Privacy Policy
Last updated: 29 July 2026
This policy explains what data the Fulfyra: Auto Fulfillments app (“the App”) accesses when a merchant installs it on their Shopify store, why, how long it is kept, and how it is deleted.
Who we are
The App is provided by SmallRocks Studio (“we”, “us”), contactable at support@smallrocks.studio. For data processed on a merchant’s behalf, the merchant is the data controller and we act as a data processor.
What we access, and why
When a merchant installs the App it requests access to the following Shopify data through Shopify’s official APIs, and uses it only to run automatic fulfillments:
| Data | Why we access it |
|---|---|
| Orders and their fulfillment status | To find orders with line items that match the merchant's auto-fulfillment rules, and to record what was fulfilled. |
| Fulfillment orders | To create fulfillments for eligible line items through Shopify's official Admin API. |
| Product information (tags, shipping requirement) | To evaluate the merchant's matching rules and to let the merchant hand-pick products in the app's settings. |
We do not request access to customer records, and we do not use any data for advertising, profiling, or resale. We never sell personal data.
What we store, and where
The App runs on a private server hosted by Hetzner Online GmbH, in Finland (European Union). Its database holds:
- Merchant staff account details supplied by Shopify when signing in: name, email address, locale, and the access token for the store.
- Store settings: the matching rules, order filters, scan schedule, the store’s name and contact email, and an optional notification email address the merchant provides. No buyer data.
- Scan and fulfillment history: which orders were scanned and what was fulfilled, identified only by order references (Shopify order ID and order number, e.g. #1042) plus line-item counts and error messages. The App never stores buyer names, email addresses, shipping addresses, or payment details.
- Privacy-request records: Shopify’s mandatory privacy webhooks (see below) are recorded for audit, including the customer reference Shopify sends with them.
- Background job records: internal queue entries for scans, fulfillments, and emails. Their payloads carry order references and configuration, not buyer data; finished jobs are purged automatically after 30 days.
Data in transit
All traffic between the merchant’s browser, Shopify, and the App is encrypted with TLS/HTTPS.
Sub-processors
- Shopify Inc.: the platform the App runs on and the system of record for all order and product data.
- Hetzner Online GmbH: hosts the App server and its database in Finland (EU).
- MXroute (transactional email): delivers the App’s emails to the merchant (activity notifications, billing reminders). It processes the merchant’s email address and the email content, which may involve servers outside the European Economic Area. No buyer data is ever emailed.
We share data with no other third parties.
Retention and deletion
- Scan and fulfillment history is kept while the App is installed, so merchants can audit past runs.
- Background job records are purged automatically after 30 days.
- On uninstall, the store’s access tokens and sessions are deleted immediately. The remaining store data is deleted when Shopify sends its shop-redaction request (48 hours after uninstall), which removes every record for that store from the App’s database.
The App implements Shopify’s mandatory privacy webhooks:
- Customer data request: we notify the merchant and describe the data the App holds. Because the App stores no buyer personal data, this is limited to order references.
- Customer redaction: recorded and confirmed immediately. The App holds no buyer personal data to erase.
- Shop redaction: all of that store’s data is permanently deleted from the App’s database.
Your rights
Buyers should direct privacy requests to the merchant whose store they shopped at (the data controller), who can fulfil them using the mechanisms above. Depending on your jurisdiction (for example GDPR or CCPA) you may have the right to access, correct, delete, or restrict processing of your personal data, and to lodge a complaint with your supervisory authority. Merchants can contact us at support@smallrocks.studio for assistance.
Changes to this policy
We may update this policy; material changes are reflected in the “Last updated” date above.
Contact
SmallRocks Studio: support@smallrocks.studio