Legal
Last updated: 5 September 2026
Last updated: 2026-09-05
Tacey (“Tacey”, “we”, “us”, “our”) is operated by ONDUTYOPS LLC, with a registered address at Coastal Highway, Lewes, Delaware 19958, United States.
Tacey is a software application distributed through the Shopify App Store that provides order-address validation, self-service order editing for shoppers, and post-purchase upsell tools for merchants running stores on the Shopify platform (the “Service”).
This Privacy Policy explains what personal data Tacey collects, why, how long we keep it, who we share it with, and the rights available to the people the data is about. It applies to:
Questions about this policy, or about how your data is handled, go to Section 23.
Tacey handles two categorically different kinds of personal data, under two different legal roles. This distinction governs everything else in this policy.
When a merchant installs Tacey, creates an account, contacts support, or receives marketing communications from us, we act as the data controller for that merchant’s own personal data, their account information, their billing relationship (which runs through Shopify, see Section 5), their support correspondence, and their communication preferences. We decide why and how that data is processed, within the limits of this policy.
When Tacey validates a shipping address, lets a shopper edit their own order, or emails a shopper about a flagged address, we act as a data processor (or “service provider” under US state privacy law) on behalf of the merchant, who is the data controller for their own customers. We process shopper data only:
We do not use shopper data for our own purposes. We do not use it for our own marketing, we do not build cross-merchant profiles from it, and we do not sell it. A merchant’s own privacy policy that references apps installed on their store should direct their shoppers to the explanation in this section and in Section 4 and Section 15.
When you (a merchant, or someone acting on a merchant’s behalf) install and use Tacey, we collect:
Account and store information, received from Shopify when you install the app and on every subsequent authentication: your shop’s domain, the Shopify shop ID, your shop’s name, the store owner’s name and email address (where Shopify provides it), your store’s country, city and business phone number, your store’s currency and time zone, your store’s detected locale, and your Shopify plan tier.
Language and settings choices you make inside Tacey, your chosen admin language (distinct from the language Shopify detects for your store), your validation region settings, your edit-window configuration, and which optional tools you have switched on.
Billing information, limited to your selected Tacey plan and your order usage against that plan’s cap. Tacey does not collect or store payment card details at any point, see Section 5.
Support and communication data, anything you send us when you contact support, plus your marketing communication preferences if you have opted in to receive product updates.
Usage data, collected through our product analytics tools, which pages of the app you visit, which features you use, and coarse technical information such as browser type and approximate location derived from IP address.
To perform the Service, Tacey processes personal data belonging to the merchant’s own shoppers. This data is provided to us by Shopify, at the merchant’s instruction, because the merchant has installed Tacey and granted it access to their store’s order data. We hold it as a processor, strictly to perform the following functions:
Order and shipping information, the shipping address on an order (name, street address, city, state/province, postal code, country, phone number where provided), the order number and line items, and order status, received via Shopify webhooks and the Shopify Admin API, to run address validation and to let the shopper view and edit their own order.
Shopper contact information, the shopper’s email address, used solely to send the shopper transactional communications about their own order: a notice that their address may need attention, a link to review or edit their order, and a reminder before the edit window closes. We do not use shopper email addresses for our own marketing, and we do not add shoppers to any mailing list of ours.
Validation results, the outcome of checking a shipping address against our address-validation providers: whether it was found deliverable, a confidence classification, and any corrected or standardized version of the address suggested to the shopper.
Edit history, a record of any change made to an order through Tacey: what was changed, when, by whom (the shopper or the merchant), and, where the change involved money, what happened to the money, this is the reconciliation ledger described in Section 8.
We hold no other shopper category of data. We do not process shoppers’ browsing history on the merchant’s storefront, their purchase history beyond the order being validated or edited, or any data not described above.
