Privacy Policy for the Shopify app FloziBack
Last updated: 12.09.2026
1. Controller and roles
The Shopify app “FloziBack” is provided by Flozify GmbH, Brühlstr. 3/1, 75236 Kämpfelbach, Germany, email: service@flozify.com.
For the data of shop customers submitted via the withdrawal form, the respective merchant (store operator) is the controller under the GDPR. Flozify GmbH processes this data as a processor on the basis of a data processing agreement under Art. 28 GDPR, which the merchant concludes inside the app. For merchant account and support data, Flozify GmbH is the controller itself.
2. What the app does
FloziBack provides the legally required online withdrawal button (§ 356a BGB, EU Directive 2023/2673). Customers submit their withdrawal declaration via a form on the merchant's shop domain, automatically receive a confirmation of receipt by email, and the merchant manages the submissions in the app.
3. Shop customer data (withdrawal form)
Collected: first and last name, email address, order or contract number, contract type, optionally affected items and reason. The app also stores the time of receipt (evidentiary timestamp), processing status, the merchant's notes and decisions. IP addresses are processed only as a hash for abuse prevention.
Purpose: fulfilment of the merchant's legal obligations under § 356a BGB (receiving, confirming and documenting the withdrawal declaration). Legal basis at the merchant: Art. 6(1)(c) GDPR (legal obligation) and (b) (contract).
Order matching: to assign the declaration, the app retrieves the order via the Shopify API by order number and email address (order date, line items, fulfilment status). Line items are only shown if the email address matches the order. Order data is not stored permanently.
Retention: withdrawal declarations are legal records and are kept for at least 36 months; the merchant can enable automatic deletion afterwards. Erasure requests via Shopify (customers/redact) lead to anonymisation once the evidence retention period has passed. When the app is uninstalled, all of the shop's data is deleted (shop/redact).
4. Email delivery
Confirmations of receipt, decision emails to customers and notifications to the merchant are sent via the provider Resend (Plus Five Five, Inc., USA). Recipient address, subject and content of the respective email are transmitted. The transfer to the USA is safeguarded by EU standard contractual clauses. On the Business plan the merchant can configure their own sender domain; the domain name and DNS verification status are stored for this.
5. Merchant data
Stored: shop domain, the Shopify user ID from the session token, settings (incl. notification addresses, sender name, templates), the selected plan, and signer, company and time of the DPA acceptance. Billing is handled exclusively by Shopify; Flozify GmbH receives no payment data. Legal basis: Art. 6(1)(b) GDPR.
Optional automations (Pro plan) transmit data only to targets enabled by the merchant: Shopify (returns, order tags) and a webhook endpoint named by the merchant (signed JSON message with name, email, order number and status of the withdrawal).
6. Hosting, database and sub-processors
The app runs on Vercel Inc. (serverless, data centre region Frankfurt am Main); the database is hosted by Supabase Inc. (region Frankfurt am Main). Both are US companies with EU data centres; the contractual relationship is safeguarded by standard contractual clauses or the Data Privacy Framework. Further sub-processors: Resend (email), Shopify International Ltd. (platform and billing, Ireland).
7. Access permissions in Shopify (scopes)
The app requests: read orders (order matching, line items for partial withdrawals, deadline marking), write orders (optional tagging of the order with the withdrawal status), write returns (optional automatic creation of a return). Of the protected customer data, only the order's email address is used, to verify that the submitter is the buyer.
8. Security
Transport encryption on all connections, strict separation of merchant data, row-level security in the database, two-factor authentication for all operational access, HMAC verification of all Shopify requests, no storage of plain-text IP addresses. The technical and organisational measures are documented as an annex to the data processing agreement.
9. Data subject rights
Shop customers contact the respective merchant for access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR); Flozify GmbH supports the merchant technically (e.g. via the Shopify privacy webhooks). Merchants and app users contact service@flozify.com directly. You have the right to lodge a complaint with a data protection supervisory authority.
10. Changes
This policy is updated when the app or the legal situation changes. The version published here applies.