{"id":4490,"date":"2026-07-17T09:02:19","date_gmt":"2026-07-17T09:02:19","guid":{"rendered":"https:\/\/8digits.es\/?page_id=4490"},"modified":"2026-07-17T15:06:32","modified_gmt":"2026-07-17T15:06:32","slug":"checkoutcontrol-privacy-policy","status":"publish","type":"page","link":"https:\/\/blue.8digits.es\/es\/checkoutcontrol-privacy-policy\/","title":{"rendered":"CheckoutControl Privacy Policy"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Effective date:** 17 July 2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CheckoutControl (the <strong>App<\/strong>) is provided by P\u00e9ter Kiss, a self-employed sole<br>trader (aut\u00f3nomo) established in Spain, trading as 8DIGITS Digital Marketing<br>(<strong>we<\/strong>, <strong>us<\/strong>o <strong>our<\/strong>). This policy explains how the App<br>processes information when a Shopify merchant installs or uses CheckoutControl.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Who is responsible<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Provider:<\/strong> P\u00e9ter Kiss, self-employed sole trader (aut\u00f3nomo)<br><strong>Registered address:<\/strong> Calle Las Huertas 15, Frigiliana, 27988 M\u00e1laga, Spain<br><strong>Registration and tax number:<\/strong> ESZ0486396C<br><strong>Privacy contact:<\/strong> support@8digits.es<br><strong>DPO or representative:<\/strong> A separate Data Protection Officer or EU\/UK<br>representative has not been appointed because the owner determined that one is<br>not required for the current processing. P\u00e9ter Kiss remains the privacy contact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For personal information about a merchant&#8217;s buyers, the merchant generally<br>decides why CheckoutControl is used and should be the buyer&#8217;s first contact.<br>We act as an independent controller for merchant account details, support<br>correspondence, security logs, billing records, and our own legal compliance.<br>When CheckoutControl processes merchant buyer data solely to provide the App<br>under the merchant&#8217;s instructions, we act as the merchant&#8217;s processor or<br>service provider. Shopify executes the Functions described below, and the<br>current App does not persist their buyer\/cart input in its application database.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. Information CheckoutControl processes<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Merchant and app-user information<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a merchant installs or uses the App, Shopify can provide and the App can<br>store:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The shop&#8217;s <code>myshopify.com<\/code> domain and installation timestamps.<\/li>\n\n\n\n<li>Shopify authentication sessions, access and refresh tokens, granted scopes,<br>session expiry information, and authentication state.<\/li>\n\n\n\n<li>For an online Shopify user session, when Shopify provides it: Shopify user ID,<br>first and last name, email address, locale, account-owner or collaborator<br>status, and email-verification status.<\/li>\n\n\n\n<li>Rules created by the merchant, including names, priorities, enabled state,<br>conditions, and payment, delivery, or COD-fee actions.<\/li>\n\n\n\n<li>App settings, including COD detection mode, merchant-configured COD gateway<br>names or handles, Shopify Function owner IDs, and the supporting fee-variant<br>ID.<\/li>\n\n\n\n<li>COD-fee settings, including whether the fee is enabled, fixed or percentage<br>type, amount, label, and supporting Shopify product-variant ID.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Buyer and cart information processed by Shopify Functions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To evaluate the merchant&#8217;s rules during a cart or checkout, CheckoutControl&#8217;s<br>Shopify Functions can transiently process the minimum fields needed for the<br>configured rules:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cart lines, quantities, product and variant identifiers, product-tag<br>membership, variant weight and weight unit, and cart amounts and currency.<\/li>\n\n\n\n<li>Delivery-option handles, titles, costs, and currency.<\/li>\n\n\n\n<li>Delivery country, province or state, city, and postal or ZIP code.<\/li>\n\n\n\n<li>Whether a signed-in customer has one of the specific tags configured by the<br>merchant. Shopify returns tag-membership results; CheckoutControl does not<br>request the customer&#8217;s tag list.<\/li>\n\n\n\n<li>The cart attribute <code>_cod_selected<\/code>, which records whether the buyer selected<br>the cart-page COD option.