merchant normally determines why and how customer, order, and shipment data is used. For that data, the merchant acts as controller and MyCozyApps acts as processor, processing the data on the merchant’s instructions through the features the merchant chooses to use.
Where MyCozyApps determines the purposes and means of processing, it acts as controller. This applies as appropriate to merchant account and configuration data, Shopify admin-user information, billing and entitlement information, security and audit records, technical logs, support communications, and information needed to administer and protect the service or comply with law.
3. Information we process
Depending on the features used, the app processes:
- Shopify shop, session, and admin-user information: shop domain, authorization state, access scopes, access and refresh tokens, session expiry, and available admin-user ID, name, email, locale, account-owner, collaborator, and email verification information.
- Customer, order, and delivery information: order identifiers and names, dates and statuses, recipient name and company, delivery address, city, region, postcode, country, phone number, order value and currency, shipment weight, parcel quantity, and any ACS shipment note the merchant explicitly enters. The voucher workflow does not retrieve the recipient email or the general Shopify order note.
- Shipping and payment metadata: shipping-line titles, payment gateway names, and limited transaction gateway metadata used to determine whether an order is cash on delivery and to calculate the applicable COD amount.
- ACS Courier configuration: test and production API URLs, API keys, company and user identifiers and passwords, billing codes, sender details, connection-test results, and voucher and fulfillment preferences supplied by the merchant.
- Voucher, fulfillment, and tracking information: ACS environment and voucher number, voucher status, Shopify fulfillment identifiers and status, tracking details, COD amount, shipment weight and parcel count, active-voucher lookup keys, and creation, printing, cancellation, tracking, and redaction dates.
- Billing, privacy-request, and audit metadata: subscription or entitlement status, privacy webhook topic and request identifiers, relevant order identifiers, request status and dates, a cryptographic digest used to identify duplicate webhook payloads, protected-data access action, resource type and count, actor type and available Shopify user ID.
- Technical and support information: normal server, security, health, and error information; browser and network request metadata made available to hosting or CDN services; and the contact details, message content, and attachments a person chooses to send when requesting support.
4. How and why we use information
We process information to:
- authenticate the merchant and maintain the Shopify connection;
- display and validate orders, including address, phone, COD, and checks of the app’s existing voucher records;
- create, retrieve, print, reprint, track, and cancel ACS vouchers;
- create, update, or cancel Shopify fulfillments and optionally ask Shopify to notify the customer;
- provide merchant settings, voucher history, billing, support, and privacy-request tools;
- secure, troubleshoot, maintain, and improve the reliability of the service, keep proportionate audit records, prevent abuse, and comply with legal obligations.
When MyCozyApps acts as controller, processing is carried out as applicable to provide and administer the service and our agreement, comply with legal obligations, protect the legitimate interests of merchants, users, and the service, and obtain consent where consent is required. When we act as processor, the merchant is responsible for the lawful basis and instructions for processing customer data.
We do not sell personal data. We do not use Shopify customer data for unrelated advertising or marketing, and no advertising analytics service is currently configured in the app.
5. Recipients and service providers
- Shopify: provides app authentication, session and Admin API services, hosted billing, compliance webhooks, fulfillment and tracking functions, App Bridge, and optional customer fulfillment notifications. The app sends tracking and fulfillment instructions back to Shopify.
- ACS Courier: receives the merchant’s ACS credentials and the recipient name and company, delivery address, telephone, Greece country code, parcel and weight details, COD amount where applicable, order reference, and only the ACS shipment notes explicitly entered by the merchant. Recipient email and the general Shopify order note are not transmitted to ACS. These details are used to create, print, track, or cancel a voucher under the merchant’s ACS relationship.
- Render and PostgreSQL: the production web service, scheduled retention process, and PostgreSQL database are configured on Render in its Frankfurt region. This regional configuration does not mean that every provider or ancillary service processes data only in the European Economic Area.
- Papaki: provides the email service used for communications sent to support@mycozyapps.com.
We may also disclose information when required by applicable law or to establish, exercise, or defend legal claims. Shopify and ACS Courier retain and process information under their respective relationships, instructions, contracts, and privacy policies. The app cannot control or erase copies held independently by them.
6. Sessions, necessary technologies, and logs
The embedded app uses Shopify authentication, App Bridge, session tokens, and related technologies necessary to securely operate inside Shopify Admin. Public pages use normal web technologies and load a Shopify-hosted font stylesheet. Shopify, Render, content delivery services, and network providers may receive ordinary request metadata such as IP address, request time, requested path, browser information, and response status under their own operating practices. The app does not currently configure advertising analytics.
7. Retention and deletion
- Stored voucher recipient name, phone number, and combined address are redacted after the configured retention period, currently 180 days by default. The associated order and voucher identifiers, status, COD and shipment metadata, and operational timestamps can remain while the app is installed.
- Protected-data audit records and completed privacy-request records are currently retained for 365 days by default. An incomplete privacy request may remain until it is completed or the shop data is deleted.
- ACS credentials and settings, Shopify sessions, voucher metadata, billing entitlements, and other shop-scoped primary database data are generally retained while the app is installed or as needed to provide the service.
- On authenticated app-uninstall or Shopify shop-redaction processing, the app deletes the shop’s sessions, ACS settings, vouchers, privacy-request records, audit records, and local billing entitlement from its primary database, subject to legal obligations.
- Support communications are retained only as long as reasonably necessary to provide support, protect the service, resolve disputes, and meet legal obligations.
Deleted information may remain temporarily in provider backups, security records, or logs until those records expire through their normal lifecycle. Deletion by this app does not automatically delete information retained by Shopify or ACS Courier under their own relationships and policies.
8. Security
The app uses HTTPS for supported production connections, Shopify-authenticated access, shop-scoped database queries, and authenticated Shopify privacy webhooks. ACS API keys, company and user passwords and identifiers, and billing codes stored by the app are protected using AES-256-GCM application-layer encryption with a dedicated production secret. Secret credential fields are not returned in the settings interface after storage.
Other database fields, including voucher metadata, recipient fields, and Shopify session tokens, do not all receive that same application-layer encryption. No system can be guaranteed completely secure. We assess suspected incidents, take reasonable containment and remediation steps, and notify affected merchants or authorities when required by applicable law.
9. International processing
Information may be processed in Greece, the Render Frankfurt region, and other locations in which Shopify, ACS Courier, Papaki, or their supporting providers operate. Where international processing occurs, it is handled under the applicable contractual and legal safeguards used by the relevant provider. We do not represent that all processing is confined to one country or region.
10. Privacy rights and requests
Depending on applicable privacy law, individuals may have rights to access, correct, delete, restrict, or object to processing, receive a copy of their personal data, or withdraw consent where processing is based on consent. These rights may be subject to lawful exceptions.
Customers should normally contact the Shopify merchant that collected their information. Merchants and individuals may also contact support@mycozyapps.com. We may need to verify identity, authority, the relevant shop, and the scope of a request before acting. Individuals also have the right to complain to the Hellenic Data Protection Authority or another competent supervisory authority under applicable law.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to the service, providers, legal requirements, or processing practices. We will post the revised policy here with a new effective date and provide reasonable additional notice where practical and appropriate to the significance of the change.
12. Contact
MyCozyAppsoperated by Kleanthis Sidiropoulos – Sole Proprietorship
Zagkliveri, Thessaloniki 57012, Greece
support@mycozyapps.com