Privacy Policy — Hybrid: COD Form & Upsells

Last updated: July 21, 2026

Thank you for using Hybrid: COD Form & Upsells. This Privacy Policy explains what Shopify store data we request, why we request it, how we use and protect it to deliver the app's features, and how you can request deletion. By installing or using Hybrid you agree to the terms below.

What we request and why

To enable Hybrid's features (the Cash on Delivery checkout form, quantity bundles and upsells, fraud prevention, delivery-success emails, and FOXPOST locker shipping), we request these Shopify permissions from your store:

  • Read and write orders / draft orders — to create the COD order (or a prefilled card-payment checkout) from the details a customer submits in the form, apply bundle and card-payment discounts, and tag orders placed through the app.
  • Read products — to power the buy button, bundle tiers, and upsell offers with real product titles, images, variants, and prices.
  • Protected customer data (name, email, phone, address) — collected in the checkout form and attached to the order so the merchant can fulfil it, send delivery-success emails, and protect against fraudulent COD orders.
  • Theme app extension — a small storefront script that renders the COD form on product and cart pages; it only activates when the merchant enables it in their theme.
  • Cart transforms — to apply bundle and card-payment discounts in the Shopify cart and checkout when the customer pays online.
  • Fulfillments — to mark orders fulfilled with a real tracking number when a FOXPOST parcel is created for a locker-pickup order.
  • Webhooks — order and fulfillment events that drive the delivery-success email automations and keep order analytics inside the app accurate.

What we store, and how it is protected

Hybrid stores only the minimum data each feature needs, and protects it as follows:

  • Order contact details (customer name, email, phone) — kept so delivery-success emails can be sent and so the merchant can review their own orders inside the app. Stored encrypted at rest.
  • Fraud-prevention identifiers — customer identifiers used for risk scoring and the merchant's blocklist are stored as irreversible keyed hashes (pseudonymized). They cannot be decoded or read back — not by us, and not by anyone who accessed the database.
  • FOXPOST shipment records (chosen locker, recipient name/phone, COD amount) — kept so parcels can be created with the merchant's own FOXPOST account and labels can be printed.
  • Merchant credentials (SMTP for emails, FOXPOST API access) — entered by the merchant, stored encrypted, never exposed back in plain text, and used only to act on the merchant's behalf.
  • Email delivery analytics — send/failure counts per automation so merchants can monitor their email health.
  • Installation metadata — the shop domain and API token needed for the app to stay installed and operate.

We never sell, rent, or share customer data. Product catalog data is fetched live from Shopify when needed and is not duplicated into our storage.

How we use the data

Data is used exclusively to provide Hybrid's functionality: creating the customer's COD order in the merchant's store, applying the discounts shown in the form, screening high-risk COD orders, sending the merchant's configured delivery emails, registering FOXPOST locker parcels, and showing the merchant their own analytics inside the app.

Retention and deletion

We honour Shopify's mandatory privacy webhooks: when a customer requests redaction, their personal data is deleted from our records; when a store uninstalls the app or requests shop redaction, that shop's records — settings, credentials, contacts, shipments, analytics — are removed. Fraud-prevention hashes are already irreversible and are deleted with the shop's records.

Your rights

Merchants and their customers can request access to, or deletion of, data we hold. To make a request, provide the store domain and (if relevant) an order number so we can locate records quickly. We respond to valid requests within a reasonable timeframe, and always within the periods required by applicable law (including GDPR).

Security

Personal data is encrypted at rest; blocklist identifiers are stored only as keyed one-way hashes; merchant credentials are encrypted and never displayed back. Access to the app backend is limited to authorized personnel, protected with industry-standard access controls, and all traffic between the storefront, our servers, and Shopify is encrypted in transit (HTTPS).

Third parties

We do not sell or rent your store data. Limited data is shared with third parties only when a feature the merchant enabled requires it: FOXPOST receives the recipient details needed to register a locker parcel; the merchant's own SMTP provider delivers the emails the merchant configured; our hosting provider stores the encrypted records described above. Each provider processes data only to the extent necessary to deliver its service.

Contact

If you have questions about this Privacy Policy, want data deleted, or need support with Hybrid, contact our support team: