Privacy Policy

Widerruf: EU Withdrawal Button · Last updated 4 July 2026

Operator to complete before publishing: replace [COMPANY_NAME], [COMPANY_ADDRESS], and [COUNTRY] below with your legal details.

This Privacy Policy explains how [COMPANY_NAME] ("we", "us", "the operator") handles personal data when a merchant installs the Widerruf: EU Withdrawal Button app (the "App") on their Shopify store, and when a customer of that store uses the withdrawal form the App provides.

For a store's customers, the merchant (the store owner) is the data controller and we act as a data processor on the merchant's behalf. We only process personal data to provide the App's functionality described below.

1. Who we are

The App is operated by [COMPANY_NAME], [COMPANY_ADDRESS], [COUNTRY]. Contact: support@widerruf.onkra.online.

2. What data we process, and why

We deliberately collect the minimum data needed to record and confirm an EU right-of-withdrawal request (EU Directive 2023/2673, Art. 11a CRD) and to act on it for the merchant.

Data submitted by a store's customer via the withdrawal form

DataPurpose
NameLegally required content of the withdrawal declaration; identifies the request.
Email addressTo send the customer a durable-medium confirmation and the merchant's accept/reject decision; to match the request to the correct order.
Order number (optional)To link the withdrawal to the correct Shopify order.
Item / service description & optional reasonTo record what is being withdrawn and (in aggregate) to show the merchant withdrawal insights.
IP address & browser user-agentSecurity and audit metadata proving when and from where the request was received; anti-abuse.

Order data accessed from the Shopify store (on the merchant's behalf)

To validate and act on a withdrawal, the App reads limited order data (order number, contact email, fulfillment status) and, where the merchant enables it, cancels the order and issues a refund through Shopify's API. We access order/customer data only for these purposes and do not use it for profiling, advertising, or any unrelated purpose.

Merchant account data

When a merchant installs the App we store the store domain, an access token, and app settings needed to run the App.

3. Legal bases (GDPR)

4. What we do not do

5. Sharing & subprocessors

We share personal data only with the service providers needed to run the App:

SubprocessorPurpose
Application hosting providerRuns the App server and database.
Email delivery (SMTP) providerSends confirmation and decision emails to customers.
Content-delivery / DNS providerServes the App securely over HTTPS.
ShopifyThe platform the merchant's store runs on.

6. Storage, security & location

7. Retention & deletion

We retain a withdrawal record while the merchant has the App installed and for as long as needed to evidence compliance. We delete data:

8. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. As we act on the merchant's behalf, please contact the store first; you may also contact us at support@widerruf.onkra.online and we will assist the merchant in fulfilling the request. You may also lodge a complaint with your local data protection authority.

9. Children

The App is not directed to children and we do not knowingly process children's data.

10. Changes

We may update this policy; the "last updated" date above reflects the current version. Material changes will be communicated to merchants.

11. Contact

[COMPANY_NAME], [COMPANY_ADDRESS], [COUNTRY] · support@widerruf.onkra.online