Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how REQUR (“we”, “us”) handles information when you install and use the PostNL Shopify app (the “App”), which connects your Shopify store to Integration.
When you use the App, the merchant (you) is the data controller for your customers’ personal data, and REQUR acts as a data processor that processes that data on your behalf and on your instructions.
1. Information we process
| Category | Examples | Purpose |
|---|---|---|
| Store & account | Your myshopify domain, store email, your Shopify access token (encrypted) and your Integration API credentials (encrypted) | Authenticate the App and let it create labels on your own Integration contract |
| Order data | Order number, order date, total, currency, line items (description, SKU, quantity, weight) and any note the buyer left at checkout | Decide what goes in the parcel, calculate its weight, and print the packing slip |
| Recipient data | Name, company, street, house number, postcode, city, country, phone and email of the person the parcel is addressed to | Print the shipping label - Integration cannot deliver a parcel without it |
| Shipment data | Integration barcode, product code, the label PDF, and the delivery scan events Integration reports | Track the parcel and report fulfilment and tracking back to Shopify so the buyer is notified |
2. How the data is used
We process the data solely to provide the App’s functionality and to provide support. We do not sell your data or your customers’ data, and we do not use it for advertising or for training machine-learning models.
3. What we store
We keep only the minimum needed to run the service reliably:
- Your configuration and preferences;
- Encrypted Shopify and Integration access tokens;
- A record of which items have already been processed, so nothing is duplicated;
- The recipient address and order contents for each shipment, for as long as you may need to reprint the label or answer a delivery question;
- The generated label PDFs, so a label can be reprinted from any device without buying a second one;
- The delivery scan events Integration reports for your parcels.
4. Sub-processors
We share data only with the services required to operate the App:
- Shopify - the source of your store data.
- Integration - your own account, where the App writes on your behalf.
- Hosting infrastructure (Laravel Cloud / Amazon Web Services) - secure application hosting and database storage.
5. Data retention and deletion
We retain data only while the App is installed. When you uninstall the App, we stop processing your data and delete or anonymise the data we hold within 60 days. We also honour Shopify’s mandatory privacy webhooks: requests to erase a specific customer’s data (customers/redact) and to erase a shop’s data (shop/redact) are processed automatically.
6. Security
All data is transmitted over encrypted connections (TLS), and access tokens are encrypted at rest. The App requests only the Shopify permissions it needs to function.
7. Your rights
Depending on your location, you and your customers may have rights to access, correct, delete, restrict, or port personal data, and to object to its processing. Because the merchant is the data controller, such requests are usually handled by the merchant directly within Shopify and Integration. You can also contact us at info@requr.nl and we will assist.
8. Changes to this policy
We may update this Privacy Policy from time to time. The “last updated” date above reflects the current version.
9. Contact
REQUR - based in the Netherlands.
Email: info@requr.nl