Privacy Policy for Parcelglance
Last updated: July 15, 2026
Controller
Haimo Tech ("we", "our", or "the App") operates Parcelglance, an AI-powered order tracking chatbot for Shopify stores. For questions about this policy, contact us at privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com).
Age Restriction
Our services are not intended for individuals under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child under the applicable age, please contact us immediately at privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com), and we will take steps to delete such information.
Who This Policy Covers
This Privacy Policy applies to two categories of users:
- Merchants: Shopify store owners who install Parcelglance on their store.
- End Customers: Customers of the merchant's store who interact with the Parcelglance chat widget to track their orders.
AI Transparency Statement
⚠️ AI-Powered Service: Parcelglance uses artificial intelligence (DeepSeek) to process order tracking inquiries and generate automated customer service responses. Users interacting with the chat widget are informed that they are communicating with an AI-powered assistant. AI-generated responses may contain inaccuracies — merchants are responsible for reviewing automated responses for accuracy and compliance with applicable laws.
Data We Collect
From Merchants
- Shop store domain: Collected during OAuth to identify your store and provide app functionality.
- Shopify access token: Stored securely to make API calls on your behalf for order tracking and fulfillment lookup.
- App settings: Widget color, position, greeting, brand name, language preference, FAQ items, and return policy URL — all configured by the merchant.
From End Customers (via Chat Widget)
- Chat messages: Questions and order information (order numbers, email addresses) typed by the customer into the chat widget.
- Customer email: Provided voluntarily by the customer to look up their orders. Used as an inline query filter to Shopify Admin GraphQL only; not persisted server-side.
- Customer name: Not collected as a structured field. If a customer types their name inside the chat, the free-text is stored only as part of the conversation transcript for merchant analytics (≤90 days) and is not extracted, indexed, or used as a Level 2 Protected Customer Data field. We do not request Level 2 PCD access from Shopify.
- Locale/language: Auto-detected from the customer's browser to respond in their preferred language.
From Shopify API (on behalf of Merchants)
- Order data: Order number, status, financial status, fulfillment status, tracking number, tracking company, tracking URL, estimated delivery date, and line items (product title, quantity, image). This data is fetched in real-time from Shopify to answer customer tracking questions.
- Fulfillment data: Tracking and shipment information associated with orders.
Legal Basis for Processing (GDPR Article 6)
We process personal data only when we have a lawful basis under GDPR Article 6. The following table describes the legal basis for each processing activity:
| Processing Activity | Legal Basis | Explanation |
|---|---|---|
| OAuth authentication & session management | Art. 6(1)(b) — Contractual necessity | Required to provide the app service the merchant requested |
| Order tracking & status lookup | Art. 6(1)(b) — Contractual necessity | Core service functionality requested by the merchant |
| AI response generation for general queries | Art. 6(1)(b) — Contractual necessity | Part of the chatbot service the merchant installed |
| Conversation storage (messages & metadata) | Art. 6(1)(b) — Contractual necessity | Required for conversation continuity and analytics promised to merchants |
| Aggregated analytics for merchants | Art. 6(1)(f) — Legitimate interest | Merchants need performance insights; data is aggregated and anonymized |
| Customer feedback (thumbs up/down) | Art. 6(1)(f) — Legitimate interest | Improving service quality; feedback is voluntary |
| Locale/language detection | Art. 6(1)(f) — Legitimate interest | Providing responses in the customer's preferred language improves service |
When we rely on legitimate interest (Art. 6(1)(f)), we have conducted a balancing test to ensure the rights and freedoms of data subjects are not overridden.
How We Use Data
- Order tracking: To look up and display order status, tracking information, and estimated delivery to end customers.
- AI response generation: Chat messages and order data are sent to our AI provider (DeepSeek) to generate contextual responses for non-tracking queries (general questions, FAQ). For pure order tracking queries, no AI call is made — responses are generated instantly from order data.
- Conversation continuity: Conversation IDs are stored locally in the customer's browser (localStorage) to maintain chat history across page loads within 24 hours.
- Analytics: Aggregated, anonymized metrics (conversation count, tracking query count, auto-resolved rate, feedback ratings) for merchants to understand chatbot performance.
- Service improvement: Customer feedback (thumbs up/down) is stored to help merchants and us improve response quality.
