> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usecharlie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Charlie collects, uses, and protects your information

**Last Updated:** April 1, 2026

## Legal Notice

**Application Publisher:**
Charlie SAS
RCS Paris 102 163 060
90 Boulevard de la Tour-Maubourg, 75007 Paris, France
President: Ghrenassia & Sons
Contact: [support@usecharlie.ai](mailto:support@usecharlie.ai)

**Hosting:**

* Application: Cloudflare Workers
* Database: Cloudflare D1
* Domain: app.usecharlie.ai

## Introduction

This Privacy Policy describes how Charlie ("we", "our", or "the App") collects, uses, and protects information when you install and use our Shopify application. Charlie is a fulfillment and location management app that helps merchants manage multiple store locations and create intelligent order routing rules.

This application is subject to French and European regulations, including the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the French Data Protection Act of January 6, 1978, as amended.

## Data Controller

The data controller is:

**Charlie SAS**
[support@usecharlie.ai](mailto:support@usecharlie.ai)

## Information We Collect

### Merchant Information

When you install and use Charlie, we collect:

| Data type                  | Description                                                                                             |
| -------------------------- | ------------------------------------------------------------------------------------------------------- |
| **Shop information**       | Store name, email address, owner name, timezone, currency, domain                                       |
| **Location data**          | Location names, addresses, types, opening hours, capacity limits, phone numbers, geographic coordinates |
| **Configuration settings** | Shipping zones, local pickup settings, fulfillment constraint rules, shop preferences                   |
| **Session data**           | Authentication tokens and session information required for app functionality                            |
| **Application logs**       | Diagnostic information including shop identifiers, location IDs, and webhook events                     |
| **Inventory exports**      | Merchant staff email address used for delivering export files                                           |

### Customer Information

<Note>
  We do **NOT** directly collect or store personal information from your customers.
</Note>

However, we may process:

* Customer attributes (B2B status, tags) solely for order routing decisions
* Delivery preferences during checkout for location selection
* Order information to determine optimal fulfillment locations

No customer personal data is stored in our database.

### Automatically Collected Information

* **Webhook events**: Tracking of webhook events (e.g., location updates, inventory changes) for app functionality
* **Application logs**: Server-side logs for debugging and performance monitoring
* **No tracking cookies**: We do not use cookies for tracking or analytics purposes

## Legal Basis for Processing

We process your data on the following legal bases:

| Basis                    | Purpose                                                 |
| ------------------------ | ------------------------------------------------------- |
| **Contract performance** | Processing necessary for the application usage contract |
| **Legitimate interests** | To improve our services and ensure application security |
| **Legal obligation**     | To comply with our legal and regulatory obligations     |

## Purposes of Processing

We use the collected information to:

* Provide core app functionality including location management and order routing
* Synchronize data with Shopify's platform
* Process fulfillment rules and routing decisions
* Display location maps and validate addresses
* Maintain app sessions and authentication
* Provide checkout UI extensions for customer location selection
* Debug issues and monitor application performance
* Improve app functionality and fix bugs
* Comply with legal obligations

## Data Storage and Security

### Location and Retention Period

| Data type                       | Retention                                                   |
| ------------------------------- | ----------------------------------------------------------- |
| **Database**                    | Cloudflare D1 (SQLite) with encryption at rest              |
| **Session data**                | Retained while subscription is active                       |
| **Event logs**                  | Webhook deduplication events retained for 48 hours          |
| **Activity logs**               | Configuration change audit trail retained for 90 days       |
| **Application logs**            | Diagnostic logs retained for 30 days                        |
| **Database backups**            | Daily backups stored in Cloudflare R2, retained for 30 days |
| **Inventory export files**      | Retained for 30 days, then automatically removed            |
| **Error monitoring (Sentry)**   | Error logs retained for 90 days                             |
| **Product analytics (PostHog)** | Usage events retained for 12 months                         |
| **Metafield data**              | Follows Shopify's data retention policies                   |

<Info>
  Most business data is stored in Shopify's platform using metafields—minimal data is stored in Charlie's database.
</Info>

### Security Measures

We implement industry-standard security measures:

* Encrypted connections (HTTPS/TLS)
* Secure authentication tokens via Shopify OAuth
* Regular security updates
* Access controls and monitoring
* Data encryption at rest and in transit
* No storage of sensitive payment information

