Privacy Policy
Effective date: 25 August 2026
This Privacy Policy explains how Parcelo (“Parcelo”, “we”, “us”), provided by Twin Ecom, collects, uses, stores, and protects information when a Shopify merchant installs and uses the Parcelo app (the “App”). Parcelo helps merchants reconcile cash-on-delivery (COD) parcels against their courier and flag customers with a high return rate.
Our role
The merchant who installs Parcelo is the data controller of their store’s and customers’ data. Parcelo acts as a data processor, processing that data only on the merchant’s behalf and instructions to provide the App’s features.
What data we access and store
Through the Shopify APIs (with the merchant’s authorization) we access order and fulfillment data. We store only what the App needs:
- Customer phone number — the only protected customer field we store. It is used to calculate a customer’s delivery-history (RTO) risk. We do not store customer names, emails, or addresses. Those fields may appear in Shopify webhook payloads we receive, but they are discarded and never persisted.
- Order and parcel data — order reference/ID, tracking number, COD amount and currency, delivery status and its history, and courier charges (delivery charge, tax, fees, net remitted, settlement date/reference).
- Courier account credentials — the API token you enter for your courier, stored encrypted at rest (AES-256-GCM). It is never displayed again after you save it.
- App settings and queued actions — your automation preferences and the tag/note/mark-paid/cancel actions the App queues for your approval.
- Customer risk records — a customer’s phone number with counts of delivered/returned/refused parcels and any manual risk label you set.
How we use data
- To pull parcel status from your courier and reconcile it against your Shopify orders.
- To tag orders, add timeline notes, and mark COD orders paid on delivery (per your settings).
- To calculate advisory return-to-origin (RTO) risk for customers, derived solely from your own store’s delivery history.
RTO risk is advisory only. It never automatically blocks or cancels an order at checkout; you always decide, and you can override any score. We do not make automated decisions that produce legal or similarly significant effects on your customers.
Who we share data with
We do not sell customer data or share it for advertising. We share data only as needed to operate the App:
- Your courier (e.g. PostEx) — we send tracking numbers to your courier’s API and receive status and charge information, using the courier account you connect.
- Shopify — to write tags, notes, and payment/cancellation updates to your orders.
- Hosting — the App and its database run on Railway, which stores data on our behalf under its own security controls.
Data retention
Parcel and delivery-event data for completed parcels (delivered, returned, lost, or cancelled) is automatically deleted 180 days after completion. You may also request deletion at any time, and all of a store’s data is deleted when the App is uninstalled (within 48 hours), through Shopify’s standard data-erasure webhooks.
Security
- All data is transmitted over encrypted connections (HTTPS/TLS).
- Courier API tokens are encrypted at rest with AES-256-GCM.
- We keep development and production environments separate and limit access to production data.
Your rights
Depending on your jurisdiction, you and your customers may have rights to access, correct, or delete personal data. As the merchant is the data controller, customer requests should be directed to the merchant, who can action them in Shopify (which triggers our deletion) or contact us for assistance.
Changes
We may update this policy; material changes will be reflected by a new effective date. Continued use of the App after an update constitutes acceptance of the revised policy.
Contact
Questions about this policy or your data: support@twinecom.com.