Privacy Policy
Last updated August 16, 2026 · Dhavira LLC, a North Carolina limited liability company
Early access — Delink is available in selected markets. Features, terms, data handling, and market availability may change before general availability.
We store compliance event metadata (including opaque Shopify IDs and, when needed, a salted hash — not contact fields) and an audit log. Raw webhook bodies are verified in memory only.
Delink is technical tooling for Shopify mandatory compliance webhooks — not legal advice, and not automatic GDPR, CCPA, or CPRA compliance. You remain responsible for fulfilling data requests in your own systems. See also our Terms of Service.
Pre-counsel publication — these documents are not legal advice and have not been reviewed by qualified counsel. They reflect our current operating intent and may change before general availability or after counsel review.
1. Who we are
Delink is a product of Dhavira LLC. This Privacy Policy describes how we handle information when you use the Delink dev console and compliance webhook service.
2. What we collect
Account data — email for sign-in, billing identifiers via Stripe, app name, and Shopify client secret (for HMAC verification only).
Account email, app name, and a valid Shopify client secret are required to provide the contracted Service; without them, you cannot authenticate, register an app, or verify signed webhooks. Billing details are required for paid plans.
Compliance event metadata — operational records when Shopify sends mandatory webhooks to your Delink endpoint. This is not a copy of webhook bodies or a full export of your customers' personal data.
Service and device data — session identifiers, IP address and request metadata, browser/device information, security events, support communications, consent records, and diagnostic logs. Sources include you, your employer or organization, Shopify webhook deliveries, Stripe, security providers, and ordinary use of the Service.
3. What we do not store
We do not persist at rest:
- raw compliance webhook JSON bodies;
- customer names, emails, phones, or mailing addresses from webhooks;
- order line items or other payload copies.
Webhook payloads are processed transiently in memory to verify the signature and extract the metadata specifically listed below, then discarded. Failed verification does not create a durable compliance record.
If you enable Forward, we forward the verified Shopify webhook request to the HTTPS endpoint you specify as a customer-directed transfer. We do not retain the raw body after that processing step; Forward delivery metadata (status, attempt count, truncated upstream errors) may appear in your event log and exports.
4. What we store
For each app and compliance event, we may store:
- Account: email, account ID, subscription tier and status;
- App registration: app name, webhook URL, client secret, creation time;
- Event metadata: topic, shop domain, received and workflow due times, workflow status;
- Shopify resource IDs (when present): opaque identifiers such as
shop_id,customer.id, andorders_to_redact; - Subject hash (optional): salted one-way token derived from a customer email or shop identifier during in-flight processing;
- Application event log: technical actions with timestamps, retained and deleted under the schedule below. It is not cryptographically immutable.
Under laws such as GDPR, some metadata we store — for example shop domain, opaque Shopify resource IDs, or a salted one-way hash derived from a customer email — may still qualify as personal data even though we do not store contact details at rest.
5. Our roles
For account, website, billing, support, and security information, Dhavira LLC generally acts as a controller or business deciding why and how that information is used. For Customer Personal Data contained in compliance events and processed under a customer's instructions, we act as a processor, subprocessor, service provider, or contractor. Our DPA governs that processing. The customer's privacy notice, not this policy, primarily governs its end users' relationship with the customer.
6. Purposes and legal bases
We process information for the following purposes:
- provide accounts, webhook verification, event records, exports, support, and billing (performance of a contract and steps requested before a contract);
- secure, troubleshoot, and monitor the Service; prevent fraud and abuse; communicate service information; and improve the Service using Delink Controller Data or data aggregated or de-identified so it is not reasonably linkable to an individual or customer (our legitimate interests in operating a reliable, secure B2B service, preventing misuse, supporting customers, and understanding service performance, balanced against individual rights);
- maintain tax, transaction, consent, and compliance records and respond to lawful requests (legal obligations); and
- process Customer Personal Data on documented customer instructions (the customer determines the applicable legal basis).
We do not use compliance event metadata for advertising, sell personal information for money, share it for cross-context behavioral advertising, or use it to make decisions producing legal or similarly significant effects about individuals.
