Widerruf: EU Withdrawal Button · Last updated 4 July 2026
[COMPANY_NAME],
[COMPANY_ADDRESS], and [COUNTRY] below with your legal details.This Privacy Policy explains how [COMPANY_NAME] ("we", "us", "the operator") handles personal data when a merchant installs the Widerruf: EU Withdrawal Button app (the "App") on their Shopify store, and when a customer of that store uses the withdrawal form the App provides.
For a store's customers, the merchant (the store owner) is the data controller and we act as a data processor on the merchant's behalf. We only process personal data to provide the App's functionality described below.
The App is operated by [COMPANY_NAME], [COMPANY_ADDRESS], [COUNTRY]. Contact: support@widerruf.onkra.online.
We deliberately collect the minimum data needed to record and confirm an EU right-of-withdrawal request (EU Directive 2023/2673, Art. 11a CRD) and to act on it for the merchant.
| Data | Purpose |
|---|---|
| Name | Legally required content of the withdrawal declaration; identifies the request. |
| Email address | To send the customer a durable-medium confirmation and the merchant's accept/reject decision; to match the request to the correct order. |
| Order number (optional) | To link the withdrawal to the correct Shopify order. |
| Item / service description & optional reason | To record what is being withdrawn and (in aggregate) to show the merchant withdrawal insights. |
| IP address & browser user-agent | Security and audit metadata proving when and from where the request was received; anti-abuse. |
To validate and act on a withdrawal, the App reads limited order data (order number, contact email, fulfillment status) and, where the merchant enables it, cancels the order and issues a refund through Shopify's API. We access order/customer data only for these purposes and do not use it for profiling, advertising, or any unrelated purpose.
When a merchant installs the App we store the store domain, an access token, and app settings needed to run the App.
We share personal data only with the service providers needed to run the App:
| Subprocessor | Purpose |
|---|---|
| Application hosting provider | Runs the App server and database. |
| Email delivery (SMTP) provider | Sends confirmation and decision emails to customers. |
| Content-delivery / DNS provider | Serves the App securely over HTTPS. |
| Shopify | The platform the merchant's store runs on. |
We retain a withdrawal record while the merchant has the App installed and for as long as needed to evidence compliance. We delete data:
customers/redact webhook;shop/redact webhook;Depending on your jurisdiction you may have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. As we act on the merchant's behalf, please contact the store first; you may also contact us at support@widerruf.onkra.online and we will assist the merchant in fulfilling the request. You may also lodge a complaint with your local data protection authority.
The App is not directed to children and we do not knowingly process children's data.
We may update this policy; the "last updated" date above reflects the current version. Material changes will be communicated to merchants.
[COMPANY_NAME], [COMPANY_ADDRESS], [COUNTRY] · support@widerruf.onkra.online