Privacy Policy for the App

This privacy policy applies to the PaketShip app for Shopify — software that installs into a Shopify store and creates DPD shipments and labels from its orders.

The dpdintegracija.com website has its own website privacy policy (Slovenian), which describes data processing when using the forms on this website. This page describes only data processing inside the app.

1. Who is responsible

The app is provided and operated by:

Manuel Fickovic, an individual established in Slovenia.
Email: info@dpdintegracija.com

The app is listed on the Shopify App Store and elsewhere under the name WP Mojster. That is a trading name of the provider named above, not a separate legal entity.

You can reach this address with any question about the processing of personal data in the app, or to exercise your rights.

The dpdintegracija.com website on which this page is published is operated by Denis Andersen s.p., Krožna cesta 10, 6000 Koper, Slovenia. Responsibility for data processing inside the app rests with the app provider named above.

2. Who is the controller and who is the processor

The merchant — the owner of the Shopify store — is the controller of their customers’ personal data. The app processes that data on the merchant’s instructions and solely to carry out what was requested: preparing a shipment with DPD. In that relationship, we act as processor.

DPD is an independent controller. Once a shipment is registered, DPD processes the recipient’s data to carry out delivery under its own rules and its own privacy policy. We are not responsible for delivery or for how DPD retains data.

Shopify is the platform the store runs on, and has its own relationship with the merchant and its own privacy policy.

3. What data is processed

Order data

The app requests access to orders, fulfillments and locations from Shopify. When you create a shipment from an order, the app reads:

  • the recipient’s first and last name and company name, if entered,
  • the delivery address: street and house number, an optional second address line, city, postcode and country,
  • the recipient’s phone number and email address,
  • the order number, weight or parcel count, and — for cash-on-delivery — the amount and currency.

This data counts as protected customer data under Shopify’s rules, and access to it is subject to a separate approval process at Shopify. Access is limited to what is listed above; the app does not read payment data, customer accounts, or store content.

Store and merchant data

We store the Shopify store’s address and its identifier, the time it was installed and removed, its time zone, the selected plan, and the settings you enter yourself: sender details (name, contact person, street, postcode, city, country, phone, email), your DPD EasyShip account username and password, and your default label and service settings.

The DPD password and the Shopify access token are encrypted in the database and are not shown anywhere in the interface.

4. What is stored and what is not

Of the recipient’s data, our database stores only:

  • the recipient’s name,
  • the postcode,
  • the country.

The recipient’s street address, phone number and email are never stored. When a shipment is created, they travel directly to DPD and leave no trace in our database.

We also store shipment data that is not personal: parcel numbers, the tracking number and link, weight, the selected service, country, the cash-on-delivery label and amount, shipment status, order number and timestamps.

This scope is chosen deliberately: the shipment overview has to work, and any data or log leak should never be able to expose more than is strictly necessary for that.

Labels

The generated label (PDF or ZPL) is stored, because DPD does not reissue it once a shipment has been registered. The label contains the recipient’s name and address — more than the shipment record itself. It is kept on a private part of the server that is not publicly reachable, and can only be downloaded through an authenticated route inside the app. The file is deleted when the shipment is cancelled.

5. Who receives the data

  • DPD — through the DPD EasyShip interface, using your DPD account, and only what is needed to produce the label and deliver the parcel: name (and company), street and house number, city, postcode, country, the recipient’s email and phone, weight, parcel count, service, order number, and for cash-on-delivery the amount and payment purpose.
  • Shopify — we write the tracking number and link back to the order and mark the order as fulfilled.
  • Hosting provider — OVH SAS, France, where the app’s server is located.

We do not sell customer data, do not pass it to third parties for their own purposes, and do not use it for advertising, profiling or automated decision-making. We use an email delivery provider for operational notifications, but those messages contain only technical operating data and no customer data.

6. Where the data is processed

The app runs on a server in the European Union (OVH SAS, France). We do not transfer data outside the EU. Shopify and DPD process data as part of their own services, each under its own privacy policy.

7. How long data is kept

  • Shipment data and stored labels are kept for as long as the app is installed — the shipment overview is part of the service.
  • When the app is uninstalled, the store’s access token is discarded immediately.
  • 48 hours after you uninstall the app, Shopify sends a request to delete the store’s data. At that point every stored label for that store, all shipment records, settings and the store record itself are deleted.
  • Backups are kept for 14 days and are then automatically overwritten. A deleted item can still exist in a backup until that period ends; backups are used exclusively to recover from an outage.

8. GDPR requests via Shopify

The app handles all three requests that Shopify sends automatically.

Customer data request

We locate the shipment records that relate to the listed orders and tell the merchant what is stored and where, so they can reply to the customer within the legal deadline. We do not copy the values of the data itself into a log while doing so — logging a customer’s data in order to answer a privacy request would create exactly the data the request is about.

Customer data erasure

On the shipment records for the listed orders, we delete the recipient’s name and postcode and any error text, delete the stored label, and mark the record as erased. Non-personal shipment data (parcel numbers, status, weight, timestamps) remains, because the merchant’s usage counter and shipment history depend on it. A deleted label cannot be recovered — the app itself is also not allowed to download it again from DPD.

Shop data erasure

We delete the entire folder of stored labels for that store, all shipment records, settings and the store record. A store that reinstalls the app after erasure starts with no settings and no history. Erasure is only carried out once the app is genuinely no longer installed on that store.

9. Security

  • All communication runs over an encrypted connection (HTTPS).
  • The DPD account password and the Shopify access token are encrypted in the database.
  • Labels sit on a private part of the server and are reachable only through an authenticated route.
  • Access to the internal support console is limited to the provider and protected by two-factor authentication.
  • Error messages are designed so that recipient data never ends up in their text.

10. Cookies

The app runs inside the Shopify admin interface and uses a single strictly necessary session cookie, which keeps you signed in. The app does not use analytics, advertising networks, tracking pixels or third-party scripts.

11. Your rights

If you are a customer of a store that uses this app, contact the store where you placed your order about your rights — the store is the controller of your data. We help the merchant fulfil the request; it can also be submitted through Shopify, which forwards it automatically.

If you are a merchant, you may at any time request access to the data we hold about your store, its correction, deletion or export, restriction of processing, or object to processing. Write to info@dpdintegracija.com.

If you believe your rights have been infringed, you have the right to lodge a complaint with a supervisory authority — in particular the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), the supervisory authority for the country where the controller is established, or the supervisory authority in your own country of residence.

12. Changes

Any change to this policy will be published on this page. If a change materially affects data processing inside the app, we will notify merchants.

Last updated: 10 August 2026.