Who We Are
AddonNordic ApS, CVR 46495985, Denmark. Contact: [email protected].
This policy covers the AddonNordic apps you install from the Shopify App Store (for example EU B2B Order Guard and our other B2B apps). It explains what data these apps process when installed on your Shopify store. For our website and the Nordic Data API platform, see our main Privacy Policy.
Data We Process
When you install one of our apps, Shopify grants it access to the data needed for that app's features. Depending on the specific app and the access scopes you approve, this may include:
- Store and account data (provided by Shopify on install) — Store domain, store-owner name and email, plan, and locale.
- Store operational data (only what the app's features require) — Orders (order ID and status, line items, and the billing/shipping address including company name and country); customer and company records (name, email, company name and tax/registration identifiers) where a feature needs them; products and related store data where relevant.
- Business-verification data (for our B2B and company-data apps) — Company identifiers you or your buyers provide (VAT number, CVR/organisation number) used to look up official business-registry data; enrichment results stored against your records (company name, registration status, risk indicators, VAT validity) and, for KYB features, the names of company directors and beneficial owners obtained from official public registries.
Each app requests only the minimum Shopify access scopes its features need.
What We Do Not Do
We do not sell your data or your customers' data. We do not use it for advertising. We do not access more data than a feature requires.
Why We Process Your Data
- Providing the app's functionality — Contract (GDPR Art. 6.1.b)
- Sending operational notifications (e.g. risk alerts) — Legitimate interest (GDPR Art. 6.1.f)
- Security, error tracking and abuse prevention — Legitimate interest (GDPR Art. 6.1.f)
- Legal and tax compliance — Legal obligation (GDPR Art. 6.1.c)
Who We Share Data With
| Processor | Purpose | Region |
|---|---|---|
| Shopify | Platform and source of store data | EU/global per your Shopify region |
| Railway | Application hosting and database | EU (West) |
| AddonNordic Data API (api.addonnordic.dk) | Company, VAT, sanctions, LEI and risk lookups from official national registries and EU systems (VIES, OpenSanctions, GLEIF) | EU |
| Resend | Transactional emails (e.g. risk alerts) | EU |
| Sentry | Error tracking (where enabled) | EU |
All processors are bound by GDPR-compliant data processing agreements. Payments for paid plans are handled by Shopify through the Shopify Billing API — we never receive your card details.
Data Location and Retention
Data is processed in the EU. We retain it only while the app is installed. We honour Shopify's mandatory privacy webhooks: customers/data_request (we provide the customer data the app holds), customers/redact (we delete data linked to that customer), and shop/redact (on uninstall we delete your store's data, within 30 days). Some records may be retained longer where required by law, such as the Danish Bookkeeping Act (5 years for financial records).
Nature of Results
For risk, KYB and sanctions features, results are generated automatically from public sources and are provided as decision support only. They are not legal, accounting, credit or compliance advice, and are never a definitive verdict on any company or person. Sanctions and PEP matches are surfaced for review and are never an automatic block.
Your Rights
Under GDPR you have the right to access, correct, delete and port your data, and to object to processing based on legitimate interest. You may lodge a complaint with the Danish Data Protection Authority (datatilsynet.dk). To exercise your rights, contact [email protected], or uninstall the app — which triggers deletion via Shopify's shop/redact webhook.
Changes
We may update this policy; the "last updated" date reflects the latest version.
Contact
AddonNordic ApS · CVR 46495985 · [email protected]