Easy EU Withdrawal Button

Legal

Privacy Policy

Privacy Policy

Easy EU Withdrawal Button

Last updated: 16 June 2026

This Privacy Policy explains how Easy EU Withdrawal Button (“the App”, “we”, “us” or “our”) collects, uses, stores and protects personal data when a Shopify merchant installs and uses the App, and when a customer submits a withdrawal request through a Shopify store using the App.

Easy EU Withdrawal Button is a Shopify app designed to help merchants provide an online function that allows consumers to submit a withdrawal request in relation to an order. The App is not a full returns management app and does not automatically approve withdrawal requests, process refunds or make legal decisions on behalf of the merchant.

This Privacy Policy applies to:

  1. Shopify merchants who install or use the App.
  2. Store customers who use the withdrawal form provided by the App.
  3. Users who contact us through our website or support channels.

1. Data controller and contact details

The provider of the App is:

Daniel Roselló Ramos
NIF: 49372351E
Address: Calle Gaspar Torrella, 12 - 6, CP 46017 Valencia, Spain
Email: support@easywithdrawal.eu

For privacy-related requests, you can contact us at support@easywithdrawal.eu.

2. Our role under data protection laws

Depending on the context, we may act either as a data controller or as a data processor.

When we process data about Shopify merchants, app installations, billing, support requests, security logs and our own business operations, we act as a data controller.

When we process personal data of a merchant’s customers in order to provide the withdrawal request functionality to that merchant, we generally act as a data processor on behalf of the merchant. In that case, the Shopify merchant remains responsible for deciding how customer withdrawal requests are reviewed and handled.

3. Data we collect from Shopify merchants

When a merchant installs or uses the App, we may collect and process the following information:

  • Shopify shop domain, including the .myshopify.com domain.
  • Store name, store email, country, currency and general shop settings.
  • Shopify access token and API permissions granted to the App.
  • App installation, uninstallation and subscription status.
  • Billing plan, subscription ID, billing status and billing events.
  • App configuration settings, such as enabled languages, button text, popup settings, email notification address, branding settings and product exclusion settings.
  • Internal notes, request status changes and audit log activity created inside the App.
  • Support messages and communications sent to us.

We use this information to provide, maintain, secure and improve the App, manage subscriptions, provide support, comply with Shopify requirements and comply with applicable legal obligations.

4. Data we collect from store customers

When a customer uses the withdrawal form, the App may process the following customer data:

  • Order number or order name entered by the customer.
  • Email address used for the order.
  • Shopify order ID.
  • Customer first name and last name, if available in the Shopify order.
  • Customer phone number, if available in the Shopify order and necessary for the request.
  • Order creation date, processing date, fulfilment date and, where available, delivery-related dates.
  • Order financial and fulfilment status.
  • Product and line item data, including product title, variant title, SKU, quantity ordered, quantity selected for withdrawal, product image, price and currency.
  • Withdrawal request reference number.
  • Withdrawal request status.
  • Optional customer message or reason, if the merchant enables an optional message field.
  • Language used when submitting the request.
  • Date and time of submission.
  • IP address and user agent at the time of submission.
  • Email delivery information for customer confirmation emails.
  • A copy or record of the confirmation email sent to the customer.
  • Audit logs related to the request.

We do not intentionally collect special categories of personal data, such as health data, religious beliefs, political opinions or biometric data. Merchants should not configure the App to request this type of information, and customers should not include sensitive information in optional message fields.

5. Shopify order and refund data

The App needs limited access to Shopify order data to verify that the order number and customer email match before displaying order items in the withdrawal form.

The App may also process refund-related information from Shopify where this is necessary to automatically update the status of a withdrawal request when a related order or item is refunded in Shopify.

The App does not automatically create refunds, approve refunds, cancel orders or make binding decisions about whether a withdrawal request is legally valid. Those actions remain under the merchant’s control.

6. Purposes of processing

We process personal data for the following purposes:

  • To install and authenticate the App in the merchant’s Shopify store.
  • To provide the public withdrawal button, link, popup or form.
  • To allow a customer to identify an order using order number and email.
  • To display the relevant order items so the customer can submit a full or partial withdrawal request.
  • To create and store a withdrawal request record.
  • To send a confirmation email to the customer as an acknowledgement of receipt.
  • To notify the merchant about new withdrawal requests.
  • To allow the merchant to review, manage, update and close requests.
  • To store audit logs for evidentiary, security and compliance purposes.
  • To synchronize request status when Shopify refund events are detected.
  • To provide customer support.
  • To prevent fraud, abuse and unauthorized access.
  • To comply with applicable data protection obligations.
  • To comply with legal, tax, accounting or regulatory obligations.

7. Legal bases for processing

Where we act as a data controller, we rely on the following legal bases under the GDPR:

  • Performance of a contract: to provide the App to merchants who install and use it.
  • Legal obligation: to comply with applicable laws and platform requirements.
  • Legitimate interests: to secure the App, prevent abuse, maintain audit logs, improve the service and respond to support requests.
  • Consent: where a user voluntarily contacts us or opts into communications that require consent.

Where we act as a processor on behalf of a merchant, the merchant is responsible for determining the applicable legal basis for processing its customers’ personal data.

8. Data minimization

We only process data that is reasonably necessary to provide the App’s withdrawal request functionality.

The App does not require customers to log in. The App does not require customers to provide a reason for withdrawal unless the merchant enables an optional message field. The App does not request payment card data and does not process payment details directly.

9. Emails sent by the App

The App may send:

  • A confirmation email to the customer after a withdrawal request is submitted.
  • A notification email to the merchant when a new request is received.
  • Operational or support-related emails to merchants.

These emails may include the withdrawal request reference, order number, submitted products, date and time of submission and the customer email address.

We may use an email delivery provider, such as Amazon SES or an equivalent service, to send these emails. Email delivery logs may be stored to confirm whether an email was sent successfully.

10. Cookies and tracking

The public withdrawal form served through the Shopify storefront is designed not to rely on cookies.

The App may use temporary tokens to complete the lookup and submission flow securely. These tokens are used to verify that a customer who has successfully matched an order can submit a withdrawal request for that order. They expire automatically and are not used for advertising.

The embedded admin area of the App may rely on Shopify authentication and session mechanisms required for apps running inside the Shopify admin.

We do not sell personal data. We do not use customer order data for advertising profiling.

11. Automated decision-making

The App does not make automated decisions that produce legal effects for customers.

The App may display internal indicators to the merchant, such as whether a request may require manual review. These indicators are informational only. The merchant remains responsible for reviewing and deciding how to handle each request.

12. Data sharing and service providers

We may share personal data with service providers only where necessary to provide and secure the App. These may include:

  • Shopify, as the platform through which the App is installed and from which order and store data is accessed.
  • Hosting and infrastructure providers.
  • Email delivery providers.
  • Security, logging or monitoring providers.
  • Professional advisers, where necessary for legal, tax, accounting or compliance purposes.
  • Public authorities, where required by law.

Service providers are required to process personal data only in accordance with our instructions, applicable data protection laws and appropriate confidentiality and security obligations.

13. International transfers

We are based in Spain and primarily operate from the European Economic Area.

Some service providers, including Shopify or cloud/email infrastructure providers, may process data outside the European Economic Area. Where this occurs, we rely on appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses or other lawful transfer mechanisms under applicable data protection law.

14. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Typical retention periods are:

  • Merchant account and installation data: for as long as the App remains installed and for a reasonable period afterwards to handle support, billing, security and legal obligations.
  • Withdrawal requests and audit logs: for as long as necessary to provide the merchant with evidence of the request, manage the request lifecycle and comply with legal or contractual obligations.
  • Temporary lookup tokens: only for the time needed to complete the lookup and submission flow.
  • Email logs: for as long as necessary to prove delivery or diagnose delivery issues.
  • Support communications: for as long as necessary to handle the request and maintain business records.
  • Billing records: for the periods required by tax, accounting and commercial law.

When data is no longer required, we delete, anonymize or securely restrict access to it.

15. Data access, deletion and anonymization requests

We comply with applicable data protection laws and Shopify’s privacy requirements.

When we receive a valid request relating to access, deletion or anonymization of personal data, we will review the request and take appropriate action within the legally required period.

If the request relates to a customer of a Shopify merchant, we may need to coordinate with the relevant merchant, since the merchant is usually the controller of that customer relationship.

16. Security measures

We apply technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.

These measures may include:

  • Authentication through Shopify.
  • Restricted access to merchant and customer data.
  • Verification of legitimate requests received from Shopify.
  • Rate limiting on public lookup endpoints.
  • Temporary lookup tokens.
  • Secure storage of access tokens.
  • Logging of relevant security and audit events.
  • Use of HTTPS.
  • Access controls for administrative systems.
  • Data minimization and retention controls.

No system connected to the internet can be guaranteed to be completely secure. However, we take reasonable measures to protect the data processed through the App.

17. Merchant responsibilities

Merchants using the App are responsible for:

  • Informing their customers that the App may be used to receive and manage withdrawal requests.
  • Ensuring that their own privacy policy explains how customer data is processed in connection with withdrawal requests.
  • Reviewing and deciding whether a withdrawal request is valid under applicable law.
  • Avoiding the collection of unnecessary or sensitive information through custom text fields.
  • Ensuring that any legal texts, withdrawal information and consumer notices shown in their store are accurate.
  • Handling refunds, returns, customer communications and legal claims outside the App where necessary.

The App helps receive and document withdrawal requests, but it does not replace the merchant’s legal obligations.

18. Your rights

Depending on your location and applicable law, you may have the right to:

  • Access your personal data.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Request restriction of processing.
  • Object to processing.
  • Request data portability.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a data protection authority.

If you are a customer of a Shopify store using the App, you should first contact the merchant/store where you made the purchase. Because we usually process customer data on behalf of the merchant, we may need to forward or refer your request to the relevant merchant.

You may also contact us at support@easywithdrawal.eu.

19. Data breach notification

If we become aware of a personal data breach affecting data processed through the App, we will assess the incident and take appropriate measures in accordance with applicable data protection laws.

Where legally required, we will notify affected merchants, competent supervisory authorities or affected individuals.

20. Children’s data

The App is intended for use by Shopify merchants and by customers submitting withdrawal requests related to purchases. The App is not directed at children and we do not knowingly collect personal data from children.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, Shopify requirements or our data processing practices.

When we make material changes, we will update the “Last updated” date and, where appropriate, notify merchants through the App or by email.

22. Contact

For questions about this Privacy Policy or the processing of personal data by Easy EU Withdrawal Button, please contact:

Easy EU Withdrawal Button
Daniel Roselló Ramos
Calle Gaspar Torrella, 12 - 6
CP 46017 Valencia, Spain
Email: support@easywithdrawal.eu