## Third-Party Services

We use the following third-party services:

| Service                                                        | Purpose                                                                                 | Data received                                                         |
| -------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| **Shopify**                                                    | Commerce platform, data source of truth, authentication                                 | All merchant commerce data                                            |
| **Cloudflare** (Workers, D1, KV, Queues, R2, Analytics Engine) | Application hosting, database, caching, background jobs, backups, fulfillment analytics | Operational configuration, OAuth sessions, anonymized routing metrics |
| **Sentry**                                                     | Error monitoring                                                                        | Stack traces and request context (no PII, no access tokens)           |
| **PostHog**                                                    | Product analytics                                                                       | Usage interaction events with shop fingerprint only                   |
| **Resend**                                                     | Transactional email (inventory export notifications)                                    | Merchant email address, download URLs                                 |
| **Mantle**                                                     | Subscription billing management                                                         | Billing plan status                                                   |
| **BetterStack**                                                | Uptime monitoring and status page                                                       | Service health heartbeats only                                        |
| **Google Maps Time Zone API**                                  | Timezone resolution from location coordinates                                           | GPS coordinates of merchant locations                                 |

<Tip>
  We do **not** use any third-party advertising, remarketing, or customer tracking services. Analytics services (Sentry, PostHog) receive only operational data and shop-level interaction events — no customer PII, no merchant business data.
</Tip>

## Data Sharing

We do **NOT** share your data:

* We do not sell, rent, or trade your information to third parties
* We do not share your data for marketing purposes
* We do not use your data for purposes other than providing app functionality

We may share information only when:

* Required by law or legal process
* Necessary to protect rights, safety, or property
* You explicitly consent to such sharing

## International Transfers

Data may be transferred outside the European Union only when:

* Appropriate safeguards are in place (standard contractual clauses, adequacy decisions)
* The transfer is necessary for contract performance
* Services used have appropriate data protection measures

## Your Rights (GDPR)

Under the GDPR, you have the following rights:

| Right                | Description                                                                |
| -------------------- | -------------------------------------------------------------------------- |
| **Access**           | Obtain confirmation that your data is being processed and access this data |
| **Rectification**    | Correct inaccurate or incomplete data                                      |
| **Erasure**          | Request deletion of your data under certain conditions                     |
| **Restriction**      | Request restriction of processing under certain conditions                 |
| **Data portability** | Receive your data in a structured format                                   |
| **Object**           | Object to the processing of your data                                      |
| **Withdraw consent** | Where processing is based on consent                                       |

To exercise these rights, contact us at: [support@usecharlie.ai](mailto:support@usecharlie.ai)

You also have the right to lodge a complaint with your local supervisory authority. For France:

**Commission Nationale de l'Informatique et des Libertés (CNIL)**
3 Place de Fontenoy - TSA 80715
75334 PARIS CEDEX 07
Tel: +33 1 53 73 22 22

## Shopify GDPR Webhooks

We comply with Shopify's mandatory GDPR compliance webhooks:

| Webhook                     | Action                                                    |
| --------------------------- | --------------------------------------------------------- |
| **customers/data\_request** | We provide any processed customer data upon request       |
| **customers/redact**        | We delete any customer data upon request                  |
| **shop/redact**             | We delete all shop data 48 hours after app uninstallation |

<Note>
  As we do not store customer personal data, these requests typically return no data.
</Note>

## Cookies and Tracking

* **No tracking cookies**: We do not use cookies for tracking, analytics, or advertising
* **Session management**: Authentication is handled through Shopify OAuth without cookies
* **No third-party tracking**: We do not use Google Analytics, Facebook Pixel, or any advertising/remarketing services

## Data Deletion

To delete all your data:

<Steps>
  <Step title="Uninstall Charlie">
    Go to your Shopify admin and uninstall the Charlie app.
  </Step>

  <Step title="Automatic deletion">
    This triggers automatic deletion of all Charlie data stored in our database:

    * All session data (immediate)
    * All webhook event logs (within 48 hours)
    * All location configurations, fulfillment rules, and preferences
    * All activity logs and export records

    Metafield values written to Shopify (inventory levels, safety stock, location tags) remain in your Shopify store since they belong to you and are accessible via the Shopify Admin API.
  </Step>
</Steps>

<Warning>
  Data deletion is permanent and cannot be reversed.
</Warning>

## Children's Privacy

Our app is not directed to children under 16. We do not knowingly collect information from children under 16 years of age.

## Customer Interaction

Your customers may interact with Charlie through:

* **Checkout UI extensions**: For selecting pickup locations or delivery options
* **Order routing**: Their delivery preferences influence fulfillment decisions

We process this information solely to fulfill orders according to your configured rules.

## Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through:

* Email to your registered shop email
* In-app notifications
* Update notices in the Shopify App Store

Continued use of the app after changes constitutes acceptance of the updated policy.

## California Privacy Rights (CCPA)

For California residents:

* We do not sell personal information
* You have the right to know what personal information we collect
* You have the right to delete your personal information
* You have the right to opt-out of the sale of personal information (though we do not sell data)
* We will not discriminate against you for exercising your privacy rights

## Contact Information

For any questions regarding data protection or to exercise your rights:

**Email**: [support@usecharlie.ai](mailto:support@usecharlie.ai)
**Responsible**: Rocco Ghrenassia
**Company**: Charlie SAS

***

By installing and using Charlie, you acknowledge that you have read, understood, and agree to this Privacy Policy.