Tacey never collects, transmits, processes, or stores payment card numbers, bank details, or any other payment credential, for merchants or for shoppers. Payment for a merchant’s Tacey subscription runs entirely through Shopify’s own billing system (Shopify’s AppSubscription API); we receive only the plan the merchant selected and confirmation of billing events from Shopify, never a card number. Payment for a shopper’s original order runs entirely through Shopify’s own checkout and whatever payment processor the merchant has configured; Tacey never touches that flow. Where a shopper’s order edit results in an additional charge or a refund, the money movement itself is performed by Shopify’s own payment rails, Tacey initiates the request through Shopify’s APIs but never handles or stores the underlying payment instrument.
This is a significant, deliberate reduction in the scope of what we hold: Tacey is fully out of scope for PCI-DSS because it never comes into contact with cardholder data in any form.
Our marketing website uses cookies and similar technologies for the purposes described below.
| CATEGORY | PURPOSE | DURATION |
|---|---|---|
| Strictly necessary | Session management, cookie-consent preference | Session to 12 months |
| Analytics | Understanding how visitors use our website, set by our product-analytics subprocessors (Google Analytics, Mixpanel) | Up to 24 months |
| Session replay | A recording of how a visit unfolds, mouse movement, scrolling, clicks, and typed input in some fields, set by our session-replay subprocessor (Microsoft Clarity). A separate choice from Analytics, off everywhere including the United States until you turn it on | Up to 12 months |
We do not use third-party advertising cookies, and we do not run retargeting pixels.
The merchant-facing part of Tacey runs embedded inside Shopify’s own admin, inside an iframe, under Shopify’s session model. It uses a session cookie required for the app to function inside that embedded context (compliant with Shopify’s App Bridge and embedded-app requirements) and sends product-analytics events to help us understand how the app is used and to improve it.
You can control or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of our website or the embedded app from working correctly.
When you make a cookie choice on this website, in the banner, the preferences modal, an opt-out, or through a Global Privacy Control signal, we keep a server-side record of that decision. This exists so that if someone disputes what they were shown or what they agreed to, we can produce the actual record rather than relying on memory.
Each record holds: which categories you allowed, the region and country we detected, whether your browser sent a Global Privacy Control signal, how the choice was made, the version of the cookie banner you were shown, a coarse device, operating system and browser description parsed from your browser’s user-agent string, which trackers were actually enabled as a result of your choice, the page you were on, the page that referred you, your browser’s language setting, your device’s time zone where your browser provides it, and your IP address.
We keep the IP address specifically so we can show, if ever asked, that a given decision came from a given visitor at a given time. We do not use it to build a profile of you, to identify you for any other purpose, or to combine it with the shopper or merchant data described elsewhere in this policy. See Section 12 for how long we keep these records.
Where the UK GDPR or EU GDPR applies, we rely on the following lawful bases:
| PROCESSING ACTIVITY | LAWFUL BASIS |
|---|---|
| Operating a merchant’s account, providing the Service they installed | Performance of a contract |
| Validating shopper shipping addresses, enabling shopper self-edit | Performance of a contract, on the merchant’s instructions, as their processor |
| Emailing a shopper about their own order | Performance of a contract, on the merchant’s behalf |
| Product analytics on merchant usage | Legitimate interest in improving and securing the Service |
| Marketing communications to merchants who opted in | Consent |
| Responding to support requests | Performance of a contract |
| Complying with legal obligations (tax, data-subject requests) | Legal obligation |
For shopper data specifically, because we act as a processor, the underlying lawful basis for processing a shopper’s personal data is the merchant’s own basis for running their store and fulfilling that shopper’s order.
We use the data described in Sections 3 and 4 to:
We do not sell personal data. We do not use shopper data to build advertising profiles, and we do not share shopper data with any party outside the subprocessors listed in Section 10 and the merchant themselves.
We share personal data only in the following circumstances:
We do not share personal data with any party for that party’s own marketing purposes.
