Privacy
Last updated: July 2026
This privacy policy informs you, pursuant to Art. 13 and 14 GDPR, what personal data we process and what rights you have. It applies to (a) the public website kuvert.app and (b) the logged-in app area for Shopify merchants. Where differences exist, they are marked in the respective section.
Controller
The controller for data processing on this website and within the app area pursuant to GDPR:
Lukas LüerCorveyer Weg 15a
33098 Paderborn
Germany
support@kuvert.app
Data protection officer
We have not appointed a data protection officer because we do not meet the legal threshold (at least 20 persons regularly engaged in automated processing).
Merchant account data (where we are the controller)
When a Shopify merchant installs and uses Kuvert, we process the following data about the merchant themselves — for this data we act as the controller (not as a processor): shop domain (e.g. my-shop.myshopify.com), email address of the shop owner, name and where applicable phone number, business address (country, city, ZIP, region), language and timezone settings, OAuth session tokens for the Shopify API, installation and sync timestamps as well as expiry data of authentication sessions, the chosen plan (Basis/Pro) and the billing status. The legal basis is Art. 6(1)(b) GDPR (performance of contract — without this data the app cannot be provided). The data is deleted as soon as the merchant uninstalls the app (technically implemented via the Shopify webhook 'shop/redact' within a maximum of 30 days). An exception applies to the record evidencing the concluded data processing agreement (company and representative details, email address, the IP address collected at the time of confirmation, and the contract text): we retain this record after uninstallation to fulfil our accountability obligations under Art. 5(2) and Art. 28 GDPR (legal basis: Art. 6(1)(c) and (f) GDPR), for a maximum of 10 years.
Requested Shopify permissions
When you install the app, Shopify asks for your consent to the following API permissions (scopes) — here we explain transparently what we need each one for: 'read_customers' and 'write_customers' to import customer master data (postal address, purchase behavior, marketing status) and to set tags identifying direct-mail recipients in your shop. 'read_products' for product-based segmentation (filtering by purchased SKUs). 'read_orders' to link orders to customers when building segments. 'read_all_orders' is required because direct-mail campaign evaluation typically happens several weeks to months after sending (postal delivery + recipient response window) — without this scope, response analytics for older campaigns would not be possible, since the standard 'read_orders' scope only exposes orders from the last 60 days. We use 'read_all_orders' solely to evaluate the performance of campaigns sent through Kuvert, never for any data processing beyond that.
Payment processing
Billing of the Pro plan is handled entirely via Shopify App Pricing. We do not receive any credit card or bank account data — these are processed exclusively by Shopify (see Shopify's privacy policy at shopify.com/legal/privacy). We only store the billing status communicated by Shopify (active, cancelled, expired) and the subscription ID, in order to manage your plan access. An exception applies to managed Dialogpost orders — see the following section.
Managed Dialogpost orders (print and mailing service)
If you as a merchant place a managed Dialogpost order (Kuvert arranges printing and mailing of your campaign), we additionally process the following data: your company's order and invoicing data (company name, address, VAT ID where applicable, order volume, amounts, invoice number and payment reference), the status of your SEPA bank transfer — during payment reconciliation we see the transfer data arriving on our bank account, such as account holder, IBAN and payment reference — as well as the design files (PDF) you upload for the print products. To fulfil the order, we transmit the print data and the recipient address list to the executing print and mailing service provider (lettershop); the providers engaged at any given time are listed as sub-processors in the DPA. The legal basis is Art. 6(1)(b) GDPR (performance of contract). Invoicing and payment data are subject to statutory retention obligations under commercial and tax law (Art. 6(1)(c) GDPR in conjunction with § 147 AO, § 257 HGB) and are therefore retained for up to 10 years even after the app is uninstalled. Design files are stored for the duration of order fulfilment and documentation.
