Legal
Last updated: 2 September 2026
Last updated: 2026-09-02
Tacey is an order-editing and address-validation app for Shopify. In plain terms: we check the shipping address on every order a merchant receives, let the merchant’s customer fix that address themselves (or make a small edit to their order) on Shopify’s own order-status page, and keep a record of what changed and whether any money moved.
Doing that job well means we handle personal data, shipping addresses, order details, and email addresses, that belongs to real people who never signed up for Tacey directly. This page explains, in one place, what we do with that data, why, for how long, who else sees it, and what rights the people it concerns can exercise.
This page covers:
tacey.app, requests a demo, or subscribes to updates from us.It does not restate our Privacy Policy or Terms of Service in full; where this page and those documents overlap, this page is the more detailed technical and legal account, written for merchants, their customers, and anyone conducting a data-protection or security review.
Tacey is built and operated by ONDUTYOPS LLC, a Delaware limited liability company with a registered address at Coastal Highway, Lewes, Delaware 19958, United States, the developer of record for the Tacey app on the Shopify App Store.
Tacey is built and operated by ONDUTYOPS LLC, the developer of record for the Tacey app on the Shopify App Store, with a registered address at Coastal Highway, Lewes, Delaware 19958, United States.
For any question about this page, a data-subject request, or a security review, contact:
We do not yet have a dedicated Data Protection Officer.
Under GDPR, the same company can be a controller in one relationship and a processor in another, and Tacey is exactly that split:
We are a PROCESSOR when it comes to shopper data. When a merchant installs Tacey, they decide to check their orders’ addresses and let their customers edit them. We act on the merchant’s instructions: we validate the address they send us, we let their customer make the edit they authorised, and we do not decide, on our own initiative, what to do with a shopper’s data beyond running the service the merchant configured. The merchant is the controller of their own shoppers’ personal data, the same relationship that exists between a merchant and Shopify itself.
We are a CONTROLLER for the data we collect about the merchant’s own business, our website visitors, and anyone who contacts us directly. When a merchant installs Tacey, we collect account information about that merchant (Section 6) to run their billing, support them, and communicate with them about the service, decisions about that data are ours to make, subject to this page and our Privacy Policy.
We are a CONTROLLER for our own website and marketing activity, tacey.app visitors, demo requests, and anyone who subscribes to updates from us directly (not through a merchant’s store).
Shopify is a separate, independent controller and processor relationship, and Shopify’s own compliance does not transfer to us. A merchant who has satisfied themselves that Shopify is GDPR-compliant has not thereby satisfied themselves that any app installed on their store, including Tacey, is. Each app a merchant installs is its own processor relationship, with its own data flows, its own subprocessors, and its own obligations. This page exists precisely because that distinction matters.
Where we act as a processor for a merchant’s shopper data, Article 28 GDPR requires us to:
These obligations are ordinarily formalised in a signed Data Processing Agreement between Tacey and each merchant. Section 21 states where that document stands today.
The lawful basis differs depending on whose data it is and in what capacity we are processing it.
Shopper data (we are the processor): the merchant, as controller, establishes their own lawful basis for processing their customers’ data (typically performance of a contract, fulfilling the sale, or legitimate interests in operating their store efficiently and preventing misdelivered orders). Our processing is lawful because it is carried out under the merchant’s instructions and documented processor agreement, per Article 28(3).
Merchant account data (we are the controller): we process this under performance of a contract, we cannot provide the Tacey service, bill for it, or support a merchant without their account and business details.
Website and marketing data (we are the controller): where someone requests a demo or subscribes to updates, our basis is consent for marketing communications, and legitimate interests for operating the site itself (security logging, abuse prevention) and responding to direct enquiries.
Emails sent to a shopper about their own order (we are the processor): these are transactional, not marketing, a confirmation that an order was edited, or a reminder that an edit window is closing. The lawful basis for sending them sits with the merchant’s own basis for the underlying order relationship; we send them because the merchant instructed us to, as their processor.
