COD2PAY
● LEGAL SPECIFICATION & DATA GOVERNANCE

COD2PAY Privacy Policy

How we protect, encrypt, and handle merchant store credentials and customer prepayment verification data across the Shopify ecosystem.

📅 Effective: January 1, 2026 GDPR & CCPA Compliant ⚖️ Shopify App Store Verified 🔐 AES-256-GCM Encrypted
🛡️ SHOPIFY APP PRIVACY COMMITMENT

COD2PAY Technologies ("COD2PAY", "we", "us", "our"), operated by QByteSoft, provides this Privacy Policy to explain how we handle information collected through our Shopify Checkout Extension and merchant administrative application. We hold customer trust paramount and design every feature around minimal data extraction and end-to-end cryptographic safeguards.

1. Overview & Scope

COD2PAY is a native Shopify application operating through Shopify's Checkout Extensibility framework (specifically on the post-purchase purchase.thank-you.block.render target and order status pages).

In the context of the European Union General Data Protection Regulation (GDPR) and similar global privacy frameworks:

  • For Merchant Data: COD2PAY acts as a Data Controller for account credentials, subscription identifiers, and gateway configuration settings provided by the merchant.
  • For Customer Checkout Data: The merchant acts as the Data Controller, and COD2PAY acts as a Data Processor, processing order metadata and transaction verification tokens solely on the merchant's instructions and for the singular purpose of validating prepayments.

2. Information We Collect

We adhere to strict data minimization principles. We only collect information strictly required to match payment confirmations, prevent fraud, and sync tags back to Shopify.

A. Merchant Store & Account Data

When a store owner installs COD2PAY through Shopify OAuth, we receive access tokens and store identity parameters via the Shopify Admin GraphQL API:

  • Shop unique identifier and primary domain (e.g. store.myshopify.com).
  • Store contact name, administrator email address, country, default currency, and timezone.
  • Merchant payout wallet credentials: bKash merchant/agent/personal numbers, Nagad numbers, Rocket IDs, Upay accounts, or bank wire details.
  • Custom incentive settings (e.g., cashback amounts, free shipping eligibility, display rules).

B. Customer Prepayment Submission Data

When a customer opts to convert their Cash-on-Delivery order into a verified instant prepayment on the Thank You or Order Status page, we collect:

  • Shopify Order ID and numeric order reference (e.g. #1024).
  • Total order payable amount and currency code (e.g. BDT, USD).
  • Customer payment source phone / wallet number (used strictly to cross-reference transactions).
  • Customer submitted Transaction ID (TrxID / UTR alphanumeric string).
  • Submission timestamp and selected payment method (bKash, Nagad, Rocket, Upay, Bank Wire).

🚫 STRICT EXCLUSION: WE NEVER COLLECT FINANCIAL SECRETS

COD2PAY NEVER collects, stores, or transmits customer PINs, Mobile Banking account passwords, credit card numbers, CVVs, or One-Time Passwords (OTPs). Prepayments occur entirely on the consumer's independent carrier rails (such as opening their native bKash or Nagad application). COD2PAY merely validates the transaction reference string generated by the banking provider.

3. How We Use Collected Information

Collected data is processed strictly for legitimate operational purposes:

01. VERIFICATION

TrxID Syntax & Duplicate Guard

Validating alphanumeric format rules and matching historical records to prevent dishonest duplicate submissions across orders.

02. SHOPIFY SYNC

Automated Order Tagging

Writing verified tags (e.g. COD2Pay-Prepaid) and updating order financial status via GraphQL Admin API.

03. COURIER AUTOMATION

Logistics Webhook Trigger

Notifying logistics APIs (Pathao, Steadfast, RedX) that payment is settled, waiving the 1.5% COD collection fee.

04. MERCHANT AUDIT

Reconciliation Ledger

Giving merchant finance teams an exportable audit record of dates, times, amounts, and transaction codes for account books.

4. Cryptographic Security & Storage

We deploy defense-in-depth architectural safeguards to guarantee merchant credentials and transaction verification logs remain impenetrable:

🔒 SYSTEM ENCRYPTION ARCHITECTURE
SOC 2 ALIGNED
AES-256-GCM at Rest

All merchant API tokens, payment credentials, and sensitive configuration tables are encrypted at rest using AES-256-GCM with unique initialization vectors.

