Easy Warranty and Claims

Data protection & privacy

How we handle customer data

Last updated August 21, 2026.

This page explains, in plain language, exactly what customer information Easy Warranty and Claims collects, why, how long we keep it, and how it's protected. It also serves as our data protection agreement with the merchant using this app.

1. What we collect, and why

When a customer places an order in your store, Shopify sends us the order details through a webhook. From that, we store only:

  • The customer's name and email address — so we can invite them to register their warranty and, later, contact them about it.
  • The product they bought, the order number, and the purchase date — so we know what's under warranty and since when.
  • If they choose to register: an optional serial number and a photo of their proof of purchase, which they upload themselves.
  • If they file a claim: a description of the issue and any photos they choose to attach.

We do not collect the customer's phone number or shipping/billing address — the app has no place to store them, because it never needs more than a name and an email address to do its job.

2. Our agreement with you, the merchant

By installing and using Easy Warranty and Claims, you agree that:

  • We process customer personal data only to provide the app's warranty registration and claims features to you — never for advertising, resale, or any other purpose.
  • You remain responsible for telling your own customers (for example, in your store's privacy policy) that a warranty app processes their name and email address on your behalf.
  • If a customer asks you to access, correct, or delete their data, we act on that request as described below, or automatically when Shopify forwards the customer's request to us directly.
  • If you stop using the app, we keep your shop's data for 48 hours (in case you reinstall) and then permanently delete it, as required by Shopify.

3. How long we keep data

We do not keep customer data indefinitely. Two rules run automatically, on a schedule:

  • If a customer never completes their warranty registration, we remove their name and email from that record after 2 years.
  • Once a warranty — and any reasonable time to file a claim afterward — has been over for 3 years, we remove the customer's name, email, serial number, and proof-of-purchase photo from that record, while keeping the record itself (with identifying details removed) so the merchant's own sales history and counts stay accurate.

4. Security measures

  • All data is encrypted both at rest and in transit.
  • Backups of the database are encrypted the same way.
  • There is exactly one production database — no stray copies of customer data anywhere else.
  • Access to every system that touches this data requires a strong, unique password, with two-factor authentication turned on everywhere it's offered.

5. Who can access data, and how it's tracked

Easy Warranty and Claims is currently operated by a single person — there is no separate staff with their own logins. Every time customer names and email addresses are viewed inside the app (for example, on the Registrations page), the app automatically records who viewed it and when, so there is always a real, checkable log — not just a promise that access is controlled.

6. If something goes wrong

If we ever discover that customer data has been accessed or exposed without authorization, we will:

  1. Immediately stop the exposure — for example, by revoking a compromised password or key.
  2. Work out exactly what data, and which merchants or customers, were affected.
  3. Notify affected merchants within 72 hours of confirming the incident, describing what happened and what we're doing about it.
  4. Notify Shopify, since access to this data exists only because of that relationship.
  5. Fix the underlying cause before considering the incident closed.
  6. Write down what happened and what changed afterward, so it doesn't happen again.

7. Your rights, no matter where you live

Shopify requires every app on its App Store to give the same privacy rights to every customer, regardless of which country they live in. We do that by giving every customer — whether in India, the United States, the United Kingdom, Australia, or anywhere else — all of the following, as one single standard, rather than a different, narrower set of rights depending on where a law happens to apply:

  • The right to know what we hold about you. You (or the merchant, on your behalf) can ask what data we have tied to your name or email address, and we will provide it.
  • The right to correct it, if something is wrong.
  • The right to have it deleted. The merchant can trigger this for you directly inside Shopify, or you can ask the merchant to do it on your behalf.
  • We never sell personal data, to anyone, for any reason. There is nothing to "opt out" of, because it never happens in the first place. We also never use it for advertising, and no automated system makes decisions about you based on it.

We aim to act on any of these requests within 30 days. Because the app doesn't have a direct account relationship with customers (only the merchant does), the request normally comes to us through the merchant — either automatically, when Shopify forwards a customer's request, or because the customer asked the merchant directly. If you're a merchant's customer and aren't sure how to start this, ask the store you bought from, or see the Questions section below.

8. How this fits with India's data protection law (the DPDP Act)

Because this business is based in India, India's Digital Personal Data Protection Act, and the detailed Rules under it (notified in November 2025), apply to how customer data is handled here. As of August 2026:

  • The law is being brought in on a phased timetable. Some duties are already active; the remaining core duties — around consent notices, data retention limits, and breach reporting — are due to be fully in force by 13 May 2027.
  • Once fully in force, a data breach must be reported to India's Data Protection Board within 72 hours, and affected customers must be told promptly what happened. The 6-step plan in Section 6 above was written with this in mind.
  • The law expects personal data to be deleted once it's no longer needed for the reason it was collected — generally not kept beyond about a year of a customer having no further activity, unless a longer period is genuinely justified. Our retention windows in Section 3 (2 years for an unclaimed invite, 3 years after a warranty and claim window ends) run longer than that one-year default. We believe this is reasonable, since a warranty is a multi-year promise and a claim can come in years later — but this is exactly the kind of judgment call a lawyer should confirm, not us alone.
  • The law also expects a clear, plain-language notice of what's collected and why, kept separate from ordinary terms of service (this page is written with that in mind), an easy way to withdraw consent, and a way to reach someone about your data — see Questions below.

This section reflects our own reading of the current rules as of August 2026 — it is not legal advice.

9. How this fits with United States, United Kingdom, and Australian privacy law

This app is built in India, for merchants and their customers in the United States, the United Kingdom, and Australia. Here is how it lines up with each region's own privacy law, as we understand it as of September 2026:

United States (including California's CCPA/CPRA)

California's law only places its full set of formal duties (like a required toll-free number for requests) on businesses that cross certain size thresholds — for example, $25 million or more in yearly revenue, or handling personal data for 100,000 or more people a year, or getting half or more of revenue from selling personal data. As a small, single-founder business, we do not currently cross any of those thresholds. That said, we are not waiting to be legally required to give customers real rights — Section 7 above already gives every customer the core things this law is designed to guarantee (knowing what's held, deleting it, and never having it sold), regardless of the size the business eventually grows to.

United Kingdom (UK GDPR)

UK law expects a privacy notice to clearly state who we are and how to reach us (see Questions below), what we collect and why (Section 1), the legal basis for processing it (we process it to carry out the warranty and claims service the merchant has engaged us for), how long we keep it (Section 3), and a customer's rights over their own data (Section 7). If a UK customer believes their data has been mishandled, they also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.

Australia (the Privacy Act and the Australian Privacy Principles)

Australia has historically exempted small businesses (under AU$3 million in yearly revenue) from most of its Privacy Act. Public reporting as of 2026 indicates that exemption is being phased out, with full removal expected by the end of 2026 — after which point size alone will no longer excuse a business from complying. Separately, whether Australia's law reaches a foreign company like ours at all is its own legal question, tied to whether we're considered to be "carrying on business" that has a real connection to Australia. We are not certain of the answer either way, which is exactly why this is one of the specific questions we've asked a lawyer to confirm. In the meantime, Section 7's rights (access, correction, deletion, never selling data) are already given to every Australian customer today, without waiting for that answer.

As with Section 8, this section is our own good-faith reading of publicly available guidance, current as of September 2026 — it is not legal advice, and it does not replace a real lawyer confirming which specific rules legally apply to this business and whether this page fully satisfies them.

Questions

If you're a merchant with questions about this policy, contact us at the support email shown in your app settings.