The following subprocessors have access to the categories of personal data listed, strictly to perform the function described. This table is public and we update it as our subprocessor list changes; a merchant performing a security review can request our full subprocessor detail using the contact in Section 23.
| SUBPROCESSOR | FUNCTION | DATA RECEIVED |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, object storage, message queues, session storage | All application data that passes through or is stored by the Service |
| Google LLC | Address validation and geocoding (Mexico and international addresses) | The shipping address being validated |
| Geocodio LLC | Address validation (United States and Canada) | The shipping address being validated |
| Postmark (a division of ActiveCampaign, LLC) | Sending transactional emails to shoppers and merchants | Recipient email address, order reference, and email content |
| Mixpanel, Inc. | Product analytics | Usage events, not shipping addresses or payment data |
| Intercom, Inc. | Merchant lifecycle tracking (install and account events) | Shop domain, Shopify plan tier, store country |
| Customer.io (Peaberry Software, Inc.) | Merchant lifecycle messaging | Merchant contact email, owner name, store name, shop domain, Shopify plan tier, currency, country, time zone, locale |
Cloudflare, Google, Geocodio, Postmark, and Mixpanel process data as part of running the core Service for every merchant. Intercom and Customer.io process merchant account data specifically to track and message merchants about their own account lifecycle (installs, plan changes) and never receive shopper order or address data.
Our subprocessors are located in, or transfer data to, the United States. Where personal data originating in the UK, EEA, Switzerland, or another jurisdiction with data-transfer restrictions is transferred to the United States or another third country, we and our subprocessors rely on the following safeguards:
| SUBPROCESSOR | TRANSFER MECHANISM |
|---|---|
| Cloudflare | EU Standard Contractual Clauses, incorporated into Cloudflare’s own customer-facing SCC addendum |
| Google’s own EU Standard Contractual Clauses and Data Processing Addendum for Google Cloud/Maps Platform services | |
| Geocodio | EU Standard Contractual Clauses under Geocodio’s Data Processing Agreement |
| Postmark | EU Standard Contractual Clauses under Postmark’s Data Processing Addendum |
| Mixpanel | Certified under the EU–US Data Privacy Framework, and EU Standard Contractual Clauses under its DPA; offers EU-region data residency |
| Intercom | EU Standard Contractual Clauses and the UK International Data Transfer Addendum under its Data Processing Agreement |
| Customer.io | Self-certified under the EU–US Data Privacy Framework, and EU Standard Contractual Clauses under its DPA; offers an EU-region configuration |
We enter into a Data Processing Agreement, incorporating these transfer safeguards, with any merchant who requests one, see Section 23.
We retain personal data only for as long as necessary for the purposes described in this policy:
| DATA CATEGORY | RETENTION PERIOD |
|---|---|
| Merchant account and shop record | For the life of the installation, deleted upon the mandatory shop/redact webhook (48 hours after uninstall) |
| Shop settings, billing and plan-usage records | Same as merchant account, deleted with the shop record |
| Order and shipping-address validation records | Deleted with the shop record; individually erasable earlier on a valid customers/redact request |
| Raw order webhook payloads | Deleted with the shop record, see the important note below |
| Reconciliation ledger entries | Retained for the life of the shop’s installation, as the audit record of edits made |
| Support correspondence | Up to 3 years after your last contact with us |
| Marketing contact preferences | Until you unsubscribe or opt out |
| Product analytics events | Up to 12 months |
| Cookie-consent records, including IP address (Section 6.4) | Up to 3 years from the date of the decision |
When a merchant uninstalls Tacey, Shopify sends a mandatory shop/redact webhook (48 hours after uninstall) instructing us to erase that merchant’s data. On receiving it, we delete the merchant’s database records and sweep raw order payloads from our object storage.
In the overwhelming majority of cases this erasure completes in the same operation. Our system is built to report this honestly: if the component responsible for sweeping object storage cannot be reached at the moment of erasure, our system records that the sweep could not be confirmed rather than reporting it as successful, and the event is logged for investigation and remediation. We never report an unconfirmed sweep as a confirmed one. A merchant with a specific concern about their erasure can contact us for the current status of their request.
A shopper (or a merchant on a shopper’s behalf) can request erasure of that shopper’s individual data through Shopify’s customers/redact mechanism, which we honor by deleting that shopper’s individually-identifiable validation and order-edit records tied to their Shopify customer ID.
