Privacy Policy
Effective date: 20 August 2026
This Privacy Policy explains how Crovion ("we," "us," "the Company") collects, uses, stores, and discloses personal data through Nucleus by CROVION (the "App"), a Shopify application that helps merchants verify and manage Cash on Delivery ("COD") orders. This policy applies to data processed by the App on behalf of merchants who install it ("Merchants") and their customers ("Customers").
We are a data processor with respect to Merchants' Customer data — we process it on the Merchant's behalf and instructions (see the Merchant Terms of Service and Data Processing Addendum). For Merchant account/staff data, we act as a data controller.
1. Categories of data we process
We distinguish between several categories of data, described in the table below.
| Category | What it includes | Source |
|---|---|---|
| Merchant / staff data | Name, email, and locale of the staff account that installs or accesses the App, via Shopify's own OAuth session (not collected by a custom form). | Shopify OAuth (session) |
| Shop metadata | Store owner name/email, plan name, timezone, currency. | Shopify Admin API, at install/re-auth |
| Order data | Order total, currency, financial status, payment method, customer phone number, shipping pincode/city/state/country, and the full order webhook payload (which may include additional fields such as customer name, email, and address, as sent by Shopify). | Shopify orders/create webhook |
| Checkout data | Checkout funnel steps are recorded two ways: (a) via our Web Pixel, which is strictly anonymous — no email, phone, or consent value is ever recorded from the pixel; and (b) via Shopify's checkouts/create/checkouts/update webhooks, which do carry the customer's email, phone, marketing/SMS-consent flags, order total, and currency. | Shopify Web Pixel + checkout webhooks |
| OTP verification data | A phone number and a one-time verification code. The code itself is never stored — only a cryptographic hash of it. See Section 4. | Customer, at checkout or post-order |
| Shipment / tracking data | Carrier name, tracking number, and fulfillment/delivery-event status. This category contains no customer name, address, or phone number — those fields are deliberately never read from Shopify's fulfillment webhooks. | Shopify fulfillment webhooks |
| Analytics / aggregate data | Dashboard metrics computed from the categories above (e.g. verification rates, order/geography breakdowns, an estimated returned-to-origin figure — see Section 5). | Derived internally |
| Payment data (prepaid orders only) | For Merchants who enable the App's Hosted Checkout (see Section 3) and connect a Razorpay account: the Customer's name, phone, email, and delivery address as entered at checkout; the order amount, currency, and a Razorpay-issued payment/order reference; and the Merchant's own Razorpay API credentials, which we store encrypted at rest. We never receive or store the Customer's card number, UPI ID, or other raw payment-instrument details — those are entered directly into Razorpay's own hosted payment widget, which runs in the Customer's browser and communicates with Razorpay, not with our servers. | Customer, at Hosted Checkout; Razorpay, via webhook |
2. Why we process this data
- Order data and OTP verification data are used to confirm genuine COD orders with the Customer before dispatch, and to give the Merchant a workflow for tracking that confirmation.
- Checkout data is used to show the Merchant checkout-funnel analytics, and — only where the Customer has given Shopify-recorded marketing/SMS consent — to trigger an abandoned-checkout recovery message. See Section 6.
- Shipment/tracking data is used to show the Merchant courier performance and a delivery-status timeline for each order.
- Shop and staff data is used to operate the Merchant's account and authenticate access to the App.
- Analytics/aggregate data is shown to the Merchant in their dashboard to help them understand COD performance.
3. Checkout — two real checkout paths, depending on what the Merchant enables
The App can operate in either or both of the following ways, depending on which features a Merchant has enabled on their store. This section describes both honestly and precisely — neither is hidden or described as something it is not.
Native Shopify Checkout (Checkout Extensibility). A Checkout Validation Function can block checkout when a Merchant's COD rules match, and a Payment Customization Function can hide the COD payment option as a secondary convenience. A Checkout UI Extension may also collect and verify a one-time code from the Customer during checkout (see Section 4). In this path, all checkout activity takes place inside Shopify's own standard, Shopify-hosted checkout — the App only reads and validates data Shopify's own checkout surface exposes to it, and never redirects the Customer away from it.
App Hosted Checkout. Separately, a Merchant may enable a theme app embed that we provide. When enabled, this embed intercepts the storefront's Buy Now and/or Checkout button and redirects the Customer to a checkout experience the App itself hosts and controls, loaded through the Merchant's own store domain (via Shopify's App Proxy mechanism, so the address bar the Customer sees stays on the Merchant's own domain). In this path, the App — not Shopify's native checkout — directly collects the Customer's phone number, delivery address, and (where offered) a discount code and upsell selection, runs OTP verification, and processes the order. For a prepaid order, the Customer enters their payment details directly into Razorpay's own hosted payment widget (see the Payment data row in Section 1) — the App never receives or stores raw card, UPI, or bank-account details. Once payment is confirmed (for prepaid orders) or immediately (for Cash on Delivery orders), the App creates the real order in the Merchant's Shopify store via Shopify's own Admin API, the same order-creation mechanism Shopify itself documents for orders originating outside its native checkout. From that point forward, the order is handled identically to any other Shopify order — the same webhooks, fulfillment flow, and dashboard reporting described elsewhere in this policy apply.
