CtrlOne · Shopify application
Privacy Policy
This policy explains the limited data Ctrl COD processes to provide Cash on Delivery controls for Shopify merchants.
Last updated: August 25, 2026
Who we are
Ctrl COD is a Shopify application operated by CtrlOne. In this policy, “merchant” means the Shopify store using Ctrl COD and “buyer” means a customer of that merchant.
Data we process
- Shop identity, app installation sessions, configuration, plan and usage information.
- Order and payment-status information needed to recognize COD orders, apply configured fees or tags, show the operations dashboard and send enabled confirmations.
- Buyer phone numbers transiently for OTP or order-confirmation delivery. OTP phone numbers are stored as shop-scoped HMAC fingerprints; notification logs retain only masked phone values.
- Operational and security records such as delivery status, automation outcome and webhook identifiers.
Quick-order contact and address fields go from the buyer’s browser to Shopify Checkout and are not sent to Ctrl COD servers. We do not sell personal data or use it for third-party advertising.
Why we process data
We process data to provide app functionality requested by the merchant, secure COD checkout with OTP, perform configured order automation, provide support, prevent abuse and meet legal obligations. Where applicable, the merchant is the controller and CtrlOne acts as its processor.
Service providers and transfers
Data may be processed by Shopify, our hosting and database providers, and—only when enabled by the merchant—WhatsApp/Meta or SMS delivery providers. These providers process data to deliver their contracted service. Processing may occur outside the buyer’s country, subject to applicable contractual safeguards.
Retention
- OTP challenges expire after five minutes and are removed after successful verification, maximum attempts or cleanup.
- Notification delivery logs are retained for up to 90 days.
- Order automation logs are retained for up to 180 days.
- Store settings and associated app records are deleted after Shopify sends the required shop-redaction request following uninstall.
Security
Ctrl COD uses Shopify authentication and signed webhooks, minimizes stored buyer data, hashes OTP identifiers and codes, limits OTP attempts and expiry, and provides authenticated deletion and retention controls. No internet service can promise absolute security.
Your choices and rights
Buyers should first contact the merchant from whom they purchased. Merchants and authorized data subjects may request access, correction or deletion by emailing support@byctrlone.com. We verify and respond to requests as required by applicable law and Shopify’s privacy workflows.
Changes and contact
We may update this policy when our service or legal requirements change. Material updates will be reflected by the date above. Contact support@byctrlone.com for privacy questions.