Who we are
GODROPIFY LIMITED, company number 81247524, registered at Room 5042, 5/F, Yau Lee Centre, No.45 Hoi Yuen Road, Kwun Tong, Kowloon, Hong Kong and operating from Shenzhen, China. For questions about your data: privacy@godropify.com.
Your data, as our client
For your own account we hold:
- Name, email address, company name and the contact handle you gave us.
- What you told us on your application: store URL, order volume, current supplier, what goes wrong there, and the product links you sent.
- Your orders, quotes, balance movements and the messages between us.
- Technical records of signing in — timestamps and the fact that a session existed.
We hold this because we need it to do the work you have asked us to do, and because we are required to keep commercial and payment records. We do not sell it, and we do not use it to advertise to you.
Your customers’ data
To ship a parcel we receive the recipient’s name, delivery address, and sometimes a phone number or email address for the carrier. On this data you are the controller and we are the processor: it is your relationship with your customer, and we act on your instructions.
- We use it only to source, pack, ship and track the order.
- We pass it to the carrier, because a parcel cannot be delivered otherwise, and to customs where the destination country requires it.
- We do not contact your customers. We do not market to them. We do not keep a list of them for any purpose of our own.
- We delete it when you close your account, or earlier on your instruction, subject to the retention periods below.
We never receive your customers’ payment details. The permissions we ask for on your Shopify store do not include them, and you can see exactly which permissions those are before you grant them.
Who else sees any of this
- Carriers — name, address and contact details for the parcel they are delivering.
- Customs authorities — what the destination country requires on the declaration.
- Suppliers — the product and quantity. Suppliers do not receive your customers’ details and do not ship directly to them.
- Our hosting and database provider — the servers this portal runs on, in the European Union.
- Payment providers — when you pay by card or link, that provider handles the payment and we see only that it happened.
We do not sell personal data to anyone, and we have no advertising partners.
Where the data sits
The portal database is hosted in Frankfurt, Germany. Our staff work from Shenzhen, China, and can reach the data they need for their role from there — which means data is transferred outside the EEA. Employees see only what their role requires: warehouse and purchasing staff can see an order and an address, and cannot see your balance, your margins, or what we paid a supplier.
How long we keep it
- Order and shipping records: seven years, because tax and customs rules require it.
- Quality control photographs: twelve months.
- Account and contact details: while your account is open, and seven years afterwards for the commercial record.
- Applications that we declined: twelve months, then deleted.
Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Write to privacy@godropify.com and we will answer within thirty days.
If your customer asks you to delete their data, tell us and we will delete it from our systems except where a shipping or tax record must be kept.
Cookies
The portal sets a cookie to keep you signed in, a short-lived cookie for the security check on the sign-in screen, and — if you start an application on the website — a half-hour cookie carrying your answers to the registration screen so you do not have to type them twice. That is the complete list. There is no analytics or advertising tracking on this site.
Security
Access to client data is enforced in the database itself rather than only in the interface, so a mistake in a screen cannot expose one client’s data to another. The access tokens you give us for your store are encrypted before they are stored and cannot be read back through the portal by anyone, including us. Changes to payment details are logged with the old value, the new value and who made the change.
If a breach affects your data, we will tell you what happened, what was exposed and what we did about it — without waiting to be asked.
