This app runs inside a merchant's Shopify admin and asks that merchant's customers, through the store's own email, whether an order arrived.
Order number, the shipping method's name, and each fulfilment's tracking company, number, URL and status, through the Shopify Admin API. No customer name, email, phone or address is ever requested or stored.
For each shipment: the order number, the fulfilment id, the tracking details as they stood, the dates the question was sent, sent once more, opened and answered, the answer, and any note the customer typed (500 characters at most). For the store: the access token Shopify issues, the store's name and domain, and the merchant's settings.
Nothing of its own. The question is the store's own Shipping update email, sent by Shopify; the confirm page is served on the store's domain or on this app's, and its link carries a random token, never personal data. If the customer says Not yet, or does not answer, Shopify sends the Shipping update once more, 3 days after the first one or after the Not yet, or as many days as the merchant sets: the app changes the shipment's tracking number to one ending in REMINDER, which is what makes Shopify send it, and the link is the same. It is never sent a third time, and the merchant can switch it off. When a customer answers Yes, the app marks the order delivered and Shopify sends the store's own Delivered notification, as it does for any delivery.
To each shipment it asks about: a tracking number of its own, starting CONFIRM-DELIVERY, with the customer's answer page as its link and Shopify's customer notification on, which is what makes Shopify send your store's Shipping update; when it asks once more, that number ending in REMINDER. And two fulfilment events: In transit when you fulfil a parcel that has no tracking, so the order's status page stops saying Confirmed; Delivered when the customer answers Yes or you mark the order delivered. Each write is read back from Shopify after it is made.
No data is sold, shared or sent to any third party. The app runs on Cloudflare Workers and stores its records in Cloudflare D1, in Western Europe, under Cloudflare's data processing terms.
Each shipment's record, with the customer's answer, note, the time they opened the question and the tracking details as they stood, is deleted 12 months after its last ask, answer or change. Everything for a store is deleted 30 days after the app is uninstalled, and at once on Shopify's shop redaction request. A customer's answers, note and the time they opened the question are cleared on Shopify's customer redaction request, and returned on a data request.
A customer's answer and note are used only to update that order and your Overdue list, and the answers are counted on your own app page, by shipping method and by courier. Nobody reads or analyses answers or notes across stores, and the app builds no dataset of its own from them.
Your own privacy notice should tell customers that you ask them by message to confirm delivery, and that a service provider processes order and fulfilment data to do it.
Questions about this policy: reply to the support address on the App Store listing.
Last updated 6 October 2026.