We deliberately hold less than most apps in this category, because our job is narrower than most apps in this category.
| CATEGORY | WHAT IT IS | WHERE IT COMES FROM | ROLE WE PLAY |
|---|---|---|---|
| Shipping addresses | Street, city, state/region, postal code, country of an order’s shipping address | The Shopify orders/create webhook | Processor |
| Order metadata | Order number, line items, quantities, totals, currency, fulfillment status | The Shopify orders/create webhook and Admin API reads | Processor |
| Customer email address | The shopper’s email, used to send them a link to check or edit their order | The Shopify order payload | Processor |
| Raw order webhook payloads | The complete, unmodified JSON Shopify sends for orders/create, archived for reprocessing | Shopify webhook delivery, archived to Cloudflare R2 | Processor |
| Merchant account data | Owner name, business contact email, store name, shop domain, country, city, business phone, currency, timezone, locale, Shopify plan | The Shopify OAuth install flow (shop address, shop settings) | Controller |
| Usage and analytics events | App installs, feature usage, error diagnostics, keyed to the shop, never to a shopper | Our own application code | Controller |
| Website and marketing data | Name, email, company, and anything submitted through a contact or demo-request form | Directly from the visitor | Controller |
We never see or store payment card data. Shopify handles payment entirely, end to end, card numbers, CVVs, and payment tokens never reach any Tacey system. This is a genuine and significant reduction in scope compared to a typical checkout or payments app, and it takes an entire category of regulatory obligation (PCI DSS) off the table for us.
Addresses sent to our validation vendors carry no name or email. When we call Google’s Address Validation API or Geocodio to check a shipping address, we send only the address fields, street, city, state, postal code, country, never the customer’s name or email address alongside it. Those vendors validate a string of address text; they do not receive a profile of the person who typed it.
We do not process any special category data (Article 9: data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data about a person’s sex life or sexual orientation), and we do not process criminal offence or conviction data (Article 10).
Nothing in Tacey’s design asks for, infers, or stores any of these categories. A shipping address and an order line item are the entirety of what the product needs, and that is the entirety of what it collects.
If GDPR (or an equivalent regime, per Section 20) applies to you, you have the following rights over your personal data:
If you are a shopper whose order was processed by a merchant using Tacey, the merchant is your primary point of contact for exercising these rights, because they are the controller of your data. We support them in fulfilling your request, see Section 9 and Section 14 for exactly how.
If you are a merchant, or a website visitor, you can exercise these rights against us directly, as the controller of your account or website data.
Shoppers: contact the merchant whose store you ordered from, they are the controller of your data and the right party to handle your request. If a merchant asks us for help fulfilling a shopper’s request, we respond promptly; in practice, the three Shopify-mandated privacy webhooks (Section 14) already automate most of this without either of us filing a manual request.
Merchants and website visitors: submit a request at tacey.app/privacy-request, or email hello@taceysupport.app. We confirm the email address a request came from before acting on it. We aim to acknowledge every request within a reasonable time and to respond substantively within one month, as GDPR Article 12(3) requires, extendable by a further two months for complex or numerous requests, with notice to you if that extension is needed.
Tacey does not carry out automated decision-making that produces legal effects or similarly significantly affects a person, within the meaning of Article 22.
Address validation produces a verdict about an address, not about a person, “verified”, “corrected”, or “could not be checked”. It never blocks a purchase, never denies service, and never decides anything about the shopper themselves. If a validation vendor is slow or unavailable, the order proceeds exactly as if no check had been run at all, the absence of a working validator produces no adverse outcome for anyone.
Any actual change to an order, an address correction, a line-item swap, a cancellation, is made by a human: the shopper themselves, confirming a change on Shopify’s order-status page, or the merchant, acting in their admin. Tacey never edits an order on its own initiative. No money moves without an explicit human confirmation, on either side.
If this changes in a future version of the product, this section will be updated before that change ships, not after.
Where we rely on consent, principally, marketing communications to merchants or website visitors who opted in, you can withdraw it at any time:
Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal, and it does not affect transactional messages (order-edit confirmations, security notices) that are not based on consent in the first place (Section 5).
We do not rely on consent as the lawful basis for shopper-facing order-edit emails; those are sent under the merchant’s instruction as part of fulfilling the order relationship (Section 5).
Tacey’s infrastructure and every subprocessor we use today is operated by a company headquartered in the United States. If you are located in the EU, the UK, or another jurisdiction with its own transfer restrictions, your personal data will typically be transferred to and processed in the United States (and, for our infrastructure provider Cloudflare, potentially at edge locations in other countries as part of its global network).
Where such a transfer requires a safeguard under GDPR (Chapter V) or UK GDPR, we rely on the EU Standard Contractual Clauses (SCCs) (and, for the UK, the UK International Data Transfer Addendum), incorporated into our agreements with each subprocessor, or on the subprocessor’s own certified mechanism (e.g. participation in an approved framework) where applicable.
We do not currently transfer any personal data outside of our subprocessors’ own infrastructure, we do not operate our own servers in any other country, and Cloudflare’s product set (Workers, D1, R2, KV, Queues) is what our application runs on.
