Pakiautomaadid

Privacy policy

Last updated: 22 September 2026

Eesti keeles

1. Who we are

Pakiautomaadid (the “App”) is a Shopify app that lets a store’s customers choose a parcel locker or pickup point, and lets the merchant register a shipment and print a label with Omniva or Smartposti.

The App and the websites pakiautomaadid.eu and app.pakiautomaadid.eu are operated by:

  • Arrowhead Creative OÜ
  • Registry code 14153865
  • Maakri tn 28a, 10145 Tallinn, Estonia
  • [email protected]

Privacy requests go to the email address above.

2. Who this policy is for

This policy explains how we handle personal data of:

  • merchants and their staff who install and use the App
  • customers of those merchants (“buyers”), when they choose a pickup point or when the merchant creates a shipping label
  • visitors to pakiautomaadid.eu

3. Our role

For a merchant’s account, settings, and the relationship with us, Arrowhead Creative OÜ is the controller.

When we process a buyer’s order data in order to show pickup points or to register a shipment with a carrier, the merchant is the controller and we are the processor. We handle that data only on the merchant’s instructions: the settings the merchant saves in the App, and the actions the merchant takes (such as creating a label). Section 10 sets out those processing terms.

We do not sell personal data. We do not use it for advertising, and we do not make automated decisions that produce legal or similarly significant effects.

4. What we collect

Through Shopify

When a merchant installs the App, Shopify gives us:

  • the shop domain (for example example.myshopify.com)
  • an offline access token and a refresh token, so the App can call the Shopify Admin API for that shop. We store both encrypted.
  • the subscription status of the App’s paid plan, which Shopify bills. We do not receive the merchant’s card number.

Shopify access is limited to reading orders, products, and theme settings; creating delivery and payment customizations; and creating fulfillments the merchant manages.

We read an order only when a merchant creates a shipping label. For that order we use the order name, the recipient’s name, phone number, and email address, the destination country, and the pickup point the buyer chose. We read products and theme settings only to configure shipping methods and to check that the storefront block is enabled. Those reads are not used to build a profile of buyers.

Information the merchant enters

In the App admin the merchant can save:

  • which carriers are enabled, the admin language, and onboarding progress
  • carrier credentials (an Omniva customer code, username, and password, or a Smartposti API key). These are stored encrypted and are not shown again after saving.
  • a sender address: name, phone, email, street, city, postal code, and country. This is the merchant’s return address on the shipment.
  • a confirmation that the shop requires a phone number at checkout. We store that yes-or-no flag, not customers’ phone numbers.

Information from buyers

The storefront block runs on the merchant’s cart page. When a buyer picks a locker, the block saves that choice on the cart in the merchant’s own Shopify store: locker id, name, address, city, postal code, and country, and opening hours when the carrier provides them. We do not copy that choice into our database.

Searching for a locker sends the selected country to our app. We return the public list of lockers for that country and carrier. We cache those public lists for a short time. The cache is not tied to a buyer.

We do not set tracking cookies, pixels, or analytics on the storefront. We do not log how a buyer browses the merchant’s store.

This website

pakiautomaadid.eu does not use analytics or marketing cookies. If you email us, we keep the message and your email address so we can reply. Our host, Cloudflare, may keep standard connection logs (such as IP address, browser type, and the time of the request) under its own retention rules.

5. Why we use it

  • To provide the App, including installation, settings, and billing status. Legal basis: contract with the merchant (GDPR Article 6(1)(b)).
  • To read an order and send it to the carrier the merchant selected, so the merchant can ship the parcel. We do this as the merchant’s processor. The merchant’s basis is the contract with the buyer.
  • To keep tokens and credentials encrypted, verify webhooks, and protect the service. Legal basis: legitimate interest in securing the App (Article 6(1)(f)), and our contract with the merchant.
  • To reply to email. Legal basis: legitimate interest, or steps toward a contract if you are asking about using the App.

We use personal data only for these purposes.

