Privacy Policy

Last updated: 12 August 2026

This policy explains what the Depozy app («the app») accesses, what it stores, and for how long. The app is operated by Mveb. For any question about this policy, write to the address at the bottom of this page.

What the app stores

The app stores one thing: an authentication session for each store that installs it — the store domain and the access token issued by Shopify. This is required to call the Shopify API on the merchant’s behalf.

The app does not store any customer personal data. Names, emails, addresses, order contents and payment details are read from Shopify when a page is opened and are never written to our database.

Payment data

The app never sees, handles or stores card numbers. When a customer pays a deposit, Shopify stores the payment method on its own side and gives the app a reference (a payment mandate). The app uses that reference to ask Shopify to collect the remaining balance according to the schedule the merchant configured. All money movement is performed by Shopify and the store’s payment provider.

What the app reads from Shopify

Sharing

No data is sold, rented or shared with third parties. The app uses no advertising networks and no analytics that identify individuals.

Retention and deletion

When the app is uninstalled, the store session is deleted. Shopify also sends mandatory data-deletion requests 48 hours after uninstall (shop/redact), and on receipt the app deletes everything belonging to that store: sessions, settings, the record of balance charge attempts and the log of reminders sent. Customer deletion requests (customers/redact) are answered as well, though the app holds no customer data to delete.

Service records that reference an order — charge attempts and the reminder log — are kept for at most 90 days after the balance is settled or abandoned, and are then deleted automatically. Unsettled balances are kept until they are resolved: deleting them early would make the app charge the same customer twice.

Security

Data processing agreement

For personal data belonging to a merchant’s customers, the merchant is the data controller and the app is the data processor. By installing the app the merchant accepts this policy as the data processing agreement between us. The app processes that data only to provide the functionality described above, only on the merchant’s instructions, and it engages no sub-processors other than the hosting provider named in the Security section. A merchant who needs a separately signed agreement can request one at the address below.

Security incidents

If personal data is exposed or lost, affected merchants are notified by email within 72 hours of discovery, together with what happened, what data was involved and what was done about it. Shopify is notified in parallel. Access is revoked and credentials rotated first, before any investigation continues.

Contact

Questions, data requests and complaints: support@mveb.org. We reply within two business days.