Nucleus by CROVION

Privacy Policy

Effective date: 20 August 2026

This Privacy Policy explains how Crovion ("we," "us," "the Company") collects, uses, stores, and discloses personal data through Nucleus by CROVION (the "App"), a Shopify application that helps merchants verify and manage Cash on Delivery ("COD") orders. This policy applies to data processed by the App on behalf of merchants who install it ("Merchants") and their customers ("Customers").

We are a data processor with respect to Merchants' Customer data — we process it on the Merchant's behalf and instructions (see the Merchant Terms of Service and Data Processing Addendum). For Merchant account/staff data, we act as a data controller.

1. Categories of data we process

We distinguish between several categories of data, described in the table below.

CategoryWhat it includesSource
Merchant / staff dataName, email, and locale of the staff account that installs or accesses the App, via Shopify's own OAuth session (not collected by a custom form).Shopify OAuth (session)
Shop metadataStore owner name/email, plan name, timezone, currency.Shopify Admin API, at install/re-auth
Order dataOrder total, currency, financial status, payment method, customer phone number, shipping pincode/city/state/country, and the full order webhook payload (which may include additional fields such as customer name, email, and address, as sent by Shopify).Shopify orders/create webhook
Checkout dataCheckout funnel steps are recorded two ways: (a) via our Web Pixel, which is strictly anonymous — no email, phone, or consent value is ever recorded from the pixel; and (b) via Shopify's checkouts/create/checkouts/update webhooks, which do carry the customer's email, phone, marketing/SMS-consent flags, order total, and currency.Shopify Web Pixel + checkout webhooks
OTP verification dataA phone number and a one-time verification code. The code itself is never stored — only a cryptographic hash of it. See Section 4.Customer, at checkout or post-order
Shipment / tracking dataCarrier name, tracking number, and fulfillment/delivery-event status. This category contains no customer name, address, or phone number — those fields are deliberately never read from Shopify's fulfillment webhooks.Shopify fulfillment webhooks
Analytics / aggregate dataDashboard metrics computed from the categories above (e.g. verification rates, order/geography breakdowns, an estimated returned-to-origin figure — see Section 5).Derived internally
Payment data (prepaid orders only)For Merchants who enable the App's Hosted Checkout (see Section 3) and connect a Razorpay account: the Customer's name, phone, email, and delivery address as entered at checkout; the order amount, currency, and a Razorpay-issued payment/order reference; and the Merchant's own Razorpay API credentials, which we store encrypted at rest. We never receive or store the Customer's card number, UPI ID, or other raw payment-instrument details — those are entered directly into Razorpay's own hosted payment widget, which runs in the Customer's browser and communicates with Razorpay, not with our servers.Customer, at Hosted Checkout; Razorpay, via webhook

2. Why we process this data

3. Checkout — two real checkout paths, depending on what the Merchant enables

The App can operate in either or both of the following ways, depending on which features a Merchant has enabled on their store. This section describes both honestly and precisely — neither is hidden or described as something it is not.

Native Shopify Checkout (Checkout Extensibility). A Checkout Validation Function can block checkout when a Merchant's COD rules match, and a Payment Customization Function can hide the COD payment option as a secondary convenience. A Checkout UI Extension may also collect and verify a one-time code from the Customer during checkout (see Section 4). In this path, all checkout activity takes place inside Shopify's own standard, Shopify-hosted checkout — the App only reads and validates data Shopify's own checkout surface exposes to it, and never redirects the Customer away from it.

App Hosted Checkout. Separately, a Merchant may enable a theme app embed that we provide. When enabled, this embed intercepts the storefront's Buy Now and/or Checkout button and redirects the Customer to a checkout experience the App itself hosts and controls, loaded through the Merchant's own store domain (via Shopify's App Proxy mechanism, so the address bar the Customer sees stays on the Merchant's own domain). In this path, the App — not Shopify's native checkout — directly collects the Customer's phone number, delivery address, and (where offered) a discount code and upsell selection, runs OTP verification, and processes the order. For a prepaid order, the Customer enters their payment details directly into Razorpay's own hosted payment widget (see the Payment data row in Section 1) — the App never receives or stores raw card, UPI, or bank-account details. Once payment is confirmed (for prepaid orders) or immediately (for Cash on Delivery orders), the App creates the real order in the Merchant's Shopify store via Shopify's own Admin API, the same order-creation mechanism Shopify itself documents for orders originating outside its native checkout. From that point forward, the order is handled identically to any other Shopify order — the same webhooks, fulfillment flow, and dashboard reporting described elsewhere in this policy apply.

