DispatchIQ ("the App", "we", "us") is a Shopify app that helps merchants dispatch orders through India Post's Contract Business Parcel service — syncing orders, generating shipping labels, and tracking delivery status. This policy explains what data we collect through the App, why, and how it's handled.
When a merchant installs DispatchIQ and connects a Shopify store, we access and store the following categories of data, limited to what's needed to book and track shipments:
| Category | Examples | Source |
|---|---|---|
| Order & fulfillment data | Order number, line items, fulfillment status | Shopify Admin API / webhooks |
| Customer shipping details | Name, phone number, shipping address | Shopify order data |
| Store & account data | Shop domain, access token, merchant's phone number/email used to log into DispatchIQ | Shopify OAuth, Firebase Authentication |
| Parcel & dispatch records | Weight, dimensions, barcode, India Post booking status, tracking events | Entered by merchant / India Post |
| Contacts | Name, phone number, source (e.g. "Order", "Import") | Auto-created from orders or manually added/imported by merchant |
| Billing data | Subscription tier, payment status | Razorpay (we do not store card/bank details — Razorpay processes and stores these directly) |
We do not sell, rent, or use merchant or customer data for advertising, marketing to third parties, or any purpose unrelated to operating the App.
We do not share data with any other third party.
Order, parcel, and contact data is retained for as long as the merchant's account remains active, so the merchant can reference past dispatches. If a merchant uninstalls the App, we stop receiving new data from that store; a merchant can request deletion of their stored data at any time by contacting us (see Section 7).
Data is stored in Firestore behind security rules that scope every merchant's records to their own account, and Shopify API access tokens are stored server-side only, never exposed to the browser. Cloud Functions handling sensitive operations run under Google Cloud's managed infrastructure.
Merchants can access, export, or delete the parcel, contact, and order data associated with their account by contacting us. End customers whose shipping details pass through the App as part of an order should direct data requests to the merchant's store, who can in turn contact us to fulfill deletion or access requests on the customer's behalf.
Questions about this policy or data requests can be sent to: yathustales@gmail.com
We may update this policy as the App's functionality changes. Material changes will be reflected by updating the "Last updated" date above.