Data protection & privacy
Last updated August 21, 2026.
This page explains, in plain language, exactly what customer information Easy Warranty and Claims collects, why, how long we keep it, and how it's protected. It also serves as our data protection agreement with the merchant using this app.
When a customer places an order in your store, Shopify sends us the order details through a webhook. From that, we store only:
We do not collect the customer's phone number or shipping/billing address — the app has no place to store them, because it never needs more than a name and an email address to do its job.
By installing and using Easy Warranty and Claims, you agree that:
We do not keep customer data indefinitely. Two rules run automatically, on a schedule:
Easy Warranty and Claims is currently operated by a single person — there is no separate staff with their own logins. Every time customer names and email addresses are viewed inside the app (for example, on the Registrations page), the app automatically records who viewed it and when, so there is always a real, checkable log — not just a promise that access is controlled.
If we ever discover that customer data has been accessed or exposed without authorization, we will:
Shopify requires every app on its App Store to give the same privacy rights to every customer, regardless of which country they live in. We do that by giving every customer — whether in India, the United States, the United Kingdom, Australia, or anywhere else — all of the following, as one single standard, rather than a different, narrower set of rights depending on where a law happens to apply:
We aim to act on any of these requests within 30 days. Because the app doesn't have a direct account relationship with customers (only the merchant does), the request normally comes to us through the merchant — either automatically, when Shopify forwards a customer's request, or because the customer asked the merchant directly. If you're a merchant's customer and aren't sure how to start this, ask the store you bought from, or see the Questions section below.
Because this business is based in India, India's Digital Personal Data Protection Act, and the detailed Rules under it (notified in November 2025), apply to how customer data is handled here. As of August 2026:
This section reflects our own reading of the current rules as of August 2026 — it is not legal advice.
This app is built in India, for merchants and their customers in the United States, the United Kingdom, and Australia. Here is how it lines up with each region's own privacy law, as we understand it as of September 2026:
United States (including California's CCPA/CPRA)
California's law only places its full set of formal duties (like a required toll-free number for requests) on businesses that cross certain size thresholds — for example, $25 million or more in yearly revenue, or handling personal data for 100,000 or more people a year, or getting half or more of revenue from selling personal data. As a small, single-founder business, we do not currently cross any of those thresholds. That said, we are not waiting to be legally required to give customers real rights — Section 7 above already gives every customer the core things this law is designed to guarantee (knowing what's held, deleting it, and never having it sold), regardless of the size the business eventually grows to.
United Kingdom (UK GDPR)
UK law expects a privacy notice to clearly state who we are and how to reach us (see Questions below), what we collect and why (Section 1), the legal basis for processing it (we process it to carry out the warranty and claims service the merchant has engaged us for), how long we keep it (Section 3), and a customer's rights over their own data (Section 7). If a UK customer believes their data has been mishandled, they also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.
Australia (the Privacy Act and the Australian Privacy Principles)
Australia has historically exempted small businesses (under AU$3 million in yearly revenue) from most of its Privacy Act. Public reporting as of 2026 indicates that exemption is being phased out, with full removal expected by the end of 2026 — after which point size alone will no longer excuse a business from complying. Separately, whether Australia's law reaches a foreign company like ours at all is its own legal question, tied to whether we're considered to be "carrying on business" that has a real connection to Australia. We are not certain of the answer either way, which is exactly why this is one of the specific questions we've asked a lawyer to confirm. In the meantime, Section 7's rights (access, correction, deletion, never selling data) are already given to every Australian customer today, without waiting for that answer.
As with Section 8, this section is our own good-faith reading of publicly available guidance, current as of September 2026 — it is not legal advice, and it does not replace a real lawyer confirming which specific rules legally apply to this business and whether this page fully satisfies them.
If you're a merchant with questions about this policy, contact us at the support email shown in your app settings.