TLS 1.3 in Transit

All communication between browser storefronts, Shopify GraphQL endpoints, and backend worker servers is enforced over TLS 1.3 with Perfect Forward Secrecy.

Strict Tenant Isolation

Merchant records are partitioned using unique shop identifiers. Cross-tenant queries are blocked at both application middleware and database schema layers.

Zero Plaintext Secrets

Webhook secrets and API access keys are cryptographically salted and hashed before persistence; plaintext versions are never visible in application logs.

5. Mandatory Shopify GDPR Webhook Compliance

In strict compliance with Shopify App Store requirements and European data protection law, COD2PAY listens for and automatically executes Shopify's three mandatory statutory data privacy webhooks in real time:

customers/data_request Mandatory Webhook 1/3

Customer Data Export Request

When a buyer contacts a merchant requesting a copy of their stored personal data, Shopify triggers this webhook. COD2PAY extracts all prepayment audit logs, customer phone references, and TrxID submissions linked to that customer's Shopify ID and securely delivers them to the merchant for fulfillment within 30 days.

customers/redact Mandatory Webhook 2/3

Customer Personal Data Erasure ("Right to be Forgotten")

When a buyer requests erasure of their personal information, COD2PAY immediately scrubs all identifying data — anonymizing the customer's phone number, scrubbing the wallet reference, and redacting personal identifiers from transaction logs while retaining aggregate numerical totals for merchant accounting integrity.

shop/redact Mandatory Webhook 3/3

Store Data Permanent Purge

Within 48 hours following an application uninstallation event, Shopify issues the shop/redact payload. COD2PAY permanently and irreversibly deletes all stored merchant credentials, gateway configurations, custom rules, cached order metadata, and historical verification logs from our database clusters.

6. Third-Party Subprocessors

We partner only with reputable technology vendors that maintain rigorous security certifications:

Subprocessor Function Location Security Standards
Shopify Inc. Platform hosting, App Bridge, Billing API, Order Webhooks Canada / Global SOC 2, PCI-DSS Level 1
Cloud Database Provider Managed PostgreSQL cluster with automated replication Singapore / US East ISO 27001, SOC 2 Type II
Courier Partner APIs Consignment tagging & fee waiver hooks (Pathao, Steadfast) Bangladesh HTTPS TLS 1.3, API Key HMAC

7. Data Retention & Erasure Policy

We retain verification records only as long as necessary to fulfill accounting reconciliation and merchant dispute resolution:

  • Active Merchant Accounts: Prepayment verification records (timestamp, TrxID, order reference) are retained for 90 days following transaction completion, after which personal phone numbers are automatically anonymized.
  • Uninstalled Stores: When an app uninstall occurs, all database tables for the respective store are queued for complete, irreversible deletion within 48 hours in concordance with Shopify's shop/redact policy.
  • Backup Cycles: Encrypted automated database backups expire and are permanently purged on a rolling 30-day lifecycle.

8. Merchant & Buyer Rights (GDPR & CCPA/CPRA)

Depending on your geographical location and the jurisdiction of your end customers, data subjects hold the following statutory rights:

Right to Access & Portability Request a machine-readable JSON or CSV export of all personal data held.
Right to Rectification Correct inaccurate payment phone numbers or merchant wallet records.
Right to Erasure ("To Be Forgotten") Permanently delete personal identification tokens and customer telemetry.
Right to Restriction & Objection Restrict automated profiling or object to certain operational processing.

To exercise any of these rights, contact us directly at support@qbytesoft.com. We respond to all verified privacy requests within thirty (30) calendar days.

9. Policy Updates & Changes

We may periodically update this Privacy Policy to reflect modifications in Shopify API policies, statutory regulations, or new payment gateway additions. Material amendments will be notified via our application dashboard and by updating the "Effective Date" at the top of this page.

10. Contact & Data Protection Officer

For questions, clarifications, compliance audits, or data deletion requests, please reach our designated Data Protection Officer:

COD2PAY Technologies / QByteSoft
Attn: Data Protection Officer & Privacy Compliance Team
Support Email: support@qbytesoft.com
WhatsApp Live Desk: +880 1611-032464
Corporate Portal: https://qbytesoft.com