TrackBridge
Features Pricing FAQ Support Open app
Privacy

Privacy Policy

How TrackBridge handles website, merchant, Shopify order, fulfillment, shipment tracking, billing, and support data.

Effective date

18 July 2026

Privacy questions:
info@trackbridge.de

Read-only workflowTrackBridge does not change orders, fulfillments, or shipment details in Shopify.
Minimal order fieldsThe tracking-health workflow focuses on order, fulfillment, carrier, and tracking status.
No ad trackingThe public website does not load advertising or behavioral analytics cookies.

1. Controller and service provider

Banida Shops UG, Sophie-Schoop-Weg 72, 21035 Hamburg, Germany, represented by Niklas Alexander Kather. Email: info@trackbridge.de.

For public-site and account administration data, we act as controller. When processing Shopify data on a merchant’s instructions, the merchant generally remains controller and we act as processor where applicable.

2. Data we process

  • Shop and installation: shop domain and name, encrypted Shopify access token, granted scopes, installation state, locale, plan, subscription and usage status.
  • Order and fulfillment: Shopify order identifiers and number, creation date, fulfillment status, carrier name, tracking number, tracking-health state, and latest synchronization time.
  • Operational records: lookback configuration, automatic-check preference, synchronization runs, counts, minimized webhook delivery records, status messages, and timestamps.
  • Support and technical data: name, email, shop URL, request content, IP address, user agent, application logs, error and security events.

3. Purposes and legal bases

  • Providing installation, authentication, tracking-health checks, plan management and support (Art. 6(1)(b) GDPR).
  • Protecting the service, preventing misuse, troubleshooting, webhook processing and maintaining reliable operations (Art. 6(1)(f) GDPR).
  • Accounting, legal obligations and defense of claims (Art. 6(1)(c) and (f) GDPR).
  • Optional processing based on consent, where expressly requested (Art. 6(1)(a) GDPR).

For Shopify order data processed on a merchant’s instructions, the merchant determines the legal basis and is responsible for notices to affected individuals.

4. Recipients and international transfers

Data is shared only with providers needed to operate the service, including Shopify and contracted hosting, email, logging, and infrastructure providers. We do not sell personal data.

Where a recipient is outside the EEA, we rely on an applicable adequacy decision, approved safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism.

5. Cookies and local storage

The public website does not use advertising or behavioral analytics trackers. Technically necessary storage may be used for sessions, form security, and remembering that the cookie notice was acknowledged.

StoragePurposeTypical durationCategory
Laravel session cookieSession continuity, form validation and security.Session or configured session lifetime.Strictly necessary
XSRF security token, when setProtects form submissions against cross-site request forgery.Session-related.Strictly necessary
trackbridge_cookie_notice_v1Remembers that the information banner was acknowledged.Until browser storage is cleared.Strictly necessary preference

6. Retention and deletion

Order tracking-health records are limited to the configured lookback and are automatically removed after no more than 60 days. Webhook delivery records are removed after 30 days and synchronization-run metadata after 90 days. Shopify access is revoked on uninstall, store records are erased on a valid shop-redaction webhook, and affected order records are deleted on verified customer-redaction requests. Statutory business records may be retained for the legally required period. Backup copies expire through the applicable backup cycle.

7. Security

We use safeguards appropriate to the risk, including encrypted transport, access controls, encrypted storage for secrets, signed webhook validation, logging, data minimization, and merchant-data separation. No internet service can guarantee absolute security.

8. Your rights

Subject to the GDPR, individuals may request access, rectification, erasure, restriction, portability, or object to certain processing. They may also complain to a competent supervisory authority. Requests concerning customer data held for a merchant should first be directed to that merchant; we assist merchants with verified requests.

We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

9. Changes

We may update this policy when the service, providers, or law changes. The current effective date is shown above. Material changes affecting existing merchants will be communicated through an appropriate channel.

TrackBridge

Fulfillment and shipment tracking clarity inside Shopify. © 2026 Banida Shops UG.

Terms Privacy Imprint Support
Privacy by default

We use only technically necessary session and security storage. No advertising or analytics cookies are set. Details