A Merchant using App Hosted Checkout is not required to disable the Checkout Extensibility features described above, and both may be present on the same store; which checkout experience an individual Customer actually reaches depends on the Merchant's own theme and app configuration.

4. OTP verification — two distinct flows

We operate two separate one-time-password ("OTP") verification flows, both used solely to confirm that the phone number placing a COD order is genuine:

In both flows, the verification code is never stored in plain text — only a salted cryptographic hash of it is kept, so that even we cannot read back an issued code.

5. Automated processing — no per-customer AI risk prediction

The App's dashboard shows an estimated number of returned-to-origin ("RTO") orders avoided. This is calculated by multiplying verified-order counts/value by a fixed, documented assumed baseline rate (currently 20%). It is a general business-reporting estimate, not a per-customer prediction and not produced by a machine-learning or AI risk-scoring model. We do not use this figure, or any automated profiling, to make a decision about an individual Customer.

6. Marketing and SMS/WhatsApp consent

Where a Customer has provided marketing and/or SMS marketing consent through Shopify's own checkout (recorded by Shopify and passed to us via webhook), and has provided a phone number, we may use that consent to send an abandoned-checkout recovery message by SMS and WhatsApp. We do not collect this consent ourselves — we rely on the consent state Shopify reports.

Limitation: this App does not currently maintain its own STOP/opt-out registry for WhatsApp messages. We cannot detect or suppress a reply such as "STOP" sent directly to a WhatsApp message outside of Shopify's own consent records. If a Customer's consent is withdrawn or updated through Shopify (including via the Merchant's store), that updated state is what we act on going forward. Customers who wish to stop receiving these messages should contact the Merchant directly.

7. Data retention

8. Third-party service providers

We use the following third-party services to operate the App. We do not sell personal data.

ProviderPurpose
ShopifyThe commerce platform the App is built on; source of all order/checkout/fulfillment data.
TwilioDelivery of SMS messages (OTP codes, order confirmations, abandoned-checkout recovery).
Meta (WhatsApp Cloud API)Delivery of WhatsApp messages (OTP codes, order confirmations, abandoned-checkout recovery).
NeonCloud PostgreSQL database hosting for all data described in this policy.

We do not currently send data to any advertising or analytics platform (such as Meta Ads, Google Ads, TikTok Ads, or GA4) — those integrations are not active in the App today.

9. Data security

One-time verification codes are never stored in plain text — only a salted HMAC-SHA256 hash. Inbound messages from Twilio and Meta are verified using their respective request signatures before being trusted. Shopify access tokens are stored using Shopify's own official session-storage mechanism. We do not claim any specific third-party security certification (e.g. SOC 2, ISO 27001) at this time.

10. Your rights and how to exercise them

Customers may request access to, or deletion of, their personal data. Because this App identifies Customers primarily by phone number, we ask that any request include the phone number used at checkout so we can locate the relevant records. These requests can be submitted to the Merchant, who can relay them to us, or directly to contact@crovion.com. We also automatically process Shopify's standard data-request, redaction, and shop-redaction webhooks.

11. Children's privacy

The App is intended for use by Merchants operating commercial online stores and their adult Customers, and is not directed at children.

12. International data transfers

We are based in India, and Customer personal data may be processed outside India through our third-party service providers (Shopify, Twilio, Meta, and Neon — see Section 8), each located and operating in jurisdictions other than India. Where such transfers occur, we rely on the lawful basis available under applicable Indian data protection law for transferring personal data outside India, together with the international-transfer safeguards each provider makes available under its own published terms:

These reflect each provider's own published terms as of the effective date of this policy and may change; we do not control, and have not independently audited, our providers' compliance with their own stated mechanisms.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above.

14. Contact us

Crovion
118 B-3, Shahpur Jat, New Delhi - 110049, India
General contact: contact@crovion.com
Privacy contact: contact@crovion.com
Governing law: the laws of India, subject to the exclusive jurisdiction of the courts located in Firozabad, Uttar Pradesh, India.