Order Change Guard

Privacy notice

Last updated: August 27, 2026

Who operates the app

EMPLARIO LTD operates Order Change Guard. This notice explains how the app processes personal data for Shopify merchants and their customers.

Data and purpose

Order Change Guard monitors Shopify order updates to identify shipping-relevant changes before fulfillment. It processes only the order and fulfillment fields needed for that purpose: Shopify order identifiers and display references, shipping-address lines and postal location fields, shipping method, line-item identifiers and quantities, fulfillment status and location identifiers, app-owned hold identifiers and outcomes, current order totals and discounts, financial status, cancellation state, and timestamps.

Order monitoring does not request protected customer name, email, phone, billing-address, payment-instrument, marketing, or analytics fields, and the app does not fetch Shopify customer profiles. Shopify's signed mandatory privacy webhooks can transiently include a customer identifier and contact fields supplied by Shopify. The app verifies the webhook, retains only the hashed request identity and requested order IDs, and does not persist or use those contact fields. A merchant may separately provide a notification recipient email and a conflict resolution note.

How the app acts

The app compares order states, classifies shipping risk, and can apply merchant-enabled review tags, place an app-owned fulfillment hold where Shopify supports it, or send a critical alert. A merchant remains responsible for reviewing and approving the edit. The app does not make a legal or similarly significant automated decision, cancel an order, refund an order, or fulfill an order.

Personal data is used only to provide, secure, support, and comply with the privacy obligations of Order Change Guard. It is not sold, used for advertising, or used to build customer profiles. The app does not perform marketing or behavioral tracking.

Storage, security, and access

Protected shipping-address values and merchant resolution notes are encrypted at the application layer with AES-256-GCM. Tenant-scoped authorization is required before a protected value can be decrypted. External traffic uses HTTPS, secrets are kept outside the repository, and metadata-only audit records are used for protected-data access.

Shopify provides authentication, order webhooks, and mandatory privacy webhooks. Railway hosts the application and database. Resend processes the merchant-configured recipient, a value-free change category, an order display reference, and an embedded-app link only when critical email alerts are enabled. Critical alert emails do not contain shipping addresses or customer contact details.

Retention and deletion

Order-monitoring records are retained for the lifetime of an active app installation to provide the monitoring and review history. Uninstall immediately stops new monitoring actions. Shopify's shop-redaction webhook deletes the shop's app data after uninstall.

A customer-redaction request destroys the affected encrypted address and note values and prevents delayed webhooks from restoring them. Shop-scoped database audit metadata is removed by shop deletion. Value-free protected-access events in hosting logs follow the hosting provider's separate operational-log retention. Customer-data export request scope expires after 29 days; generated JSON is created in memory for an authenticated download and is never stored as an artifact.

Privacy requests and contact

Order Change Guard receives Shopify's mandatory customer data request, customer redaction, and shop redaction webhooks. Merchants can generate and download a shop-scoped customer-data export inside the authenticated app. Customers should normally contact the Shopify merchant that controls their order; merchants and regulators can contact EMPLARIO LTD at sven-lapadus@web.de.