← Back to Home

Privacy Policy

Last updated: December 1, 2025

Duplicate Guard ("we", "us", or "our") provides a duplicate order detection service for Shopify merchants. This Privacy Policy describes how we collect, use, and handle your personal information and your customers' data when you use our app. We are committed to protecting the privacy and security of your data in compliance with GDPR, CCPA, and Shopify's Protected Customer Data requirements.

1. Information We Collect

We process only the minimum personal data required to provide duplicate order detection services. When you install Duplicate Guard, we collect:

Legal Basis: We process this data based on our legitimate interest in providing fraud prevention services and in compliance with the Shopify Partner API License and Terms of Use.

2. How We Use Your Information

We use customer personal data solely for duplicate order detection. Specifically:

Purpose Limitation: We do NOT use customer data for:

Automated Decision-Making: Our duplicate detection algorithms only flag orders for merchant review and do not have legal or significant effects on customers. Merchants make all final decisions about handling duplicates.

3. Data Retention

We apply specific retention periods to ensure personal data is not kept longer than necessary:

4. Data Sharing and Third Parties

No Data Sale: We do not sell, rent, or share your personal data or your customers' data with third parties for marketing purposes.

Service Providers: We may share data with trusted third-party service providers (e.g., hosting providers, database providers) solely for the purpose of operating our app. These providers are bound by data processing agreements and confidentiality obligations.

Customer Opt-Out: Customers can opt out of data processing by requesting merchants to uninstall our app, which triggers automatic data deletion.

5. Security Measures

5.1 Encryption

5.2 Access Controls

5.3 Environment Separation

5.4 Data Loss Prevention

5.5 Staff Access Requirements

5.6 Access Logging

5.7 Security Incident Response Policy

We have a documented Security Incident Response Policy that includes:

6. Customer Rights and GDPR Compliance

6.1 Customer Rights

Under GDPR and other privacy regulations, customers have the following rights:

6.2 GDPR Webhook Implementation

We have implemented the following GDPR compliance webhooks:

6.3 How to Exercise Rights

Customers can exercise their rights by:

7. Consent and Opt-Out

8. Data Protection Agreements

Our data protection framework includes:

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

10. Contact Us

If you have any questions about this Privacy Policy, data protection, or wish to exercise your privacy rights, please contact us at:

Email: [email protected]

For privacy-specific inquiries, please include "Privacy Request" in your subject line.