Special Delivery
Privacy Policy
Last updated: July 27, 2026
Who we are
Special Delivery (special-delivery.app) is a Shopify app that helps merchants win repeat orders: it predicts when a customer will run out of a product and sends reorder reminders — QR codes on packaging, emails, and printed mail pieces — on the merchant’s behalf. For the shopper data described below, the merchant is the data controller and Special Delivery acts as a processor on their instructions.
Data we process
When a merchant installs the app, we receive data from Shopify strictly to provide the service:
- Order data — customer name, email address, shipping and billing address, the products, quantities and values of their orders, and their email marketing consent status. Order history is what teaches each customer’s reorder rhythm.
- Store data — store name, domain, contact email, currency, and the settings the merchant configures in the app (including the postcard return address).
- Reminder activity — the content of reminder messages we generate, delivery identifiers from our providers, and whether a reorder link or QR code was scanned, snoozed or opted out of, so reorders can be attributed, the timing model can learn, and usage can be billed accurately.
We do not collect payment card details, and shoppers check out only through Shopify — never through us.
How we use it
Only to operate the service for the merchant: predicting when a customer will run out under the merchant’s rules, writing and sending reorder reminders by email and mail, attributing reorders, and billing usage through Shopify. Reminder emails are sent only to customers who have accepted email marketing from the store. We do not sell personal data, use it for advertising, or use one merchant’s data for another merchant’s benefit.
Service providers
We use a small set of subprocessors, each receiving only what its role requires:
- Vercel — application hosting.
- Supabase — database hosting.
- Resend — reminder email delivery.
- Lob — printing and mailing physical reminder pieces (receives recipient name and mailing address).
- OpenAI — on plans with personalized copy, receives the shopper’s first name, the product title, and the store name to write the message. It never receives email addresses, mailing addresses, or order history.
Retention and deletion
- When a merchant uninstalls the app, our access credentials are revoked immediately and the store’s data is deleted when Shopify issues its uninstall redaction request.
- When a shopper asks their merchant for erasure, Shopify’s
customers/redactrequest causes us to erase that shopper’s personal data (name, email, addresses, message content) while preserving the merchant’s anonymous revenue records. - When a shopper asks their merchant for their data, we deliver what we hold to the merchant, who responds to their customer.
Security
All traffic is encrypted in transit. Data is stored in an access-controlled database reachable only by the application backend, and Shopify access tokens are short-lived and rotated automatically. Merchant dashboards are authenticated with Shopify-signed session tokens, so only a store’s own staff can see its data.
Contact
Questions or requests about this policy: benjaminfingram@gmail.com. If you are a shopper, contact the store you purchased from first — under data-protection law they are the controller of your data, and we act on their instructions.