6. Who we share it with

  • Shopify Inc. and its affiliates. Shopify runs the store, the checkout, billing for the App, and the admin session. Shopify processes data in Canada and the United States, among other places.
  • Cloudflare, Inc. Hosts the App (Cloudflare Workers), the database (D1), a short-lived cache (KV), and this website. Cloudflare may process data on a global network. Transfers outside the European Economic Area are covered by Cloudflare’s data processing addendum and Standard Contractual Clauses.
  • Omniva and Smartposti, only when the merchant registers a shipment. We send the recipient’s name, phone, email, and pickup point, and the merchant’s sender details, through the merchant’s own carrier account. We do not send buyer data to a carrier when someone is only searching for a locker. Those carriers operate in the European Union.
  • Public authorities, if the law requires us to disclose information.

We do not share personal data with advertisers. We do not sell it, and we do not “share” it as that word is used in US state privacy laws, including the CPRA.

7. How long we keep it

We keep a shop’s tokens, settings, carrier credentials, and sender address while the App is installed.

When a merchant uninstalls the App, we mark the shop as uninstalled and stop using the data. Shopify then sends a shop-deletion request, usually about 48 hours later. When we receive it, we delete that shop’s rows from our database, including tokens, settings, credentials, and the sender address.

We do not store buyer personal data. It is read from Shopify when a label is created, sent to the carrier, and not kept by us afterwards. The chosen locker stays on the cart in the merchant’s Shopify store, under Shopify’s and the merchant’s retention.

Cached locker lists expire on their own and contain no buyer identity.

We keep emails we receive for as long as we need them to handle the request and any follow-up, and then delete them.

8. Security

The App is served over TLS. Shopify access tokens, refresh tokens, and carrier credentials are encrypted at rest with AES-256-GCM. Access tokens expire and are refreshed. We check the signature on incoming Shopify webhooks before acting on them. Access to production data is limited to the people who operate the App.

9. Your rights

Where we are the controller, you can ask us to:

  • give you access to the personal data we hold about you
  • correct it
  • delete it
  • restrict processing
  • provide a portable copy
  • stop processing that is based on legitimate interest

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee.

If you are a buyer, the merchant is the controller of your order. Please contact the store first. We also respond to Shopify’s mandatory privacy webhooks. A customer data request or deletion notice does not require us to export or erase a separate copy, because we do not keep one. The order remains in the merchant’s Shopify admin until the merchant or Shopify deletes it.

10. Processing on behalf of merchants

This section is the processing arrangement between us and the merchant for buyer personal data.

  • Subject matter: pickup-point selection and shipment registration for the merchant’s Shopify store.
  • Duration: while the App is installed, and until the deletion described in section 7.
  • Nature and purpose: reading only the order fields needed to register a parcel with the carrier the merchant has connected, and writing the buyer’s locker choice onto the merchant’s cart.
  • Data: recipient name, phone, email, destination country, pickup point, and the order name. We do not request buyer data for any other purpose.
  • We process that data only on the merchant’s documented instructions, including this policy and the actions the merchant takes in the App. If a law requires us to process it differently, we tell the merchant unless the law forbids that notice.
  • People who operate the App are bound by confidentiality.
  • We apply the security measures in section 8.
  • We use only the subprocessors in section 6. We will update this policy before we add a subprocessor that handles buyer personal data.
  • We help the merchant respond to buyer requests, including the Shopify webhooks customers/data_request and customers/redact.
  • When the merchant uninstalls the App, we delete the shop’s data as described in section 7. We do not keep a copy of buyer personal data to return.
  • We make available the information the merchant reasonably needs to show that this processing meets Article 28 of the GDPR. We do not currently hold an independent audit report.

11. Cookies

This website does not set analytics or marketing cookies. The App inside the Shopify admin uses Shopify’s own session, which Shopify controls. The storefront block does not set a cookie to track the buyer. The chosen locker is stored as cart attributes in the merchant’s store.

12. Children

The App is for merchants and is not directed at children.

13. Changes

When we change this policy, we update the date at the top of this page. If a change materially affects how we process buyer data on a merchant’s behalf, we describe it here before it takes effect.

14. Contact