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The current Function inputs do <strong>not<\/strong> request a buyer&#8217;s customer ID, name,<br>email address, phone number, or order history. CheckoutControl does not persist<br>the Function&#8217;s buyer\/cart input in its application database. Shopify executes<br>the Functions and applies their returned payment, delivery, or cart-transform<br>operations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cart-page selector<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When enabled by the merchant, the theme app block writes <code>_cod_selected<\/code> as a<br>Shopify cart attribute through Shopify&#8217;s cart API. The App&#8217;s current source does<br>not add advertising, marketing, or behavioral-analytics trackers to the<br>storefront. Shopify and the merchant&#8217;s theme or other apps may independently<br>use cookies or similar technologies under their own policies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Support and operational information<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a merchant contacts support, we receive the information they choose to send,<br>such as contact details, store domain, screenshots, and troubleshooting details.<br>Do not send access tokens, passwords, payment-card data, or unnecessary buyer<br>information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The App creates limited operational logs containing events such as shop domain,<br>webhook topic, Function registration or configuration status, payload size, and<br>error details. Compliance-webhook payload bodies and their customer or order<br>identifiers are not intentionally logged by the current source.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. How information is used<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We use information to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Authenticate the merchant and operate the embedded Shopify app.<\/li>\n\n\n\n<li>Save and apply the merchant&#8217;s payment, delivery, and COD-fee rules.<\/li>\n\n\n\n<li>Register and configure Shopify Functions and the cart-page theme block.<\/li>\n\n\n\n<li>Provision or validate the merchant&#8217;s supporting COD-fee product variant.<\/li>\n\n\n\n<li>Provide Shopify-managed billing, installation, support, security, debugging,<br>and service reliability.<\/li>\n\n\n\n<li>Respond to privacy, legal, fraud, abuse, and security obligations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For controller-side processing, we rely on performance of the merchant contract<br>where Article 6(1)(b) GDPR applies; our legitimate interests under Article<br>6(1)(f) in operating, securing, supporting, debugging, preventing abuse, and<br>improving the App&#8217;s reliability; and Article 6(1)(c) legal obligations for tax,<br>accounting, regulatory, privacy, and lawful-request compliance. Where a future<br>optional purpose requires consent, we will request it before that processing.<br>The current source has no advertising or behavioral-analytics purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We do not use buyer information for advertising, data-broker activity, or<br>independent profiling. We do not sell or share personal information as those<br>terms are defined by the California Consumer Privacy Act.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Service providers and disclosures<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CheckoutControl depends on:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Shopify<\/strong>, for app distribution, authentication, APIs, billing, storefront<br>cart storage, Functions execution, and checkout processing.<\/li>\n\n\n\n<li><strong>Railway<\/strong>, for application hosting, operational logs, and PostgreSQL<br>database hosting.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Shopify&#8217;s privacy terms and Data Processing Addendum are available at<br>https:\/\/www.shopify.com\/legal\/privacy and https:\/\/www.shopify.com\/legal\/dpa.<br>Railway&#8217;s privacy policy, terms, and Data Processing Addendum are available at<br>https:\/\/railway.com\/legal\/privacy, https:\/\/railway.com\/legal\/terms, and<br>https:\/\/railway.com\/legal\/dpa. The current source uses no other runtime<br>subprocessors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We can also disclose information when required by law, to protect rights or<br>security, in connection with a business transaction, or with the merchant&#8217;s<br>instructions. We require service providers to process information only for the<br>agreed services and subject to appropriate safeguards.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. International transfers and hosting location<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The App is operated from Spain. Railway stores and processes the production<br>application and PostgreSQL database in the EU. Shopify and Railway may process<br>information in other locations as described in their applicable terms and<br>DPAs. Where required, international transfers are protected through applicable<br>adequacy mechanisms, standard contractual clauses, or other lawful safeguards.