Privacy Policy
KM Distance Shipping

Last updated: August 2026

1. Controller

The controller for data processing in connection with the Shopify app "KM Distance Shipping" (the "App") is:

KEVIN METZDORF LTD
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Email: info@kevin-metzdorf.com

2. The essentials in brief

The App is deliberately built to be data-minimal: end-customer delivery addresses are never stored — they are used only transiently in memory for the individual shipping-rate calculation. No external map service is involved (no Google Maps, no Mapbox): the App looks up postal-code coordinates in locally bundled datasets (GeoNames, licensed CC BY 4.0). Address data does not leave the App's server.

3. What data the App processes

a) Shop and configuration data (stored)

When the App is installed and used, the following is stored: the shop domain, the API access token issued by Shopify, Shopify sessions and the configuration created by the merchant (postal-code zones, distance tiers with prices, origin postal code and country, language and onboarding settings). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR / UK GDPR).

b) End-customer delivery addresses (not stored)

When calculating shipping rates, Shopify transmits the order's delivery address to the App — of which the postal code and country are used. This data is used exclusively and transiently in memory for that one calculation and is neither stored nor cached nor logged. The App's server logs deliberately contain no end-customer postal codes. The legal basis is the performance of the contract with the merchant (Art. 6(1)(b) GDPR) and the legitimate interest in providing the shipping-rate calculation (Art. 6(1)(f) GDPR).

c) Merchant contact data

Through the Shopify session, the name and email address of the user logged into the Shopify admin may technically occur (standard session fields of the Shopify SDK). No storage or use beyond this takes place.

4. Recipients and processors

Fly.io Inc. (USA) operates the App's server infrastructure as hosting provider, including the database and log storage. The server location is Frankfurt am Main, Germany; as Fly.io is a US company, the engagement is based on EU Standard Contractual Clauses (SCCs). The logs contain no personal data of end customers.

Shopify, as the e-commerce platform, is the technical origin of all data: Shopify transmits the order data required for the calculation to the App and handles billing. Shopify's privacy policy applies to processing by Shopify.

There are no other recipients — the App uses no analytics, tracking, error-tracking or email services.

5. International transfers

The controller is established in the United Kingdom; transfers from the EU are covered by the European Commission's adequacy decision. For the US provider Fly.io, EU Standard Contractual Clauses apply, with servers located in Germany.

6. Retention and deletion

End-customer data: no storage (see above). Shop and configuration data is stored for as long as the App is installed in the shop. After uninstallation, Shopify sends the deletion request (shop/redact, usually 48 hours later) — upon which all stored data of the shop is deleted completely and irreversibly: configuration, zones, tiers, settings, access token and sessions.

7. Shopify privacy webhooks

The App implements all privacy endpoints required by Shopify: data requests (customers/data_request) and erasure requests (customers/redact) are answered — as the App stores no end-customer data, there is nothing to disclose or erase. The shop erasure request (shop/redact) triggers the complete deletion described in section 6.

8. Your rights

Data subjects have — under the applicable rules (GDPR / UK GDPR) — the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Please contact info@kevin-metzdorf.com. You also have the right to lodge a complaint with a supervisory authority — in the United Kingdom the Information Commissioner's Office (ICO), in the EU the authority responsible for you.

Note for end customers of shops using the App: the primary controller for the processing of your order is the respective merchant. Please direct data-subject requests concerning an order to the shop where you placed it.

9. Changes to this policy

This privacy policy will be updated when the App or legal requirements change. The version published here applies.