Privacy Policy

Privacy Policy · Selfix · As of 2026

1. Data Controller

Gianluca Iacona (infinitecodes)
Rolshover Straße 70
51105 Cologne, North Rhine-Westphalia
Germany
Email: info@infinitecodes.de

2. Data Collected

Selfix lets a shop's customers self-service edit their orders (change the shipping address, swap a variant) as long as the order has not already entered fulfillment. The following data is processed:

This data is stored as an audit log solely to track the change and to enforce the time-window and locking mechanism (e.g. locking orders that have already shipped).

3. Purpose and Legal Basis

Processing is carried out to provide the app's functionality (order edits by customers on behalf of the merchant) as well as fraud and abuse prevention (e.g. preventing edits to orders that have already shipped). The legal basis is Art. 6(1)(b) and (f) GDPR.

4. Retention Period

Session data is automatically deleted when the app is uninstalled. Audit log entries containing personal data (shipping addresses) are automatically anonymized after 90 days; the entry itself is kept without any personal reference for statistical purposes. Earlier deletion takes place upon a GDPR request or when the app is uninstalled. Encrypted backups are kept for 14 days and are then deleted automatically.

5. Disclosure to Third Parties

Data is never sold or passed on for third-party purposes. The app communicates exclusively with the Shopify Admin API of the respective shop. The following processors are engaged under Art. 28 GDPR:

Backups are encrypted before they leave our server; the storage provider has no access to the plaintext.

6. Hosting

The app is hosted on servers within the European Union (STRATO GmbH). Encrypted backups are stored in Falkenstein, Germany (Hetzner Online GmbH). All processing is based on data processing agreements under Art. 28 GDPR.

7. Your Rights

Under GDPR, you have the following rights:

To exercise your rights: info@infinitecodes.de

8. Cookies

Selfix does not use tracking cookies. Technically necessary session cookies for Shopify authentication are permitted under Art. 6(1)(f) GDPR.

9. Security

Shipping addresses in the audit log are encrypted (AES-256-GCM) before being stored. Every access to protected customer data is logged. Backups are encrypted with GPG (RSA-4096) before they leave the server and are stored exclusively within the EU.

© 2026 infinitecodes