What We Do NOT Do
- We do not sell, rent, or share personal information with third parties for marketing purposes
- We do not use customer data for advertising or profiling
- We do not store order data after responding — it is fetched in real-time from Shopify and discarded
- We do not use third-party analytics or tracking services
- We do not share chat conversations with anyone except the merchant who owns the store
Third-Party Services (Subprocessors)
We use the following third-party service providers (subprocessors) to operate Parcelglance:
| Provider | Purpose | Location | Transfer Basis |
|---|---|---|---|
| Supabase Inc. | Database hosting (conversations, messages, analytics, settings) | Tokyo, Japan (EU adequacy decision) | EU adequacy (Japan) |
| DeepSeek (High-Flyer AI) | AI response generation for non-tracking queries only | China (no EU adequacy) | SCCs + encryption + data minimization |
| Vercel Inc. | Application hosting & deployment | USA (EU-US Data Privacy Framework) | DPF certification |
| Shopify Inc. | OAuth, API access, billing | USA/Canada (DPF certified) | DPF certification |
We will notify merchants via email of any changes to our subprocessor list at least 30 days before the change takes effect, giving you the opportunity to object.
International Data Transfers
Your data may be transferred to and processed in countries outside your jurisdiction. We protect your data during international transfers through:
- EU Adequacy Decisions: Data stored in Supabase (Tokyo, Japan) benefits from the EU's adequacy decision for Japan (Commission Implementing Decision 2019/1919), ensuring equivalent data protection standards.
- Data Privacy Framework (DPF): Vercel and Shopify are certified under the EU-U.S. Data Privacy Framework, providing adequate safeguards for U.S.-based processing.
- Standard Contractual Clauses (SCCs): For transfers to DeepSeek in China (which lacks an EU adequacy decision), we rely on the European Commission's Standard Contractual Clauses (Module 3: Processor to Processor) as the transfer mechanism, incorporated into our API service agreement with DeepSeek. This is supplemented by encryption in transit (TLS 1.2+) and at rest, data minimization (only non-tracking chat messages are sent; order data never leaves our system), and pseudonymization of customer identifiers where feasible. EU merchants may request a copy of the executed SCCs by contacting us.
- Transfer Impact Assessment: We have assessed the legal framework of China and implemented supplementary measures (encryption, data minimization, limited retention) to ensure essentially equivalent protection of personal data.
China Data Transfer Notice: Chat messages for non-tracking queries are sent to DeepSeek's servers in China for AI processing. China's data protection laws (PIPL, Cybersecurity Law) may grant government authorities access to data under certain circumstances. We mitigate this risk through: (1) only sending minimal chat messages (no order data, no financial data), (2) real-time processing without retention by DeepSeek, (3) encryption in transit and at rest, and (4) pseudonymization where feasible. If you are an EU merchant concerned about this transfer, you may contact us to discuss additional safeguards or alternative processing arrangements.
Cookie & Local Storage Policy
We use limited cookies and local storage technologies:
| Type | Purpose | Duration |
|---|---|---|
| Essential Session Cookies | Required for Shopify App authentication and session management | Session |
| localStorage (Widget) | Stores conversation ID for chat continuity across page loads (essential for service functionality) | 24 hours |
| Third-party Analytics | We do not use any third-party analytics or tracking cookies | N/A |
Data Retention
- Access tokens: Stored until you uninstall the App. Automatically deleted upon uninstallation via Shopify webhook.
- Conversations & messages: Stored in Supabase (Tokyo) for conversation continuity and analytics. Retained for up to 90 days from the last message, after which they are automatically purged via a daily automated cleanup process. Deleted immediately when the App is uninstalled.
- Customer PII in conversations (email, name): Anonymized after 90 days of inactivity. Deleted upon customer request or App uninstallation.
- Order data: Fetched in real-time from Shopify API. Not stored by our App after the response is sent.
- Chat messages sent to DeepSeek: Processed in real-time. According to DeepSeek's stated data policies, chat messages are not retained after generating the response. However, we cannot independently verify DeepSeek's internal data practices and recommend merchants review DeepSeek's privacy policy at deepseek.com/privacy for the most current information.
- Analytics: Aggregated, anonymized daily metrics retained for 12 months for trend analysis.
- Widget localStorage: Conversation ID stored in the customer's browser for 24 hours only, then automatically expires.
Your Rights
For Merchants (Data Controllers)
- Right to access: Request a copy of your store data.
- Right to erasure: Uninstalling the App triggers automatic deletion of all your data.
- Right to data portability: Request your data in a machine-readable format.
- Right to object: Object to processing of your personal data.
- Data Processing Agreement: Available at parcelglance.com/dpa or upon request for EU merchants who require a signed copy.
For End Customers (Data Subjects)
- Right to access: Request information about any data we hold about you.
- Right to erasure: Request deletion of your conversation messages and pseudonymization of associated conversation records (we delete chat messages containing PII and replace customer identifiers with anonymous tokens in retained metadata — see customers/redact webhook below; this approach is GDPR Art 17(3)(b)-defensible because pseudonymized metadata is required for fraud/abuse detection and aggregate analytics). You can also clear the chat widget's localStorage by clearing your browser data.
