This appendix applies in addition to the general Cosmetic Wholesale website privacy policy. It covers personal data processed when a Shopify merchant installs and uses the Cosmetic Wholesale Sync app (sync.cosmeticwholesale.eu).
Controller / operator: Distraal B.V. trading as Cosmetic Wholesale.
Privacy contact: privacy@cosmeticwholesale.eu
1. Role of the parties
- The merchant is the Shopify store operator. Customer personal data in the store belongs to the merchant’s relationship with their end customers.
- Cosmetic Wholesale / Distraal B.V. processes certain order-related personal data as a service provider / processor solely to fulfil dropship orders the merchant places through Cosmetic Wholesale via this app.
- We do not sell merchant customer data and do not use it for unrelated marketing.
Merchants remain responsible for their own privacy notices to end customers and for the lawful basis of sales.
2. What data we process (Shopify → Cosmetic Wholesale)
When a merchant enables order sync and a customer pays an order that contains synced catalogue products, the app reads from the Shopify Admin API (scopes granted at install) and transmits to Cosmetic Wholesale’s order API:
| Data | Purpose |
|---|---|
| Customer name | Shipping label / fulfilment |
| Order contact / fulfilment exceptions | |
| Phone | Delivery coordination where provided |
| Shipping address (and billing if required) | Delivery |
| Order lines (SKU/EAN, qty), order id / external reference | Fulfilment accuracy |
| Tracking numbers from Cosmetic Wholesale | Written back to Shopify fulfilment when enabled |
Catalogue sync (products, prices, stock, images) uses wholesale product feed data and the merchant’s account token — not end-customer PII.
3. Legal bases
Processing is necessary to perform the dropshipping / fulfilment service the merchant requests (contractual necessity with the merchant; merchant’s instructions). Where local law requires end-customer consent for certain processing, the merchant is responsible for collecting it.
4. How data flows
- Customer checks out on the merchant’s Shopify store.
- On payment, Shopify notifies the app (
orders/paid) or the app processes queued pushes. - App sends order + shipping contact fields to Cosmetic Wholesale over HTTPS.
- Cosmetic Wholesale fulfils from warehouse; tracking may be returned and written to Shopify.
App runtime data is stored in a dedicated PostgreSQL database (EU-region infrastructure as configured by ops), including Shopify session tokens and per-shop settings. Order payloads are retained only as needed for retries, support, and audit.
5. Retention
| Data | Retention |
|---|---|
| Shopify OAuth sessions | Until uninstall or token expiry / refresh |
| Shop settings (token, margins) | Until uninstall or merchant deletes/rotates |
| Order push records / payloads | Typically up to 90 days after successful delivery or last retry (then deleted or anonymised), unless legal hold applies |
| PII access logs | Same retention window as order push records |
| Application logs | Short operational window (about 14–30 days); avoid full PII where possible |
On Shopify customers/redact, shop/redact, and customers/data_request compliance webhooks, we process deletion / export requests for data we hold for that shop/customer as required. Automated purge runs daily via the app’s retention job (job=purge).
6. Subprocessors / access
- Hosting / database / infrastructure providers (e.g. DigitalOcean) under our config
- Shopify (as the merchant’s platform)
- Cosmetic Wholesale operational systems used to pick, pack, and ship
Staff access to production systems containing protected customer data is limited to roles that need it for support and incident response, protected by strong authentication, and logged where feasible (PiiAccessLog).
7. Security measures (summary)
- TLS for data in transit (HTTPS)
- Encryption at rest as provided by managed database / volume encryption
- Separate production databases for staging vs public Shopify apps
- Secrets in Kubernetes Secrets / env, not in client-side code
- Mandatory Shopify compliance webhooks on the app host
8. Merchant and end-customer rights
- Merchants can uninstall the app; we stop receiving new webhooks and purge shop data per retention /
shop/redact. - End customers should contact the merchant first for access/deletion related to their purchase; we honour platform erasure flows via compliance webhooks.
- Privacy contact: privacy@cosmeticwholesale.eu
9. Changes
We may update this appendix; the “Last updated” date will change. Material changes affecting merchants will be communicated via listing notes or partner communications where appropriate.
This page supports Shopify App Store Protected Customer Data requirements. It is not a substitute for independent legal advice.
