Privacy Policy

DispatchIQ — Last updated: August 24, 2026

DispatchIQ ("the App", "we", "us") is a Shopify app that helps merchants dispatch orders through India Post's Contract Business Parcel service — syncing orders, generating shipping labels, and tracking delivery status. This policy explains what data we collect through the App, why, and how it's handled.

1. Information we collect

When a merchant installs DispatchIQ and connects a Shopify store, we access and store the following categories of data, limited to what's needed to book and track shipments:

CategoryExamplesSource
Order & fulfillment dataOrder number, line items, fulfillment statusShopify Admin API / webhooks
Customer shipping detailsName, phone number, shipping addressShopify order data
Store & account dataShop domain, access token, merchant's phone number/email used to log into DispatchIQShopify OAuth, Firebase Authentication
Parcel & dispatch recordsWeight, dimensions, barcode, India Post booking status, tracking eventsEntered by merchant / India Post
ContactsName, phone number, source (e.g. "Order", "Import")Auto-created from orders or manually added/imported by merchant
Billing dataSubscription tier, payment statusRazorpay (we do not store card/bank details — Razorpay processes and stores these directly)

2. How we use this information

We do not sell, rent, or use merchant or customer data for advertising, marketing to third parties, or any purpose unrelated to operating the App.

3. Who we share data with

We do not share data with any other third party.

4. Data retention

Order, parcel, and contact data is retained for as long as the merchant's account remains active, so the merchant can reference past dispatches. If a merchant uninstalls the App, we stop receiving new data from that store; a merchant can request deletion of their stored data at any time by contacting us (see Section 7).

5. Data security

Data is stored in Firestore behind security rules that scope every merchant's records to their own account, and Shopify API access tokens are stored server-side only, never exposed to the browser. Cloud Functions handling sensitive operations run under Google Cloud's managed infrastructure.

6. Merchant and customer rights

Merchants can access, export, or delete the parcel, contact, and order data associated with their account by contacting us. End customers whose shipping details pass through the App as part of an order should direct data requests to the merchant's store, who can in turn contact us to fulfill deletion or access requests on the customer's behalf.

7. Contact us

Questions about this policy or data requests can be sent to: yathustales@gmail.com

8. Changes to this policy

We may update this policy as the App's functionality changes. Material changes will be reflected by updating the "Last updated" date above.