PackPost 개인정보처리방침
PackPost(이하 "앱")는 Shopify 스토어에 설치되어, 판매자가 직접 입력하는 배송 단계(포장중 · 발송 · 통관 · 도착 등)를 구매자에게 공유하는 서비스입니다. 실시간 위치 추적이 아니라 판매자가 수동으로 갱신하는 정보라는 점을 이 문서와 앱 화면 전반에 명확히 표시합니다. 이 문서는 앱이 어떤 정보를 수집·이용·보관하는지 설명합니다.
1. 수집하는 정보
앱은 서비스 제공에 필요한 최소한의 정보만 처리합니다.
- 스토어 도메인 및 판매자가 설정한 배송 단계 이름/순서
- 주문 ID, 주문번호(예: #1001)
- 주문에 포함된 고객 이메일 (구매자가 자신의 주문 상태를 조회할 때 본인 확인 용도로만 사용)
- 판매자가 직접 입력한 단계 변경 이력(변경 시각, 선택한 단계, 메모, 첨부 이미지 URL)
앱은 소비자의 이름, 배송지 주소, 전화번호, 결제 정보를 저장하지 않습니다.
2. 수집 목적
수집한 정보는 아래 목적에만 사용됩니다.
- 판매자의 관리자 화면에 주문 목록과 현재 배송 단계를 표시
- 구매자가 주문번호와 이메일로 본인 주문의 배송 현황(타임라인)을 조회할 수 있도록 제공
- 판매자가 언제 어떤 상태로 갱신했는지 이력을 보여주어 신뢰를 뒷받침
마케팅, 프로파일링, 제3자 광고 등 다른 목적으로는 사용하지 않습니다.
3. 보관 및 삭제
- 데이터는 앱이 스토어에 설치되어 있는 동안 보관됩니다.
- 주문 타임라인 데이터는 원칙적으로 최대 24개월간 보관 후 삭제하는 것을 목표로 운영합니다.
- 스토어에서 앱을 삭제하면 Shopify가 전송하는
shop/redact웹훅을 통해 해당 스토어의 모든 데이터(단계 설정, 주문 타임라인, 이력)가 삭제됩니다. - 소비자가
customers/redact절차로 삭제를 요청하면 해당 주문에 저장된 이메일을 즉시 삭제합니다(주문 단계 이력 자체는 판매자의 운영 기록으로 남되, 개인 식별 정보는 제거됩니다). customers/data_request요청 시 보관 중인 이메일·주문번호 정보를 요청자에게 안내합니다.
4. 제3자 제공
수집한 정보를 제3자에게 판매, 대여, 공유하지 않습니다. 서비스 운영을 위해 아래 인프라 제공업체만 이용하며, 이들은 각자의 보안·개인정보 정책에 따라 데이터를 처리합니다.
- Neon (PostgreSQL 데이터베이스 호스팅)
- Render (앱 서버 호스팅)
- Shopify (스토어/주문 데이터 연동)
5. 보안
앱과 Shopify 간의 모든 통신은 HTTPS(TLS)로 암호화됩니다. 데이터베이스에 저장된 데이터는 전송 중·저장 시 모두 암호화됩니다. 스토어프론트 위젯의 조회 요청은 Shopify App Proxy 서명 검증을 거치며, 관리자 화면은 Shopify 세션 인증을 통해 해당 스토어의 담당자만 접근할 수 있습니다.
6. 이용자 권리
스토어 운영자 또는 구매자는 아래 연락처로 보관 중인 정보에 대한 열람, 정정, 삭제를 요청할 수 있습니다. 요청 접수 후 합리적인 기간 내에 처리합니다.
7. 정책 변경
본 방침이 변경되는 경우 이 페이지를 통해 고지하며, 페이지 상단의 최종 수정일이 갱신됩니다.
문의처
PackPost Privacy Policy
PackPost (the "App") is installed on Shopify stores to let merchants share manually-updated delivery stages (packing, shipped, customs, arrived, etc.) with their buyers. This is not real-time location tracking — every stage shown is entered by the merchant themselves, and this is disclosed clearly throughout the app and the storefront widget. This document explains what information the App collects, uses, and stores.
1. Information We Collect
The App processes only the minimum information required to provide its service.
- Store domain and the merchant's configured delivery stage names/order
- Order ID and order name (e.g. #1001)
- The customer email attached to the order (used only to verify identity when a buyer looks up their own order status)
- The merchant's manually-entered stage update history (timestamp, selected stage, note, attached image URL)
The App does not store the customer's name, shipping address, phone number, or payment information.
2. Purpose of Processing
Collected information is used only for the following purposes:
- Displaying the order list and current delivery stage in the merchant's admin screen
- Letting a buyer look up their own order's delivery timeline using their order number and email
- Showing when and to what stage the merchant updated the order, to support the transparency the App is built around
Data is never used for marketing, profiling, or third-party advertising.
3. Retention and Deletion
- Data is retained while the App remains installed on the store.
- As a policy target, order timeline data is retained for at most 24 months before deletion.
- When a store uninstalls the App, all data for that store (stage configuration,
order timelines, history) is deleted via the Shopify
shop/redactwebhook. - When a customer requests deletion via
customers/redact, the email stored on that order is deleted immediately (the stage history itself may remain as the merchant's operational record, with personal identifiers removed). - For a
customers/data_request, we disclose the stored email and order name to the requester.
4. Third-Party Sharing
Collected information is never sold, rented, or shared with third parties. We rely only on the following infrastructure providers to operate the service, each subject to their own security and privacy practices.
- Neon (PostgreSQL database hosting)
- Render (application server hosting)
- Shopify (store/order data integration)
5. Security
All communication between the App and Shopify is encrypted via HTTPS (TLS). Data stored in the database is encrypted both in transit and at rest. Storefront widget requests are verified via Shopify App Proxy signature checks, and the admin screen is gated behind Shopify session authentication so only that store's own staff can access it.
6. Your Rights
Store owners and customers may contact us at any time using the details below to request access to, correction of, or deletion of any information held about them. We respond to such requests within a reasonable timeframe.
7. Changes to This Policy
If this policy changes, the update will be posted on this page and the "Last updated" date above will be revised accordingly.
Contact
Email: shopboost.dev@gmail.com