TraceOps
FeaturesPricingHow it works
Add app to Shopify
Legal

Privacy Policy

This policy explains what personal data the TraceOps app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.

Last updated: 2026-09-11 · Applies to the TraceOps Shopify app and the pages under traceops.dilight.website.

1. Who we are

TraceOps is operated by DiLight Entertainment UG (haftungsbeschränkt) ("TraceOps", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.

When TraceOps is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and TraceOps acts as a data processor on the merchant's behalf, processing store data only to provide the app's traceability features. For our own account and billing records, we act as the controller.

2. Data we process

TraceOps adds lot, batch and serial-level traceability to a Shopify store. It reads store data from Shopify on demand (per request, using the merchant's session) rather than keeping a background copy, and it persistently stores only the trace records it creates plus a small cache needed to render public pages. The data involved:

  • Store & account data — your .myshopify.com domain, the OAuth access token issued at install (stored encrypted and never shown to us in plain text in the UI), your locations, plan and billing status, and your trace configuration (which products are traced, how sold units are assigned, and per-product exposure settings for public pages).
  • Product & inventory data — product and variant details (title, SKU, image) and per-location inventory levels are read live from Shopify when you use the app; they are not synced into a background datastore. A small cache of product titles and image URLs is kept so public trace pages can render without a live call. TraceOps stores its own lot/batch records (quantities, expiry, supplier/origin) and serial numbers, and keeps a per-lot inventory ledger that it compares against live Shopify totals to flag drift — it never writes back to Shopify inventory. It writes trace metadata (metafields) to your products and orders (write_products).
  • Order & fulfilment data — order ID and number, line items, quantities, fulfilment status and the associated customer email are read on demand and are also delivered through the order-paid and fulfilment webhooks, so each sold line item can be assigned to the lot or serial it came from and updated when the order ships. An inventory-levels webhook is used only to refresh the drift comparison.
  • Customer data — the customer email on an order is the only protected customer field we process. It is used solely to build order-level trace assignments and to power the merchant-triggered recall center (identifying which customers received an affected lot) and the resulting merchant-only export. It is never shown on public pages.
  • Scan telemetry — when a public trace/verify QR page is scanned, we store the scan event with a salted hash of the IP address and user-agent for anti-counterfeit detection; we never store the raw IP or user-agent.

We do not process payment card details. Access to store data is limited to the Shopify scopes granted at install (read_customers, read_fulfillments, read_inventory, read_locations, read_orders, read_products, write_products).

3. How we use data

  • Create and manage lots, batches and serial numbers, and assign sold units to them (FEFO/FIFO).
  • Shadow Shopify inventory per lot and flag drift for the merchant.
  • Serve public provenance and authenticity-verify pages for a scanned lot or serial — exposing only a whitelisted set of trace events, never order or customer payloads.
  • Detect suspicious scan patterns to help identify counterfeiting.
  • Power the recall center: compute the affected orders and customers for selected lots and let the merchant export those lists (CSV) for their own notification tools.
  • Operate billing, enforce plan limits, and provide support.

4. Legal basis (GDPR)

Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing, securing and protecting the integrity of the service (including anti-counterfeit scan detection). For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.

5. Sharing & sub-processors

We do not sell personal data. We share data only with the providers needed to run the service:

  • Shopify — the platform the app is installed on and the source of product, order, inventory and store data.
  • Our hosting/infrastructure provider — to host the application and its database.

Recall exports (CSV) are generated only when a merchant triggers them and are delivered to that merchant; they are the only customer-data egress from the app.

6. Data retention

We keep store data only for as long as it is needed to provide the service to the merchant. Trace records (lots, serials, assignments, trace events, scans and recalls) are retained while the app is installed so the store's traceability history stays intact. When the app is uninstalled, or on a Shopify shop/redact request, we purge the store's data as described below. Aggregated, non-identifying statistics may be kept longer.

7. GDPR / data-deletion requests

TraceOps implements Shopify's mandatory compliance webhooks (verified by HMAC signature before any action):

  • customers/data_request — we record the subject-access request so the merchant (the controller) can fulfil it; the data cannot be returned inline in the webhook response.
  • customers/redact — we anonymize the identified customer's personal data across the store's trace records.
  • shop/redact — sent by Shopify roughly 48 hours after uninstall, we purge all of the store's data (trace configuration, lots, serials, trace events, assignments, scans, recalls, inventory shadow, cached product titles/images and billing records) and revoke the stored install.

Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.

8. Security

The app uses Shopify's OAuth for install and stores access tokens encrypted. Inbound webhooks are verified with HMAC signatures, and public App Proxy pages are verified with a signed request check. Public trace pages are read-only, exposure-gated per product, rate-limited and served with a strict content-security policy. Scan telemetry is stored only as salted hashes, all reads and writes are scoped to the individual store, and all traffic is served over TLS.

9. Cookies

The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.

10. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.

11. Contact

DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website

← Back to TraceOps

TraceOps
FeaturesPricingHow it worksPrivacy
Native Shopify app
© 2026 TraceOps by DiLight Entertainment UG (haftungsbeschränkt). Product traceability for Shopify.
TraceOps is not affiliated with or endorsed by Shopify Inc. “Shopify” is a trademark of Shopify Inc.