We apply the following measures to protect personal data:
We do not currently hold third-party security certifications such as SOC 2, ISO 27001/27017, or PCI-DSS (the last of which does not apply given Section 5). No accredited body issues a general-purpose “GDPR certification”, our privacy program is built to meet GDPR obligations, and we describe it in those terms rather than as a certification we hold.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Depending on where you are located, you may have some or all of the following rights over your personal data:
These rights apply directly to merchants with respect to their own account data, and to website visitors with respect to the website and marketing data described in Section 6. To exercise them, submit a request at tacey.app/privacy-request, or contact us using the details in Section 23. We confirm the email address a request came from before acting on it.
For shopper data, see Section 15, the mechanism is different because we act as a processor, not a controller, for that data.
Because Tacey processes shopper data as a processor acting on a merchant’s instructions, a shopper’s primary relationship for exercising their privacy rights is with the merchant they bought from, not with us directly. This mirrors how Shopify itself structures privacy requests across its entire platform.
In practice, this happens automatically through three mechanisms Shopify requires every app to support, and which Tacey implements:
customers/data_request topic). We respond to the merchant’s store with a count and description of what we hold about that shopper so the merchant can fulfill the request, we do not contact the shopper directly, because the merchant is the controller and because Shopify’s API Terms restrict apps from contacting a merchant’s customers outside the merchant’s own instruction.customers/redact topic). We delete that shopper’s individually-identifiable records.shop/redact topic). We delete the merchant’s full data set, including the shopper data processed on their behalf, subject to the note in Section 12.All three mechanisms are implemented and active in Tacey’s production system. A shopper who wants to exercise a privacy right about a specific order should contact the merchant they ordered from; a merchant who needs help fulfilling that request, or who wants to confirm what we hold, can contact us directly using Section 23.
The Service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16 (or the relevant age of digital consent in their jurisdiction, if higher). Tacey processes shopper order data only in the ordinary course of a merchant’s own commerce transactions; if we become aware that we have inadvertently processed a child’s data outside that context, we will delete it.
Tacey uses automated logic to classify a shipping address (for example, as likely deliverable, likely undeliverable, or uncertain) and to suggest a corrected form of an address. This is not automated decision-making with legal or similarly significant effect on a person:
Tacey does not perform automated decision-making that would trigger a right to human review, explanation, or objection under Article 22 of the GDPR or equivalent laws.
In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we notify affected merchants without undue delay and, where legally required, notify the relevant supervisory authority within the timeframe required by applicable law (72 hours under the GDPR, from the time we become aware of the breach). Where a breach affects shopper data we process as a processor, we notify the affected merchant promptly so they can meet their own notification obligations as the controller.
Our website does not currently respond differently to browser “Do Not Track” signals. We will update this section if that changes, including in response to legally binding opt-out signals such as the Global Privacy Control where applicable.
We may update this Privacy Policy from time to time to reflect changes in our practices, our subprocessors, or applicable law. We post the updated policy on this page with a revised “Last updated” date, and where a change is material, we provide merchants with additional notice (such as an in-app notification or an email) before the change takes effect. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
If you believe we have not handled your personal data in accordance with this policy or applicable law, contact us first so we can try to resolve your concern (see Section 23). You also have the right to lodge a complaint with a data protection supervisory authority in your country of residence, place of work, or the place of the alleged infringement, for example, the Information Commissioner’s Office in the United Kingdom (ico.org.uk), or your national data protection authority in the European Union.
Depending on your state of residence, you may have rights under laws such as the California Consumer Privacy Act (as amended by the CPRA), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, and similar state laws, including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the sale or “sharing” of personal information for cross-context behavioral advertising.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable state law. To exercise a state privacy right, contact us using the details in Section 23.
For any question about this Privacy Policy, or to exercise a right described above, contact us at:
Data-subject request form: tacey.app/privacy-request
Email: hello@taceysupport.app
Postal address: Coastal Highway, Lewes, Delaware 19958, United States