A Merchant using App Hosted Checkout is not required to disable the Checkout Extensibility features described above, and both may be present on the same store; which checkout experience an individual Customer actually reaches depends on the Merchant's own theme and app configuration.
4. OTP verification — two distinct flows
We operate two separate one-time-password ("OTP") verification flows, both used solely to confirm that the phone number placing a COD order is genuine:
- Post-order OTP: after Shopify creates the order, we may send a verification code by SMS and/or WhatsApp to the phone number on the order, and ask the Customer to confirm it.
- Checkout-time OTP: during checkout itself, the Checkout UI Extension may read the phone number the Customer has entered and send a verification code before the order is placed.
In both flows, the verification code is never stored in plain text — only a salted cryptographic hash of it is kept, so that even we cannot read back an issued code.
5. Automated processing — no per-customer AI risk prediction
6. Marketing and SMS/WhatsApp consent
Where a Customer has provided marketing and/or SMS marketing consent through Shopify's own checkout (recorded by Shopify and passed to us via webhook), and has provided a phone number, we may use that consent to send an abandoned-checkout recovery message by SMS and WhatsApp. We do not collect this consent ourselves — we rely on the consent state Shopify reports.
Limitation: this App does not currently maintain its own STOP/opt-out registry for WhatsApp messages. We cannot detect or suppress a reply such as "STOP" sent directly to a WhatsApp message outside of Shopify's own consent records. If a Customer's consent is withdrawn or updated through Shopify (including via the Merchant's store), that updated state is what we act on going forward. Customers who wish to stop receiving these messages should contact the Merchant directly.
7. Data retention
- Most operational records (orders, checkout events, notification records, and several internal audit/decision logs) are retained for 90 days by default, after which they are automatically purged.
- A one-time verification code's supporting data is redacted immediately once that notification reaches a final state (sent, delivered, bounced, or failed) — sooner than the general 90-day window.
- When a Merchant uninstalls the App, we retain their data for a further 30 days (a grace period, in case of accidental uninstall/reinstall), after which all remaining data for that store is automatically and permanently deleted.
- Shipment/tracking records and aggregate marketing-channel/campaign records, which contain no personal data, are kept indefinitely for historical business reporting.
8. Third-party service providers
We use the following third-party services to operate the App. We do not sell personal data.
| Provider | Purpose |
|---|---|
| Shopify | The commerce platform the App is built on; source of all order/checkout/fulfillment data. |
| Twilio | Delivery of SMS messages (OTP codes, order confirmations, abandoned-checkout recovery). |
| Meta (WhatsApp Cloud API) | Delivery of WhatsApp messages (OTP codes, order confirmations, abandoned-checkout recovery). |
| Neon | Cloud PostgreSQL database hosting for all data described in this policy. |
We do not currently send data to any advertising or analytics platform (such as Meta Ads, Google Ads, TikTok Ads, or GA4) — those integrations are not active in the App today.
9. Data security
One-time verification codes are never stored in plain text — only a salted HMAC-SHA256 hash. Inbound messages from Twilio and Meta are verified using their respective request signatures before being trusted. Shopify access tokens are stored using Shopify's own official session-storage mechanism. We do not claim any specific third-party security certification (e.g. SOC 2, ISO 27001) at this time.
10. Your rights and how to exercise them
Customers may request access to, or deletion of, their personal data. Because this App identifies Customers primarily by phone number, we ask that any request include the phone number used at checkout so we can locate the relevant records. These requests can be submitted to the Merchant, who can relay them to us, or directly to contact@crovion.com. We also automatically process Shopify's standard data-request, redaction, and shop-redaction webhooks.
11. Children's privacy
The App is intended for use by Merchants operating commercial online stores and their adult Customers, and is not directed at children.
12. International data transfers
We are based in India, and Customer personal data may be processed outside India through our third-party service providers (Shopify, Twilio, Meta, and Neon — see Section 8), each located and operating in jurisdictions other than India. Where such transfers occur, we rely on the lawful basis available under applicable Indian data protection law for transferring personal data outside India, together with the international-transfer safeguards each provider makes available under its own published terms:
- Shopify — Standard Contractual Clauses (European Commission-approved modules) and Shopify's own Binding Corporate Rules, under Shopify's Data Processing Addendum.
- Twilio — Standard Contractual Clauses (all three EU modules), together with Twilio's EU–US Data Privacy Framework self-certification and Binding Corporate Rules, under Twilio's Data Protection Addendum.
- Meta (WhatsApp Cloud API) — Standard Contractual Clauses and Meta's own Global Data Transfer Addendum, under Meta's Platform Terms.
- Neon — Standard Contractual Clauses (European Commission-approved), under the Data Processing Addendum of Databricks (Neon's parent company since its acquisition by Databricks).
These reflect each provider's own published terms as of the effective date of this policy and may change; we do not control, and have not independently audited, our providers' compliance with their own stated mechanisms.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above.
14. Contact us
Crovion
118 B-3, Shahpur Jat, New Delhi - 110049, India
General contact: contact@crovion.com
Privacy contact: contact@crovion.com
Governing law: the laws of India, subject to the exclusive jurisdiction of the courts located in Firozabad, Uttar Pradesh, India.