Privacy Policy
Last updated 31 July 2026
This policy covers the Shopify app Nilla ("the app"), operated by Rafael Ortiz ("we", "us"). It explains what the app stores, why, who it is shared with, and how long it is kept.
In data protection terms: for the order data the app processes, the merchant who installs it is the controller and we are a processor acting on their instructions. Calendar events are written into the merchant's own Google account, where the merchant is the controller and we hold no copy beyond what is described below.
What the app stores
| Data | Why | Kept for |
|---|---|---|
| Shop domain, shop name, timezone, granted permissions, install date | To identify the store and read cutoff times in the right timezone | Until uninstall |
| Shopify access token | To read orders. Encrypted at rest with AES-256-GCM | Until uninstall |
| Google refresh token, Google account email, calendar identifier | To write events to the calendar the app created. Encrypted at rest | Until you disconnect or uninstall |
| Your configuration — workflows, cutoff rules, tag filters, teams, and the staff email addresses you invite | It is the app's settings | Until uninstall |
| Order webhooks received from Shopify. These contain customer names, addresses, phone numbers and line items | Recorded on arrival so a slow or failed sync cannot lose an order, and so you can see what happened on the sync log | 30 days, then the contents are erased automatically |
| A record of which order produced which calendar event, and a fingerprint of the event's content | So re-running a sync updates the existing event instead of creating a duplicate | Until uninstall |
| Events staged for approval, where a workflow requires it — including the event title, description and invitee list | So you can approve or reject them | Until decided, then until uninstall |
After 30 days the stored webhook contents are erased but a payload-free record that the delivery happened is retained, so there is still an audit trail of what the app did.
What the app does not do
- It never receives payment card details. Shopify does not send them.
- It asks Shopify only for read access to orders and products. It cannot modify, fulfil or cancel an order.
-
On Google it uses the
calendar.app.createdpermission, which limits it to calendars it created itself. It cannot read, change or even list your existing calendars. - There is no advertising, no analytics or tracking service, no profiling, and no automated decision-making with legal effect.
- We do not sell or share personal information, in the CCPA sense or any other.
Who the data is shared with
The app sends data to three places, and nowhere else:
- Google Calendar — the event title, description, location, time and invitee list are written to the calendar the app created in your Google account. What appears there is whatever your workflow templates produce, which may include order and customer details you chose to include.
- Shopify — the app calls Shopify's Admin API to read orders and shop details.
- OVH Cloud — hosts the server and database, in the US East region.
We may also disclose data where legally required. We would tell you first unless prohibited from doing so.
Where the data is held
On servers operated by OVH Cloud, located in the United States (US East). Google processes calendar data according to its own terms and may store it in other countries. Where personal data of people in the UK/EEA leaves that area, the transfer relies on the UK/EU Standard Contractual Clauses or an adequacy decision.
How it is protected
- All traffic is over HTTPS. Plain HTTP is redirected and refused.
- Shopify access tokens and Google refresh tokens are encrypted at rest with AES-256-GCM. They are never written to logs.
- Every request from the Shopify admin is authenticated by a signed session token, and every webhook by an HMAC signature, both verified before anything is read or written.
- Each store's data is scoped to that store. The app has no interface through which one merchant can reach another's orders, settings or events.
- The database is not reachable from the public internet.
What happens when you uninstall
- The app's access to your Google account is released immediately. Calendar events already created are left alone — they are yours, in your calendar. If you would rather they were removed, there is a setting for that; turn it on before uninstalling.
- Shopify sends a shop redaction request around 48 hours later. On receiving it we delete the store's record, tokens, configuration and stored order data. A payload-free record that the request was honoured is kept as evidence it was actioned.
Your rights, and your customers'
Depending on where you or your customers live, there may be a right to access, correct, delete, or export personal data, to restrict or object to processing, and to complain to a supervisory authority.
Because we act on the merchant's behalf, a customer's request should go to the merchant, who can raise it with us. The app implements Shopify's mandatory privacy webhooks, so a request made through Shopify reaches us automatically:
- Customer data request — we respond to the merchant within 30 days with the data held for that customer.
- Customer redaction — stored order data for the named orders is erased.
- Shop redaction — everything belonging to the store is deleted, as described above.
You can also write to rortiz@nilla.app directly. We do not charge for these requests and will not treat you differently for making one.
Children
The app is a business tool, is not directed at children, and we do not knowingly collect data from them.
Changes
If this policy changes materially we will update the date above and notify merchants by email or in the app before the change takes effect.
Contact
Rafael Ortiz
rortiz@nilla.app