7. Recipients and subprocessors
We disclose information only as needed to operate the Service: to personnel and contractors with a need to know; providers for hosting, payments, email, and sign-in security; a successor in a merger, financing, reorganization, or sale; professional advisers; and authorities or others when reasonably necessary to comply with law, protect rights and safety, or investigate abuse. See our Subprocessor list. Some providers, such as payment processors, may also act as independent controllers under their own notices. Delink provides direct email or in-product notice of material subprocessor changes to the account contact and retains delivery evidence where practicable. We provide at least 30 days' notice before an intended subprocessor addition or replacement. Where GDPR requires a processor agreement, our DPA applies when you accept it at checkout. Copy-ready subprocessor language for your app privacy policy is in each app's Setup tab.
8. Retention
During early access, the following retention schedule applies to production compliance events received through the Service. Compliance events remain visible through 90 days after the workflow due date on all plans, then are hidden and queued for deletion by the weekly retention job. Actual deletion can occur on the next successful job run. If your subscription ends, console access is blocked and event data is scheduled for deletion after a 30-day resubscription period. Synthetic events using the dedicated test.myshopify.com test domain are queued after 24 hours; other test scenarios may follow the ordinary schedule until their classification is unified.
- account and app registration data: while the account is active, then as reasonably needed for closure, disputes, security, and legal obligations;
- billing and tax records: generally up to seven years or the period required by applicable law;
- authentication codes: until expiration and routine cleanup; session cookies: until their stated expiry or logout;
- consent records: for the life of the agreement and applicable limitation period;
- support records: until the issue is closed and then as needed for follow-up, disputes, or legal requirements;
- security and diagnostic records: for the shortest period reasonably needed to detect, investigate, and prevent incidents, then deleted or de-identified under the operational logging schedule.
Where encrypted backups exist, deletion from active systems may not immediately remove backup copies. They remain protected and are removed through the configured backup lifecycle; if restored for recovery, deletion controls must be reapplied. Specific periods may be shortened or extended for legal holds, security incidents, or documented customer instructions.
9. Cookies and security
The console uses __delink_session, an HTTP-only authentication cookie lasting up to three days, and __delink_reauth, an HTTP-only cookie lasting up to 12 hours that contains a signed account email to support short-term reauthentication. Browser local storage key delink-theme remembers light or dark appearance. These technologies are used for requested functionality, authentication, and security. Cloudflare Turnstile may process IP address, browser, device, interaction, and security signals when shown. We do not use advertising cookies or respond differently to legacy browser Do Not Track signals; because we do not sell or share personal information for targeted advertising, Global Privacy Control does not change how we process Service data.
We use safeguards designed for the nature of the Service, including TLS, access controls, one-time-code sign-in, secret management, encryption at rest where supported, logging, and data minimization. No method is completely secure. You are responsible for safeguarding your Shopify client secrets and account access and should notify us promptly of suspected compromise.
10. Your privacy rights
Depending on law and context, you may ask to access, know, correct, delete, restrict, or obtain a portable copy of personal data about you; object to or withdraw consent for certain processing; or appeal our response. You may also complain to your local privacy or data protection regulator, including an EU/EEA supervisory authority, the UK Information Commissioner's Office, the Office of the Australian Information Commissioner, the Personal Data Protection Commission of Singapore, the Office of the Privacy Commissioner of Canada, the Data Protection Board of India, or an applicable provincial or U.S. state regulator. Withdrawing consent does not affect earlier lawful processing. We do not discriminate for exercising a privacy right.
Submit a request to support@getdelink.com. We may verify your identity and authority, ask for information needed to locate records, and use an authorized agent where law permits. We will respond within the period required by applicable law. Some information may be exempt or must be retained. If your request concerns an end customer of a Delink customer, contact that merchant or app developer first; when we act as processor, we refer the request to our customer and assist as required by the DPA.
11. United States state disclosures
In the preceding 12 months, we have collected the categories described in §§2–4, including identifiers, commercial/account information, internet or electronic activity, and professional information you provide. We collect, use, retain, and disclose those categories for the purposes in §§6–9 and to the recipients in §7. We do not knowingly sell or share personal information, including information of people under 16, for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about individuals.
