Privacy Policy
Last updated: July 13, 2026
CODFlow ("we", "us", "the app") is a Shopify app that lets merchants accept Cash on Delivery orders on their storefront. This policy explains what data we collect, why, and how it's handled.
What we collect
- Merchant (store) data: shop domain, app settings, and configuration you enter in the CODFlow dashboard (form design, courier settings, discounts, upsell rules, and similar preferences).
- Buyer data submitted through the COD form: name, phone number, delivery address, and order details, which are used solely to create the order in your Shopify store.
- Order and fraud-signal data: order history used to power delivery-success/fraud scoring features, where enabled.
How we use it
Data is used only to operate the app's features for the merchant who installed it: creating draft/real orders, running analytics, sending order notifications, and (if configured) syncing orders to Google Sheets or sending events to ad pixels. We do not sell buyer or merchant data.
Data retention & deletion
When a merchant uninstalls CODFlow, their session is removed immediately. All store data is permanently erased when Shopify sends the mandatory shop/redact webhook (48 hours after uninstall). Buyer data-erasure and data-request requests are honored via Shopify's mandatory customers/redact and customers/data_request webhooks.
Third parties
Depending on which optional features a merchant enables, order data may be shared with: the merchant's chosen courier service (for delivery), Google Sheets (if the merchant connects a sheet), and ad platforms via server-side conversion events (if the merchant configures pixels). These integrations are opt-in and configured by the merchant.
Contact
Questions about this policy or your data? Email mhtareqarz@gmail.com or visit our support page.