A subprocessor is a third party we engage to help deliver the Tacey service. The full, current list, what each one does, what data it receives, and where it is located, is published on our dedicated Subprocessors page, rather than gated behind an access request. We believe merchants and their customers are entitled to see this without having to ask.
We engage each subprocessor under a written agreement that requires them to protect personal data to a standard consistent with our own obligations under Article 28.
Your right to object: if we intend to add a new subprocessor, or replace an existing one, we will update the Subprocessors page and notify merchants in advance (the notice period and mechanism are detailed there). If a merchant reasonably objects to a new subprocessor on data-protection grounds, we will work with them in good faith to address the objection, which may include not proceeding with that subprocessor for their account, or, if the concern cannot be resolved, allowing the merchant to terminate the affected service without penalty.
Every public Shopify app must implement three mandatory privacy webhooks. Tacey implements all three:
customers/data_request, triggered when a shopper asks a merchant what data is held about them. We do not contact the shopper directly (Shopify API Terms Section 6.2 prohibits an app from contacting a merchant’s customers by default, and we honour that), instead, we count and log what we hold for that customer so the merchant can fulfil the request themselves.customers/redact, triggered when a shopper’s data should be erased (typically at the merchant’s request, or automatically for customers who have had no order activity for a defined period). This deletes the customer’s rows from our address-validation and address-cache tables.shop/redact, triggered by Shopify approximately 48 hours after a merchant uninstalls Tacey. This deletes every row scoped to that shop across our database, and sweeps the merchant’s archived raw order payloads out of our object storage.What “deletes” means concretely, and the one gap we are naming rather than hiding: our deletion process removes the merchant’s database rows across every shop-scoped table, and separately sweeps the archived webhook payloads from object storage. That storage sweep returns one of three outcomes: it deletes a specific number of objects, it correctly reports zero objects existed, or, if the storage connection itself is unavailable at the moment of erasure, which is a configuration failure rather than a normal outcome, it cannot attempt the sweep at all, and that failure is distinguished from “nothing to delete” and logged loudly rather than reported as success.
We are stating this plainly because a deletion commitment that glosses over its own failure mode is worse than no commitment. In the rare case where that storage connection is unavailable, the database rows are still deleted in full, only the archived raw payloads could be affected, and the failure is never silently reported as a successful erasure. Closing this gap entirely (so a sweep can never simply fail to run) is tracked as an engineering priority ahead of a merchant relying on this page in a compliance audit.
shop/redact (Section 14).shop/redact fires roughly 48 hours after uninstall and triggers erasure as described above.We hold no third-party security certification today (no SOC 2, no ISO 27001), see the Trust Centre for the honest account of what that does and does not mean, and we do not represent otherwise on this page.
If we become aware of a personal data breach affecting shopper or merchant data, we will:
We maintain records of our processing activities as required by Article 30, including the categories of processing we carry out, the categories of data subjects and personal data involved, and our subprocessors.
On request, and subject to appropriate confidentiality protections, we can provide:
Email hello@taceysupport.app to request any of the above, or to arrange a security review call.
As a US-based company processing personal data of EU and UK data subjects, Article 27 GDPR and Article 27 UK GDPR may require us to appoint a representative in the EU and/or UK, unless a derogation applies (e.g. processing is occasional, low-risk, and does not involve special category data at scale). We have not yet appointed an EU or UK representative. This is an open item for legal review, not an oversight to be read past.
Regardless of whether we have a representative, if you believe our processing of your personal data infringes GDPR, you have the right to lodge a complaint with the supervisory authority in your own country of residence, place of work, or the place of the alleged infringement. You do not need to contact us first.
GDPR is the framework this page is written against because it is the most comprehensive and the one most of our merchants’ compliance teams ask about, but we apply the same standard of care regardless of where a shopper or merchant is located. Depending on where you are, additional rights may apply under your local law, for example, the California Consumer Privacy Act (CCPA/CPRA) for California residents, or Canada’s PIPEDA.
Our Data Processing Agreement is published and forms part of, and is incorporated by reference into, the Tacey Terms of Service. It incorporates by reference:
A merchant who needs a signable copy addressed specifically to their organisation can email hello@taceysupport.app to request one.
We will update this page as our processing activities, subprocessors, or legal obligations change, and we will update the “Last updated” date at the top whenever we do. Material changes, a new category of data, a new subprocessor, or a change to how long we retain something, will also be communicated to merchants directly, not only through a silent page edit (see also Section 13’s subprocessor-change notice).
Questions about this page, a data-subject request, or a security review:
If you are a shopper with a question about an order, please contact the store you ordered from, they are best placed to help you, and are the controller of your order data (Section 3).