Where an applicable U.S. state privacy law grants rights, §10 explains how to exercise them. We act as a service provider or contractor for Customer Personal Data and do not retain, use, or disclose it outside the limited purposes in the DPA except as law permits.
12. Canada
We use contractual and other measures intended to provide comparable protection when Canadian personal information is processed by providers outside Canada. Information processed in another country may be available to courts, law enforcement, or national security authorities under that country's law. Contact us to ask about our practices, challenge their compliance, or exercise applicable access and correction rights. Delink's Privacy Lead is responsible for our privacy program. At this time, the Service is offered only to businesses based in United States, Canada (outside Quebec), Australia, Singapore, New Zealand, Israel, and India. This list reflects our current operating intent and may change before general availability or after counsel review. Businesses based in Quebec, the European Economic Area, the United Kingdom, or Switzerland may not subscribe at this time. Delink has not completed counsel review or the launch requirements for those jurisdictions.
13. Australia, New Zealand, and Singapore
For available markets outside the United States and Canada, the following describes our current practices during early access and may change before general availability.
When we offer the Service to businesses in Australia, New Zealand, or Singapore during early access, we process personal information to provide the contracted Service and for the purposes in §§6–9. Information may be transferred to and processed in the United States and other countries where our providers operate. We use safeguards designed for a B2B subprocessor, including access controls, encryption where supported, and contractual restrictions on provider use. Depending on applicable law, you may have rights to access, correct, or delete personal information about you, to complain to a local regulator, and to receive notice about cross-border disclosure. Submit requests to support@getdelink.com.
14. Israel
During early access, when we offer the Service to businesses in Israel, we process personal information under the contract and for the purposes in §§6–9. Information may be transferred to and processed in the United States and other countries where our providers operate. We apply safeguards appropriate to the nature of the Service. You may contact us to exercise applicable access, correction, or deletion rights or to raise a privacy complaint with us before any applicable regulator.
15. India
During early access, when we offer the Service to businesses in India, we process digital personal data to provide the contracted Service and for the purposes in §§6–9. Information may be transferred to and processed in the United States and other countries where our providers operate, subject to applicable restrictions that the Government of India may notify from time to time. We maintain reasonable security safeguards and use contractual measures with processors. You may contact our Privacy Lead for grievances, corrections, or deletion requests relating to information for which Delink acts as a controller. When we process end-customer information on your instructions, we assist you as processor under the DPA.
16. Service availability and international transfers
At this time, the Service is offered only to businesses based in United States, Canada (outside Quebec), Australia, Singapore, New Zealand, Israel, and India. This list reflects our current operating intent and may change before general availability or after counsel review. Businesses based in Quebec, the European Economic Area, the United Kingdom, or Switzerland may not subscribe at this time. Delink has not completed counsel review or the launch requirements for those jurisdictions. The Service is operated from the United States. If you access Delink from an available market, information may still be transferred to and processed in the U.S. and other countries where our providers operate. If a customer in a blocked jurisdiction attempts to use the Service contrary to these Terms, Delink may suspend or terminate access. Before a restricted EEA, UK, or Swiss transfer that requires contractual safeguards, the customer and Delink must execute a completed transfer addendum as described in the DPA. This online policy and DPA do not by themselves complete the SCC or UK Addendum annexes. We have not appointed an EU or UK representative or a data protection officer; we will do so before processing that requires one.
17. Children and policy changes
The Service is for business users and is not directed to children. We do not knowingly collect account data from anyone under 18. We may update this policy; material changes are posted here with a new effective date and communicated directly by email or in-console notice before taking effect, except urgent legal or security changes may take effect sooner. We will request consent or acknowledgment when required for a new use. If we receive account contact information indirectly from your organization, we make this policy available no later than our first communication where applicable.
18. Contact
Privacy Lead, Dhavira LLC — privacy questions, complaints, and rights requests: support@getdelink.com.
Questions? support@getdelink.com