Legal
Privacy policy
Last updated: 9 September 2026
Provider: eplatforms ltd ("we", "us"), a company registered in England and Wales under company number 3954521, whose registered office is the address recorded against that number at Companies House.
ICO registration: Z871919X
Contact: [email protected]
This policy explains what personal data the Order Exceptions app processes, why, and for how long. It covers two different groups: merchants who install the app, and the customers of those merchants.
1. What the app does
Order Exceptions detects refunds where money never actually reached the customer — where the refund transaction failed, stalled in a pending state, or was never created — and alerts the merchant so they can resolve it.
2. Customer personal data
2.1 What we do not process
We do not process any customer name, email address, postal address or phone number. These fields are not read from the Shopify API response, not stored, not displayed in the app, and never included in any alert we send.
Where a merchant needs to identify or contact a shopper, the app links them into their own Shopify admin, where that data already lives.
2.2 What we do process
We hold the following, which relates to an order and therefore indirectly to a customer, but does not identify them to us:
| Data | Example |
|---|---|
| Shopify order identifier and order number | gid://shopify/Order/450789469, #10428 |
| Shopify refund and transaction identifiers | gid://shopify/Refund/509562969 |
| Refund and order amounts, and currency | 182.00, GBP |
| Payment gateway name | shopify_payments |
| Transaction status, error code and gateway message | FAILURE, card_declined |
| Timestamps for the refund and the transaction | ISO 8601 |
Shopify treats data that can be linked back to a person — including an order total — as personal data, so we treat the above as personal data even though it contains no identifiers of our own.
Note on refund notes. Shopify refunds can carry a free-text note written by merchant staff, which could contain anything. We do not request that field from the API and do not store it.
2.3 Our role
For this data the merchant is the data controller and we are a data processor. We process it only on the merchant's documented instructions, as set out in our Data Processing Agreement.
2.4 Where it comes from
Two sources, both Shopify:
- Webhooks the merchant's store sends us (
refunds/create,order_transactions/create). - The Shopify Admin GraphQL API, which we poll to catch webhooks that were never delivered.
We request one access scope, read_orders. We do not request read_all_orders, read_customers, or any other scope.
3. Merchant personal data
Separately, we process a small amount of data about merchants and their staff. For this we are the data controller.
| Data | Purpose | Lawful basis |
|---|---|---|
| Store domain, store name, store currency | Identify the installation | Contract |
| Shopify API access token | Read order data on the store's behalf | Contract |
| Email addresses the merchant enters as alert recipients | Send the alerts they asked for | Contract |
| Webhook URL and signing secret the merchant enters | Deliver alerts to their systems | Contract |
| Shopify staff account details (name, email, user id) where Shopify provides them during authentication | Authenticate the session | Contract |
| Install, uninstall and billing status | Operate the service and bill correctly | Contract / legal obligation |
| Application logs containing store domain and error detail | Diagnose faults, keep the service secure | Legitimate interests |
We do not use merchant data for advertising, and we do not sell it.
4. Visitors to orderexceptions.com
The website itself is deliberately quiet.
- No cookies. The site sets none, so there is no consent banner because there is nothing to consent to.
- No analytics, no tracking, no advertising pixels, no third-party fonts or scripts. Every asset is served from our own domain. A Content Security Policy on the site permits nothing else.
- Server logs record the usual request lines, including IP address, for security and fault diagnosis. They are kept for 30 days.
If you send us a message through the contact form we process the name, email address, and any store URL and message you write, for the sole purpose of replying to you. Lawful basis: legitimate interests, in answering an enquiry you chose to send. It is emailed to us and kept in a file outside the web root, deleted after 12 months. We do not add you to any mailing list.
The form is rate-limited per connection. That check hashes the IP address rather than storing it, so it records that someone submitted, not who.
5. What we never do
- We do not sell personal data, and we never have.
- We do not use personal data for marketing, profiling, advertising or personalisation.
- We do not use personal data to train machine learning models.
- We do not share data with third parties other than the sub-processors in section 6.
6. How long we keep it
| Data | Retention |
|---|---|
| Refund and transaction records, once settled, and closed exceptions | 180 days, then deleted automatically |
| Records with an unresolved exception | Kept until resolved — the merchant is still owed action on them |
| Webhook replay-protection records | 30 days |
| All data for a store | Erased in full on Shopify's shop/redact webhook, sent 48 hours after uninstall |
| Application logs | 30 days |
| Contact form enquiries | 12 months |
| Billing records | As required by law, currently 6 years in the UK |
Retention is enforced automatically by a scheduled job, not manually.
Backups. Deleted records persist in encrypted database backups until those backups age out, currently 7 days. Backups are encrypted at rest and access-controlled, are never used to repopulate deleted data, and are only restored in a disaster-recovery event - after which any deletion that had already been applied is re-applied.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Application and database hosting | United Kingdom |
| eplatforms ltd's own mail server | Sending alert emails | United Kingdom |
| Shopify Inc. | Source of the data; hosts the merchant's store | Global |
Alert emails contain the order number, amount, gateway and failure reason. They contain no customer personal data.
Where a merchant configures an outbound webhook, we send alerts to a URL of their choosing. That destination is under the merchant's control, not ours, and they are responsible for it.
We will give merchants notice before adding or replacing a sub-processor, as set out in the DPA.
8. International transfers
Data is hosted in the United Kingdom. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with any additional safeguards required.
9. Security
- All data in transit is encrypted with TLS — to Shopify, to our email provider, and to merchant-configured webhook endpoints.
- Data at rest is encrypted by our database provider.
- Inbound Shopify webhooks are verified by HMAC-SHA256 signature; unsigned or incorrectly signed requests are rejected.
- Outbound alert webhooks are signed with HMAC-SHA256 so merchants can verify they came from us.
- Access to production systems is restricted to named personnel and protected by multi-factor authentication.
- Where a merchant configures an outbound webhook, the destination is resolved and refused if it points at a private or internal network address, so the feature cannot be used to reach systems that are not the merchant's own.
- We request the narrowest access scope that makes the product work, and we hold no customer contact details, so a compromise of our systems would not expose shoppers' identities.
10. Rights of merchants' customers
Because the merchant is the controller of customer data, a shopper exercising their rights should contact the merchant, not us. We support merchants in responding, and we honour Shopify's mandatory compliance webhooks:
customers/data_request— we hold no personal data identifying a shopper, so there is nothing to return.customers/redact— we hold no personal data identifying a shopper, so there is nothing to erase.shop/redact— we erase all data held for that store.
11. Rights of merchants
If you are a merchant, you have the right to access, correct, erase, restrict, port or object to our processing of your own personal data, and to complain to the UK Information Commissioner's Office (ico.org.uk), with whom we are registered under number Z871919X, or your local supervisory authority. Contact [email protected].
12. Breach notification
If we become aware of a personal data breach affecting a merchant's data, we will notify the affected merchant without undue delay and in any event within 48 hours of becoming aware, with the detail required for them to meet their own notification obligations.
13. Changes
We will post material changes here and notify merchants by email at least 30 days before they take effect.