End-customer data of merchants (where we are a processor)
Within the logged-in app area, Kuvert processes data of the end customers of the connected Shopify shop. We deliberately import only those data fields that are relevant for segmentation and filtering by the merchant: full postal address (first and last name, optionally company name, street, ZIP, city, country — the central data point for our direct mail product), purchase behavior (number of orders, total revenue, date of last order, refund information), purchased products as SKU list, the email marketing status (e.g. SUBSCRIBED, UNSUBSCRIBED — we only use this status flag for filtering, the email address itself is not stored) and the internal Shopify customer ID for correlation. We also store the direct mail dispatch history (which recipients were included in which campaign). Other data points such as email address, phone number or payment data are deliberately not imported (data minimization pursuant to Art. 5(1)(c) GDPR). This end-customer data is additionally deleted automatically from our infrastructure after a maximum of 30 days — the merchant may also trigger an immediate manual deletion at any time. With respect to this data, we act as a data processor within the meaning of Art. 28 GDPR — the respective merchant is the controller. We conclude a data processing agreement (DPA) with each merchant during app installation. As a merchant, you can find the current DPA version in the app dashboard under 'Legal'.
End-customer requests
If you are an end customer of a Shopify shop that uses Kuvert: you exercise your data protection rights (access, deletion, etc.) towards the respective Shopify merchant, not towards Kuvert. We technically execute deletion and information requests as soon as the merchant initiates them via the Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact) — processing takes place within a maximum of 30 days from receipt.
Server log data
When you access the website or app, technical data is stored in server log files: IP address, date and time of the request, requested URL, HTTP status code, transferred data volume, referer and user-agent. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the smooth operation of the site and defense against attacks). Storage is limited to a maximum of 30 days, after which the data is automatically deleted. This retention period is necessary to detect recurring attack patterns, bot scanners and anomalies over a sufficient time window. In addition, the application keeps technical processing and error logs (without IP addresses, with shop domain), which are rotated by size and automatically overwritten in the process.
Cookies
We use only strictly necessary cookies. On the public website, we set the 'app-locale' cookie to remember your preferred language. In the logged-in app area, additional Shopify session cookies are used for authentication. These cookies do not require consent under §25(2) TDDDG, as they are strictly necessary for services explicitly requested by the user (language selection, login).
No tracking, no analytics
Neither on the public website nor in the app area do we use web analytics tools, tracking pixels, conversion pixels or profiling cookies. We do not analyze your behavior, neither ourselves nor through third parties such as Google Analytics, Plausible or Meta Pixel.
External content (Shopify CDN)
In the logged-in app area, the App Bridge script for the Shopify integration is loaded from the Shopify CDN (cdn.shopify.com) — this script is technically required for embedding the app within the Shopify Admin. The provider is Shopify International Limited, Ireland (EU subsidiary of Shopify Inc., Canada). This may involve transmission of your IP address to Shopify group companies, including to the USA and Canada. For transfers to the USA, we rely on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR, Decision (EU) 2021/914), which Shopify commits to in its Data Processing Addendum. Transfers to Canada are covered by the European Commission's adequacy decision under Art. 45 GDPR in conjunction with PIPEDA. The legal basis for processing is Art. 6(1)(f) GDPR (legitimate interest in seamless Shopify integration). Fonts (Inter) are self-hosted by us — no third-party transmission occurs there. For more information, see shopify.com/legal/privacy.
Hosting
This website and the Kuvert app are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Data processing including backups and disaster recovery takes place exclusively in data centers in Germany. We have a data processing agreement (DPA) with Hetzner pursuant to Art. 28 GDPR. There is no data transfer to third countries (exception: see 'External content' section).
Contact via email
When you contact us by email (e.g. at support@kuvert.app), we process your email address, your name (if provided) and the content of your message in order to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures / performance of contract) or (f) (legitimate interest in responding to your inquiry). The correspondence is deleted as soon as it is no longer required for processing and no statutory retention obligations (e.g. commercial or tax law) apply. The same applies to support requests submitted via the contact form in the logged-in app area: we store the message text and the shop domain in our database for processing.
Your rights
You have the following rights: access to the data stored about you (Art. 15 GDPR), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21). Please send requests by email to support@kuvert.app.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent authority for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Postfach 20 04 44, 40102 Düsseldorf, Germany (ldi.nrw.de).