Service privacy policy
Who processes your data
The service is published by GRT Ventures OÜ, a company incorporated in Estonia. Questions on this page are handled by the legal representative of GRT Ventures OÜ, reachable at the contact address at the bottom of this page.
GRT Ventures OÜ acts in two distinct roles. For the data of merchants who open an account, it is the data controller. For the data of the buyers of those merchants' shops, it acts as a data processor, on the merchant's instructions. The merchant remains the controller towards their own customers.
Data processed on the merchant side
- Contact e-mail address of the account.
- Password, stored only in hashed form. It is never kept in plain text.
- Shop domain and shop name.
- API keys used to connect the shop to the service.
- Subscribed plan and the usage data needed for billing.
- Technical logs related to the use of the service.
- Sign-in history of the account: date, authentication method, IP address, browser, success or failure.
Data processed about end buyers
When a shop connects the service, the service receives the following buyer data for each order.
- E-mail address and name.
- Country code of the delivery destination.
- Order number, order amount and currency.
- Carrier tracking numbers and the masked tracking identifier generated by the service.
- Parcel transport events, meaning the statuses and logistics locations provided by carriers.
The service neither receives nor stores the buyer's postal address or phone number.
Purposes
- Generate a presentable tracking identifier and display a tracking page to the buyer.
- Send delivery notifications by e-mail, where the merchant has enabled this feature.
- Bill the merchant according to their usage.
- Keep the service secure and diagnose incidents.
- Answer support requests.
Legal bases
Merchant data is processed to perform the contract between the merchant and the service. Buyer data is processed on the merchant's instructions, under that same contract. The merchant is responsible for the legal basis that applies to their own customers. Technical logs are kept under the legitimate interest of securing the service.
Sub-processors
The service relies on the following providers.
- Hetzner Online GmbH, for server hosting, in Germany and Finland.
- OpenAI, for the classification of transport event labels. This provider only receives commercial fields: the event status and description, its logistics location, a country code, the carrier name and the parcel's origin country. It never receives a buyer's e-mail, name, order number or tracking number.
- A tracking data provider is currently being selected. This page will be updated before any real data is processed by that provider.
Integrations enabled by the merchant
The service can send tracking data to third-party tools, in particular Klaviyo, Gorgias and outbound webhooks configured by the merchant. These integrations are off by default. They only run when the merchant decides to enable them, chooses the recipient and remains responsible for how the data is used in that tool.
Retention periods
Merchant account data and the related buyer data are kept for the duration of the contract. They are purged when the account is deleted, subject to legal retention obligations, in particular billing records. Technical logs are kept for 180 days. The sign-in history of the merchant account (date, authentication method, IP address, browser, success or failure) is kept for 365 days, then purged automatically.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability provided by the General Data Protection Regulation.
If you are a merchant, send your request directly to the contact address at the bottom of this page.
If you bought from a shop that uses the service, send your request to that merchant. They are your data controller, and the service assists them in answering. For Shopify shops, the service receives and handles the requests forwarded by the platform's compliance webhooks, which cover data access and data erasure.
Complaints
You can lodge a complaint with the Estonian data protection authority, the Andmekaitse Inspektsioon (www.aki.ee), or with the supervisory authority of your country of residence.
Changes
This page may evolve with the service. The date of the last update is shown at the bottom. If a sub-processor changes, the list above is updated before the corresponding processing starts.