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">6. Retention and deletion<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Active installation data and authentication sessions are retained while<br>needed to provide the App.<\/li>\n\n\n\n<li>The current App deletes its active shop, rule, settings, COD-fee, and session<br>rows when it receives a valid uninstall or <code>shop\/redact<\/code> event.<\/li>\n\n\n\n<li>CheckoutControl does not maintain application-database buyer profiles for the<br>Function inputs described above.<\/li>\n\n\n\n<li>Application logs are retained for 90 days. Database backups are retained and<br>aged out within 90 days after uninstall or a valid deletion request.<\/li>\n\n\n\n<li>Support records are retained for 365 days.<\/li>\n\n\n\n<li>We can retain specific information longer when required by law, to establish<br>or defend legal claims, or to prevent fraud or abuse.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Shopify requires App Store apps to act on valid privacy requests within 30 days,<br>subject to lawful retention exceptions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7. Privacy requests and choices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on applicable law, an individual may have rights to access, correct,<br>delete, restrict, object to, or receive a portable copy of personal information,<br>and to complain to a data-protection authority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Buyers should normally submit requests to the Shopify merchant that operates the<br>store. Merchants and other individuals can contact support@8digits.es. We may need<br>to verify the request and coordinate with the relevant merchant and Shopify.<br>The App is subscribed to Shopify&#8217;s mandatory <code>customers\/data_request<\/code>,<br><code>customers\/redact<\/code>y <code>shop\/redact<\/code> compliance webhooks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">P\u00e9ter Kiss records each request and its deadline, verifies the requester using<br>the least additional information reasonably necessary, identifies the relevant<br>merchant and responsible party, coordinates with the merchant and Shopify,<br>searches applicable app, session, support, and operational records, and carries<br>out the applicable access, correction, export, restriction, or deletion. We<br>respond within 30 days unless applicable law permits an extension. Backups age<br>out under the retention schedule above, and a minimal response record is kept<br>under the support-record schedule.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The current App uses Shopify OAuth, Shopify&#8217;s webhook authentication, encrypted<br>HTTPS connections, restricted OAuth scopes, and access-controlled production<br>services. Railway provides encryption at rest, managed backups, access controls,<br>access reviews, incident-response procedures, and secret-rotation controls for<br>the production application and PostgreSQL database. No internet service is<br>completely secure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">9. Changes to this policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We may update this policy when CheckoutControl, our providers, or legal<br>requirements change. We will post the revised policy at<br>https:\/\/8digits.es\/checkoutcontrol-privacy-policy\/ and update the effective<br>date. Where required, we will provide additional notice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">10. Contact<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Questions or privacy requests can be sent to:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">P\u00e9ter Kiss, trading as 8DIGITS Digital Marketing<br>Calle Las Huertas 15, Frigiliana, 27988 M\u00e1laga, Spain<br>support@8digits.es<\/p>","protected":false},"excerpt":{"rendered":"<p>Effective date:** 17 July 2026 CheckoutControl (the App) is provided by P\u00e9ter Kiss, a self-employed soletrader (aut\u00f3nomo) established in Spain, trading as 8DIGITS Digital Marketing(we, us, or our). This policy explains how the Appprocesses information when a Shopify merchant installs or uses CheckoutControl. 1. Who is responsible Provider: P\u00e9ter Kiss, self-employed sole trader (aut\u00f3nomo)Registered address: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"nf_dc_page":"","om_disable_all_campaigns":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-4490","page","type-page","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/pages\/4490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/comments?post=4490"}],"version-history":[{"count":3,"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/pages\/4490\/revisions"}],"predecessor-version":[{"id":4502,"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/pages\/4490\/revisions\/4502"}],"wp:attachment":[{"href":"https:\/\/blue.8digits.es\/es\/wp-json\/wp\/v2\/media?parent=4490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}