Privacy Policy
1. Controller and contact
This Privacy Policy explains how Workflow Suite ("the app") processes personal data. The app is operated by Code Creation Labs GmbH, Friedensstr. 1, 47647 Kerken, Germany (Yann Faulhaber; Amtsgericht Kleve, HRB 20472; VAT ID DE451671933).
For any data-protection question or to exercise your rights, contact us at [email protected].
2. Our role: processor for the merchant
The app is installed by a Shopify merchant (the "merchant") to automate tasks in their store with workflows. For any personal data contained in the store data and events the merchant's workflows handle, the merchant is the data controller and we act as a processor on the merchant's behalf under Article 28 GDPR. Our Data Processing Agreement is available on request at [email protected].
We are the controller only for the limited account and operational data we need to run the service and to communicate with the merchant (for example the merchant's contact email, shop domain and plan, alert recipients the merchant adds, and support correspondence).
3. What we process and why
Purpose of processing: running the workflows the merchant builds. A workflow starts on an event in the merchant's store (or on a schedule, a manual start or a call from another system), evaluates the merchant's conditions and runs the merchant's steps: changes to store data through the Shopify Admin API, requests to other systems, emails through the merchant's own mail sender, file transfers, and code the merchant writes. We store the workflows, a history of their runs, files the workflows keep, values they store between runs, and any secrets the merchant configures.
Categories of personal data: any personal data contained in the Shopify events and store data the merchant's workflows handle. Depending on the workflows this may include customer names, email addresses, phone numbers, postal addresses, order and checkout data and any custom fields the merchant includes. Emails a workflow sends go to the recipients the merchant defines; we keep a count of recipients and a one-way hash per recipient, not the addresses. If the merchant uses storefront behaviour triggers, the app receives storefront events (such as a viewed product or a started checkout) with a customer ID or an anonymous visitor ID; these events are only collected when the visitor has consented to analytics in the merchant's store, and we do not store the visitor's IP address with them.
Categories of data subjects: the merchant's customers and storefront visitors, and any other individuals whose data appears in the data the workflows handle; the merchant's own staff who use the app or receive its alerts.
Legal basis: performance of the contract with the merchant and our legitimate interest in providing and securing the service (Art. 6(1)(b) and (f) GDPR). For the personal data the merchant routes through the app, the merchant determines the legal basis towards its own customers.
4. Where your data is hosted
All processing takes place in the European Union on Google Cloud, region europe-west1 (Belgium). Databases, caches and file storage are region-local, with encryption at rest.
The data of workflow runs (the event that started a run and the results of its steps) and secrets (such as credentials and tokens) are additionally encrypted at field level using Google Cloud KMS, with separate keys, and are decrypted only in memory for the moment they are needed.
Our public website and the documentation for the app are delivered through Cloudflare, Inc. (DNS, TLS termination and edge caching), which processes the visitor's technical connection data. The app itself and all merchant data stay on Google Cloud in the europe-west1 region.
5. Sub-processors
We engage the following sub-processors to provide the service. Each is bound by a data processing agreement with obligations equivalent to ours:
- Google Cloud (Google Ireland Limited) - Compute, storage and Cloud KMS key management - European Union - Google Cloud region europe-west1 (Belgium) - DPA: https://cloud.google.com/terms/data-processing-addendum
- Shopify International Limited - The Shopify platform - the app receives events from the merchant's store and reads and changes store data through the Shopify Admin API; that data may contain personal data - Ireland (EU); Shopify operates globally, third-country transfers safeguarded under Chapter V GDPR (SCC / EU-U.S. DPF) - DPA: https://www.shopify.com/legal/dpa
- Amazon Web Services EMEA SARL (Amazon SES) - Delivery of the app's own alert and notification emails to the merchant and the recipients the merchant adds (for example "a workflow run failed"). Emails that a workflow sends are NOT delivered through this service; they go through the merchant's own mail sender - European Union - AWS region eu-central-1 (Frankfurt)
- seven communications GmbH & Co. KG (seven.io) - Delivery of alert text messages to phone numbers the merchant has added and verified, on paid plans, only when the merchant turns text message alerts on - Germany
6. Services the merchant connects
A workflow can send data to destinations the merchant chooses: the merchant's own mail server, web addresses of other systems, SFTP or FTP servers, chat tools such as Slack, Microsoft Teams or Discord, and, if the merchant adds their own key, an AI provider for generating code. These are the merchant's own services, used on the merchant's instruction and under the merchant's own agreements with them; they are not our sub-processors.
7. Data retention and deletion
We keep personal data only as long as needed to provide the service. The history of workflow runs is cleared automatically after the period of the merchant's plan (30, 60, 90 or 180 days). Files and stored values are kept until a workflow or the merchant deletes them. Operational logs are kept for a limited period only.
Uninstalling the app deletes the merchant's data; on termination we delete or return all personal data processed on the merchant's behalf within 30 days, unless Union or Member State law requires storage. We honour Shopify's mandatory data-protection webhooks (customers/data_request, customers/redact and shop/redact) within the timelines Shopify specifies.
Merchants can request deletion at any time by contacting [email protected].
8. International transfers
Our own infrastructure is in the EU. Where a sub-processor - in particular Shopify - processes personal data outside the EEA, the transfer is safeguarded under Chapter V GDPR, in particular the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
9. Your rights
Subject to the applicable conditions, you have the right of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with a supervisory authority. Our lead authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
Because we usually act as the merchant's processor, requests about a merchant's customer data are best directed to that merchant; we will assist the merchant in responding.
10. No tracking on this site
This website sets no third-party advertising or analytics cookies and embeds no third-party trackers.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to the service or the law. The current version and its date are shown at the top of this page; material changes to sub-processors are notified in accordance with our DPA.
12. Our other apps
We operate other Shopify apps, each with its own privacy policy:
- Workflow Webhooks: https://workflow-webhooks.app
- Workflow Trigger Extensions: https://workflow-trigger-extensions.app
- Workflow Transactional Email: https://workflow-transactional-email.app
- Workflow Functions: https://workflow-functions.app