tacey.

SECURITY AND PRIVACY

Trust Centre. What we hold, where it goes, and how you get it back.

Tacey sits between your store and your customers’ addresses. That means we handle personal data, and you are entitled to know exactly how much, for how long, and who else touches it. This page answers that without a sales call.

SOC 2 Type II infrastructure (Cloudflare)ISO 27001 infrastructure (Cloudflare)GDPR and CCPA ready Card data never reaches us Every subprocessor listed below

The first two describe the infrastructure we run on, held by Cloudflare, not by Tacey. We do not hold SOC 2 or ISO 27001 ourselves and will not imply otherwise.

We ask Shopify for as little as the job needs.

Every Shopify app declares exactly what it can access, and Shopify enforces it, not us. Ours is listed on our App Store page, and you approve it before anything is installed.

What we read

Orders and their shipping addresses, so we can check them. Your shop’s settings and plan, so we know how to behave.

What we write

A validation result on the order. Address and line-item changes, and order cancellations from merging duplicate orders, but only ones you or your customer explicitly confirmed.

What we never touch

Payment details. We never see or store a card. Money only moves through Shopify’s own flow, with a confirmation, every time.

Where your data lives, and how long we keep it.

Encrypted in transit

Every connection uses TLS. There is no unencrypted path in or out.

Encrypted at rest

Storage is encrypted by our infrastructure provider by default.

Held on Cloudflare

The application, the database, and stored payloads all run on Cloudflare’s network.

Deleted when you leave

When you uninstall, Shopify tells us to erase your data, and we do, including the raw order payloads we archived.

Customer privacy requests are handled automatically.

Shopify sends us three mandatory privacy requests on your behalf: a customer asking what data you hold, a customer asking to be erased, and your store asking to be erased after you uninstall. All three are wired and answered. You do not have to file a ticket with us to make a privacy request work.

THE THREE MANDATORY WEBHOOKS

A customer asks what you hold

Answered with everything tied to that shopper.

Answered

A customer asks to be erased

Their data is removed from what we hold for you.

Answered

Your store asks to be erased

Sent when you uninstall, including archived payloads.

Answered

Who else touches the data, and why.

Published here in the open, not behind an access request.

SUBPROCESSORWHAT THEY DOWHAT THEY RECEIVE
CloudflareHosting, database, storage, queuesAll application data
GoogleAddress validation and geocodingThe shipping address being checked
GeocodioUS and Canada address validationThe shipping address being checked
PostmarkSending customer emailsCustomer email address and order details
MixpanelProduct analyticsUsage events. No customer addresses
PostHogProduct analyticsUsage events. No customer addresses
See the full subprocessor detail →

What happens when something breaks.

Address checking never blocks a sale

If our checker is slow, or a provider has a bad minute, the order goes through exactly as it would have. We mark it as unchecked and say so plainly rather than guessing.

Money never moves on its own

Not on an upward edit, not on a refund, not by default, and not on the day you install.

Every edit leaves a record

What changed, what it cost, who asked, and whether your warehouse acknowledged it.

Documents.

Doing a security review?

Email us and we will send the full packet, including our subprocessor detail and answers to your own questionnaire.

Request the security packet