Wonqy COD App ("the App") is built and operated by Wonqy Media ("Wonqy", "we", "us"). This policy explains what data the App collects when a merchant installs it on their Shopify store, and when that store's customers use the Cash on Delivery / Prepaid checkout popup.
What the App does
The App shows a popup at checkout letting a customer choose Prepaid (normal Shopify checkout) or Cash on Delivery (a deposit + handling fee is collected now via a draft order; the remaining balance is collected on delivery). Merchants configure the deposit amount, handling fee, and popup appearance from the App's Settings page.
Information we collect
From merchants
- Shop domain and an access token issued by Shopify when the App is installed, so we can make API calls to the merchant's store on their behalf. Stored in our database until the App is uninstalled.
- Settings the merchant configures (deposit amount, handling fee, popup text/icons) — these are stored as metafields directly on the merchant's own Shopify store, not in our database.
- Order volume, used solely to calculate the App's own usage-based billing charges through Shopify's Billing API.
From customers
We do not collect or store customer personal information ourselves. When a customer chooses Cash on Delivery, their cart contents and (if available) email address are sent directly to Shopify to create a draft order — this data is stored by Shopify as part of the merchant's own order records, governed by the merchant's own privacy policy and Shopify's terms, not retained in any database we operate.
How we use information
Solely to operate the App: authenticating API requests to the merchant's store, calculating deposits, creating draft orders, and billing merchants for usage. We do not sell data, and we do not use it for advertising.
Third-party service providers
We use the following subprocessors to run the App:
- Shopify — the platform the App operates on and through.
- Vercel — hosts the App's admin interface and backend.
- Prisma Postgres — stores shop session data (access tokens) and Cash on Delivery order counts (timestamps and deposit amounts, no customer information) used for the App's reporting pages and billing.
Data retention & deletion
When a merchant uninstalls the App, their session/access token is deleted immediately, and again — along with the shop's Cash on Delivery order-count records — as a safety check within 48 hours per Shopify's mandatory data-redaction process. Settings stored as shop metafields are the merchant's own store data and are managed by them directly in Shopify admin.
Your rights
If you're a merchant or a customer of a store using this App and want to request access to, correction of, or deletion of any data related to you, contact us at support@wonqymedia.com.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy or the App generally: support@wonqymedia.com.