COD2PAY Privacy Policy
How we protect, encrypt, and handle merchant store credentials and customer prepayment verification data across the Shopify ecosystem.
COD2PAY Technologies ("COD2PAY", "we", "us", "our"), operated by QByteSoft, provides this Privacy Policy to explain how we handle information collected through our Shopify Checkout Extension and merchant administrative application. We hold customer trust paramount and design every feature around minimal data extraction and end-to-end cryptographic safeguards.
1. Overview & Scope
COD2PAY is a native Shopify application operating through Shopify's Checkout Extensibility framework (specifically on the post-purchase purchase.thank-you.block.render target and order status pages).
In the context of the European Union General Data Protection Regulation (GDPR) and similar global privacy frameworks:
- For Merchant Data: COD2PAY acts as a Data Controller for account credentials, subscription identifiers, and gateway configuration settings provided by the merchant.
- For Customer Checkout Data: The merchant acts as the Data Controller, and COD2PAY acts as a Data Processor, processing order metadata and transaction verification tokens solely on the merchant's instructions and for the singular purpose of validating prepayments.
2. Information We Collect
We adhere to strict data minimization principles. We only collect information strictly required to match payment confirmations, prevent fraud, and sync tags back to Shopify.
A. Merchant Store & Account Data
When a store owner installs COD2PAY through Shopify OAuth, we receive access tokens and store identity parameters via the Shopify Admin GraphQL API:
- Shop unique identifier and primary domain (e.g.
store.myshopify.com). - Store contact name, administrator email address, country, default currency, and timezone.
- Merchant payout wallet credentials: bKash merchant/agent/personal numbers, Nagad numbers, Rocket IDs, Upay accounts, or bank wire details.
- Custom incentive settings (e.g., cashback amounts, free shipping eligibility, display rules).
B. Customer Prepayment Submission Data
When a customer opts to convert their Cash-on-Delivery order into a verified instant prepayment on the Thank You or Order Status page, we collect:
- Shopify Order ID and numeric order reference (e.g.
#1024). - Total order payable amount and currency code (e.g. BDT, USD).
- Customer payment source phone / wallet number (used strictly to cross-reference transactions).
- Customer submitted Transaction ID (TrxID / UTR alphanumeric string).
- Submission timestamp and selected payment method (bKash, Nagad, Rocket, Upay, Bank Wire).
🚫 STRICT EXCLUSION: WE NEVER COLLECT FINANCIAL SECRETS
COD2PAY NEVER collects, stores, or transmits customer PINs, Mobile Banking account passwords, credit card numbers, CVVs, or One-Time Passwords (OTPs). Prepayments occur entirely on the consumer's independent carrier rails (such as opening their native bKash or Nagad application). COD2PAY merely validates the transaction reference string generated by the banking provider.
3. How We Use Collected Information
Collected data is processed strictly for legitimate operational purposes:
TrxID Syntax & Duplicate Guard
Validating alphanumeric format rules and matching historical records to prevent dishonest duplicate submissions across orders.
Automated Order Tagging
Writing verified tags (e.g. COD2Pay-Prepaid) and updating order financial status via GraphQL Admin API.
Logistics Webhook Trigger
Notifying logistics APIs (Pathao, Steadfast, RedX) that payment is settled, waiving the 1.5% COD collection fee.
Reconciliation Ledger
Giving merchant finance teams an exportable audit record of dates, times, amounts, and transaction codes for account books.
4. Cryptographic Security & Storage
We deploy defense-in-depth architectural safeguards to guarantee merchant credentials and transaction verification logs remain impenetrable:
All merchant API tokens, payment credentials, and sensitive configuration tables are encrypted at rest using AES-256-GCM with unique initialization vectors.
All communication between browser storefronts, Shopify GraphQL endpoints, and backend worker servers is enforced over TLS 1.3 with Perfect Forward Secrecy.
Merchant records are partitioned using unique shop identifiers. Cross-tenant queries are blocked at both application middleware and database schema layers.
Webhook secrets and API access keys are cryptographically salted and hashed before persistence; plaintext versions are never visible in application logs.
5. Mandatory Shopify GDPR Webhook Compliance
In strict compliance with Shopify App Store requirements and European data protection law, COD2PAY listens for and automatically executes Shopify's three mandatory statutory data privacy webhooks in real time:
Customer Data Export Request
When a buyer contacts a merchant requesting a copy of their stored personal data, Shopify triggers this webhook. COD2PAY extracts all prepayment audit logs, customer phone references, and TrxID submissions linked to that customer's Shopify ID and securely delivers them to the merchant for fulfillment within 30 days.
Customer Personal Data Erasure ("Right to be Forgotten")
When a buyer requests erasure of their personal information, COD2PAY immediately scrubs all identifying data — anonymizing the customer's phone number, scrubbing the wallet reference, and redacting personal identifiers from transaction logs while retaining aggregate numerical totals for merchant accounting integrity.
Store Data Permanent Purge
Within 48 hours following an application uninstallation event, Shopify issues the shop/redact payload. COD2PAY permanently and irreversibly deletes all stored merchant credentials, gateway configurations, custom rules, cached order metadata, and historical verification logs from our database clusters.
6. Third-Party Subprocessors
We partner only with reputable technology vendors that maintain rigorous security certifications:
| Subprocessor | Function | Location | Security Standards |
|---|---|---|---|
| Shopify Inc. | Platform hosting, App Bridge, Billing API, Order Webhooks | Canada / Global | SOC 2, PCI-DSS Level 1 |
| Cloud Database Provider | Managed PostgreSQL cluster with automated replication | Singapore / US East | ISO 27001, SOC 2 Type II |
| Courier Partner APIs | Consignment tagging & fee waiver hooks (Pathao, Steadfast) | Bangladesh | HTTPS TLS 1.3, API Key HMAC |
7. Data Retention & Erasure Policy
We retain verification records only as long as necessary to fulfill accounting reconciliation and merchant dispute resolution:
- Active Merchant Accounts: Prepayment verification records (timestamp, TrxID, order reference) are retained for 90 days following transaction completion, after which personal phone numbers are automatically anonymized.
- Uninstalled Stores: When an app uninstall occurs, all database tables for the respective store are queued for complete, irreversible deletion within 48 hours in concordance with Shopify's
shop/redactpolicy. - Backup Cycles: Encrypted automated database backups expire and are permanently purged on a rolling 30-day lifecycle.
8. Merchant & Buyer Rights (GDPR & CCPA/CPRA)
Depending on your geographical location and the jurisdiction of your end customers, data subjects hold the following statutory rights:
To exercise any of these rights, contact us directly at support@qbytesoft.com. We respond to all verified privacy requests within thirty (30) calendar days.
9. Policy Updates & Changes
We may periodically update this Privacy Policy to reflect modifications in Shopify API policies, statutory regulations, or new payment gateway additions. Material amendments will be notified via our application dashboard and by updating the "Effective Date" at the top of this page.
10. Contact & Data Protection Officer
For questions, clarifications, compliance audits, or data deletion requests, please reach our designated Data Protection Officer: