> For the complete documentation index, see [llms.txt](https://appsetup-eng.gitbook.io/pickup-points/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://appsetup-eng.gitbook.io/pickup-points/privacy-policy.md).

# Privacy Policy

Last Updated: 28.07.2026

### Introduction

This Privacy Policy explains how Appsetup Eng. (“we”, “us”, “our”) collects, uses, protects, and shares data for **Pickup Points & Lockers by Appsetup** (the “App”).

By installing or using the App, you (“Merchant”, “User”, “you”) consent to the practices described here. If you do not agree, do not install or use the App.

### Data Collected

**Merchant/Store Data:** Shop ID, shop domain, app installation status, app settings, enabled couriers, country settings, shipping-zone mappings, Shopify shipping-rate mappings, feature states, plan status, usage limits, and operational settings needed to run the App.

**Customer Contact Data:** Email address, first name, last name, and phone number when the customer enters these details in the pre-checkout pickup form or when Shopify makes them available for the delivery flow.

**Customer Delivery Data:** Delivery country, city, address, postal code, selected delivery type, selected courier, selected pickup office, pickup point, parcel shop, locker, or address-delivery details.

**Cart, Checkout, And Order Data:** Cart context, checkout context, order references, selected courier/location data, and related attributes or metadata needed to pass the selected delivery option into Shopify checkout, support order handling, and count usage for billing limits.

**Courier Location Data:** Cached pickup-point data used by the App, such as provider code, external location ID, location name, address, city, postal code, coordinates, location type, active status, and source metadata. This data may come from public, authorized, merchant-provided, or credentialed provider sources.

**Technical/Operational Signals:** Non-personal diagnostics, request timing, sync status, sync errors, endpoint errors, rate-limit events, and basic logs used to maintain reliability, security, and performance.

**Optional Integration Data:** If optional courier APIs, provider feeds, or integrations are enabled, any keys, tokens, file paths, or configuration values you provide are used only for the features you activate.

### Storage & Protection

**App Database Storage:** The App stores configuration, courier mappings, cached pickup locations, pickup selections, usage counters, and operational records in the App database or Shopify resources as required for functionality.

**Shopify Storage:** Some selected delivery details may be saved into Shopify cart attributes, checkout fields, order data, metafields, or other Shopify resources where Shopify allows it.

**Location Data Protection:** Storefront JavaScript and CSS are public by design. The App protects location data through backend controls, including Shopify-signed proxy requests, cart-scoped location tokens, country/courier/type checks, capped responses, single-point detail requests, rate limits, and server-side syncs.

**Limited Storefront Exposure:** The storefront does not receive the full pickup-location database at once. Map and list requests return limited data needed for customer selection. Full details for a pickup point are returned only when a customer selects that specific location.

**Security Measures:** We apply reasonable technical and organizational safeguards designed to protect App data. No method of transmission or storage is 100% secure. You control Shopify user access, staff permissions, app permissions, and any provider credentials you add.

**Retention:** App configuration and operational data remain while the App is installed and needed to provide the service. Cached courier locations may remain until replaced, resynced, disabled, or removed. Customer-related pickup selections may remain in Shopify order records according to Shopify and merchant retention settings.

### Use Of Data

**Core Functionality:** Show the pre-checkout pickup form, display available courier offices and lockers, allow location search and selection, pass selected delivery information into Shopify checkout, and connect customer selections to the correct Shopify shipping rates.

**Courier Configuration:** Enable merchants to configure couriers by country, delivery type, and Shopify shipping-rate mapping.

**Checkout And Order Handling:** Save or pass selected courier, location, address, city, postal code, phone, and contact information where Shopify allows it and where the data is available.

**Billing And Usage Limits:** Count eligible orders or usage events needed to apply plan limits, billing-period limits, and upgrade prompts.

**Administration:** Power admin pages, sync dashboards, courier settings, pickup form settings, search, pagination, status indicators, and support tools.

**Security And Abuse Prevention:** Detect endpoint misuse, rate-limit suspicious requests, protect location endpoints, and prevent unauthorized bulk extraction of courier location data.

**Analytics/Improvement:** Use aggregate, non-personal insights such as feature usage, error patterns, and sync performance to improve reliability and support. We do not sell customer data.

### Sharing

**Shopify:** The App operates through Shopify APIs, Shopify app proxy, Shopify checkout, and Shopify admin. Your use is governed by Shopify’s terms and policies.

**Courier Providers And Third-Party Services:** The App may interact with courier APIs, location feeds, map services, hosting providers, databases, or other third-party services needed for functionality. Their privacy practices are not covered by this Policy.

**Merchant Fulfillment:** The merchant may use selected customer delivery and pickup-location data to fulfill orders, communicate with couriers, and provide delivery support.

**Legal:** We may disclose information if required by law, valid legal process, Shopify requirement, provider complaint, or security investigation. We limit such disclosures to what is necessary.

**No Sale:** We do not sell or rent customer data.

### Your Rights

**Control:** You manage app settings, couriers, shipping-rate mappings, pickup form settings, provider credentials, and enabled delivery methods within Shopify admin and the App.

**Access/Correction/Deletion:** You may update or delete app configuration where the App provides controls. Customer order data stored in Shopify is managed according to Shopify’s tools and merchant retention settings.

**Uninstall:** If you uninstall the App, Shopify sends required uninstall/privacy events. The App will process shop erasure according to Shopify app requirements and operational retention needs.

**GDPR/International:** You are the controller for your customers’ data and must maintain a lawful basis, honor data-subject rights, and comply with applicable privacy, consumer, e-commerce, and delivery laws. Appsetup acts as a service provider or processor where applicable, depending on the merchant’s use of the App and applicable law.

### Courier Location Data

The App may cache courier pickup-point data from public, authorized, merchant-provided, or credentialed sources.

You are responsible for confirming that your use of courier data, APIs, files, widgets, or feeds complies with provider terms and applicable laws.

The App is not intended to be used as a source for extracting, copying, exporting, reselling, redistributing, or building a separate courier-location database.

We may disable, remove, restrict, or modify any courier data source if required by a provider, Shopify, law, security concern, abuse risk, or operational risk.

### Third-Party Services

The App may reference or interact with third-party services, including Shopify, courier providers, map providers, hosting providers, database providers, and API services.

Their privacy practices are not covered by this Policy. Review their policies before sharing personal information or enabling integrations.

### Risk Disclaimers

**No Delivery Guarantee:** The App does not ship orders, guarantee courier acceptance, guarantee pickup-point availability, or guarantee successful delivery.

**Data Accuracy:** Courier location data may be incomplete, outdated, unavailable, duplicated, missing coordinates, or missing postal codes depending on the provider source.

**Checkout Limitations:** Shopify controls checkout behavior and may not accept or preserve every field in every situation. Some delivery information can be passed only where Shopify allows it and where the data exists.

**Configuration Responsibility:** You are responsible for the accuracy of couriers, shipping zones, shipping rates, delivery methods, provider settings, customer-facing labels, and checkout testing before going live.

### Policy Updates

We may update this Policy at any time.

Significant changes will be posted in the App, documentation, or on our website. Continued use after updates constitutes acceptance of the revised Policy.

### Contact

For privacy questions or requests, contact:

<team@appsetupeng.com>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://appsetup-eng.gitbook.io/pickup-points/privacy-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