- Right to rectification: Request correction of inaccurate data.
- Right to restrict processing: Request that we limit how we use your data.
To exercise these rights, contact us at privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com) or ask the merchant to submit a request on your behalf. We will respond within 30 days.
Shopify Data Compliance
This App complies with Shopify's mandatory privacy requirements:
- customers/data_request webhook: Handles customer data access requests
- customers/redact webhook: Anonymizes and deletes customer PII from conversations
- shop/redact webhook: Deletes ALL shop data (including conversations, messages, feedback, analytics, settings) upon uninstallation
EU Consumer Rights (14-Day Withdrawal)
If you are located in the European Union or European Economic Area, you have the following consumer rights under EU consumer protection laws:
- Right of Withdrawal: You have the right to withdraw from your subscription contract within 14 days without giving any reason.
- Exercise of Withdrawal: To exercise the right of withdrawal, send an email to privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com).
- Reimbursement: We will reimburse all payments within 14 days of receiving your withdrawal request.
- Exceptions: The right of withdrawal does not apply to services fully performed before the end of the withdrawal period with your express consent.
CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the personal data we collect and how it is used
- Right to Delete: Request deletion of your personal information
- Right to Opt Out: We do not sell personal information. There is nothing to opt out of
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Automated Decision-Making (GDPR Article 22)
We do not engage in automated decision-making that produces legal effects or similarly significant effects on individuals. Parcelglance generates order tracking responses and general customer service replies. These responses are informational only and do not:
- Make decisions about creditworthiness, employment, or legal status
- Automatically approve or deny customer claims, refunds, or returns
- Produce effects that significantly affect individuals' rights or freedoms
All refund, return, and claim decisions remain with the merchant. Customers can always request human assistance by using the persistent "Talk to a human" option in the chat widget footer, which notifies the store team and directs the customer to contact the store directly.
EU AI Act Compliance
In accordance with the EU Artificial Intelligence Act (Regulation 2024/1689):
- Transparency (Art. 50): All users interacting with the Parcelglance chat widget are informed that they are communicating with an AI system. The widget header displays "AI-powered · Online" to clearly indicate AI operation, and the footer provides a persistent "Talk to a human" option for human escalation at any time.
- Human Oversight: Merchants can review all automated responses and configure the widget. Customers can request to speak with a human agent at any time.
- No Automated Decisions with Legal Effects: The App does not make decisions that produce legal effects for users.
- Accuracy: We implement quality measures, but cannot guarantee the accuracy of AI-generated content. Merchants are responsible for reviewing automated responses.
Data Breach Notification
In the event of a data breach affecting personal information, we will:
- As a Data Processor: Notify the affected merchant (Data Controller) without undue delay, and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33. The merchant is responsible for notifying the relevant supervisory authority and affected individuals where required.
- Take immediate steps to contain the breach and prevent further data loss
- Provide the merchant with all information necessary to fulfill their notification obligations under GDPR Articles 33 and 34
Geographic Restrictions
This App is not available to users in mainland China. By installing and using this App, you confirm that you are not a resident of or accessing the service from the People's Republic of China (excluding Hong Kong, Macau, and Taiwan). This App has not been registered with Chinese regulatory authorities under the Interim Measures for the Management of Generative Artificial Intelligence Services.
We implement IP-based geographic blocking (Vercel Geo-Location) to prevent access from mainland China IP addresses. Chinese users accessing this service through VPN or proxy do so at their own risk. We do not intentionally provide services to users located in mainland China, and our compliance with Chinese laws is limited to the extent required for offshore services only.
Chinese AI Service Disclaimer
This App uses DeepSeek's AI model (deepseek-chat), a generative AI service that has completed registration with Chinese regulatory authorities in accordance with the Interim Measures for the Management of Generative Artificial Intelligence Services. DeepSeek is a third-party AI service provider and is responsible for its own compliance with Chinese laws and regulations.
This App operates as an offshore service provider and does not offer services to users located in mainland China. Our use of DeepSeek's API is for the purpose of providing customer service automation to international Shopify merchants. We do not control DeepSeek's model training, data processing, or content generation policies. For information about DeepSeek's compliance practices, please refer to DeepSeek's privacy policy and terms of service.
Disclaimer
Important: Parcelglance is an independent third-party application developed by Haimo Tech. It is not affiliated with, endorsed by, or sponsored by Shopify Inc. "Shopify" is a trademark of Shopify Inc. This App uses the Shopify API in accordance with Shopify's API Terms of Service.
Contact
Questions about this privacy policy? Contact us at: privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com)
For Data Processing Agreement requests (EU merchants), please email the above address with "DPA Request" in the subject line.