Cozy Shipping Rules and Rates — Privacy Policy
Last updated: 2026-07-08
Cozy Shipping Rules and Rates is a Shopify carrier-calculated shipping-rates app operated by Cozy Farm LLC (“we”, “us”, “our”). This policy explains what data the app processes when a merchant installs it, why we process it, how long we keep it, and how to reach us. If you need us to correct or delete anything, write to info@mycozyfarm.com.
1. Data we collect from merchants
When a merchant installs Cozy Shipping Rules and Rates on their Shopify store, we store the following configuration and operational data — tied to the merchant’s shop, not to any individual person:
- The store’s
.myshopify.comdomain. - The Shopify offline access token issued at install, encrypted at rest with AES-256-GCM and used only to call the Shopify Admin API on the merchant’s behalf.
- The API scopes the merchant granted.
- Shipping configuration created by the merchant: rules, zones, ship-from address (country, state, city, postal code), and the on/off toggle.
- Plan tier, trial dates, and subscription status.
- Monthly order counts — a single integer per shop, per calendar month, used to enforce plan limits (see Section 2).
- Postal-code coordinates (latitude/longitude of postal codes we have seen) cached to compute distance-based zones. This data is public reference data keyed only by country + postal code and is not tied to any individual.
- Support tickets a merchant submits through the in-app form: the merchant’s shop, contact email they provide, and the message text.
2. Data we do not collect
We deliberately minimize the personal data we touch. Specifically, Cozy Shipping Rules and Rates does not collect, store, or share:
- Customer or shopper names, email addresses, or phone numbers.
- Full shipping or billing addresses of individual customers.
- Order line items, product details, or order contents.
- Payment information of any kind.
- Any other personally identifiable information about shoppers.
Shopify sends us an orders/create webhook so we can enforce subscription plan order limits. We HMAC-verify the webhook, increment a per-shop integer counter, and discard the entire payload. Order contents and customer data are never persisted.
At checkout, Shopify calls our carrier rate endpoint with the destination country, state, and postal code so we can match shipping zones. We use those three fields to compute the shipping rate and do not store them tied to any order or shopper.
3. How we use the data
- To return shipping rates during checkout on the merchant’s store.
- To render the app’s admin UI (rules, zones, rate tester, settings).
- To bill the merchant via Shopify’s billing system and enforce plan limits.
- To respond to support requests the merchant submits.
- To fulfill our GDPR obligations (customer data request, customer redact, shop redact webhooks).
We do not use merchant data for advertising, profiling, automated decision-making with legal effect, or resale.
4. Subprocessors
We use the following service providers to operate the app. Each is bound by their own data-processing terms and has been selected for their security posture.
- Vercel Inc. (United States) — application hosting and serverless compute.
- Neon Inc. (United States) — managed PostgreSQL database; storage encrypted at rest by the provider.
- Resend Inc. (United States) — transactional email delivery for merchant support-ticket confirmations.
- OpenStreetMap Foundation (Nominatim, United Kingdom) — postal-code geocoding. We send only a country code and postal code, never personal data.
- Shopify Inc. (Canada / United States) — the platform on which the app runs; Shopify processes all merchant billing and webhook delivery.
5. Retention
- Merchant configuration is retained while the app is installed.
- On uninstall, we immediately drop the merchant’s Shopify access token and mark the shop inactive.
- On receipt of Shopify’s
shop/redactGDPR webhook (fired ~48 hours after uninstall), we hard-delete all remaining data associated with the merchant’s shop, including rules, zones, and usage counters. - Order counters reset at the start of each calendar month; historical counts are not retained beyond operational need.
- Support tickets are retained for reference to help us serve future requests from the same shop, and are deleted on request.
6. Security
- All traffic is served over HTTPS/TLS.
- Shopify access tokens are encrypted at rest using AES-256-GCM before being written to the database.
- Every webhook we receive from Shopify is HMAC-verified using the app’s secret before any processing occurs.
- Multi-tenant data isolation is enforced at the database query layer: every query on shop-scoped tables filters by shop identifier.
- Cozy Shipping Rules and Rates does not sell data. We do not share merchant data with third parties for marketing purposes.
7. Your rights
Depending on your location, you may have rights under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), or similar laws — including the right to access, correct, or delete the data we hold, and the right to lodge a complaint with a data protection authority.
For most requests, uninstalling the app from your Shopify store is enough: Shopify will send us a shop/redact request within ~48 hours and we will delete your shop’s data. To make a request sooner or to ask a question about your data, email info@mycozyfarm.com with the shop domain.
8. International transfers
Our subprocessors are primarily located in the United States. When data about a merchant located in the European Economic Area, the United Kingdom, or Switzerland is transferred to the United States, we rely on the Standard Contractual Clauses (or an equivalent lawful transfer mechanism) put in place by those subprocessors.
9. Changes to this policy
We may update this Privacy Policy from time to time — for example, to reflect new features, a new subprocessor, or a change in the law. The “Last updated” date at the top of the page indicates the current version. Material changes will be communicated in-app or by email to the address on file for the merchant.
10. Contact
Cozy Farm LLCinfo@mycozyfarm.com