Privacy Policy
KM Payment Rules
Last updated: August 2026
1. Controller
The controller for data processing in connection with the Shopify app "KM Payment Rules" (the "App") is:
KEVIN METZDORF LTD
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Email: info@kevin-metzdorf.com
2. The essentials in brief
The App controls which payment methods a customer sees in Shopify checkout, in what order and under what name. The rules run as a Shopify Function on Shopify's infrastructure. The data needed to evaluate a rule — cart, shipping country, customer tags, selected shipping method — is evaluated there and never reaches the App's servers. The App stores only the merchant's shop and configuration data. End-customer data is never stored.
3. What data the App processes
a) Shop and configuration data (stored)
When the App is installed and used, the following is stored: the shop
domain, the OAuth access token issued by Shopify (short-lived, expires
automatically), session data of the user signed in to the Shopify admin,
the rules and settings created by the merchant — that is, payment method
names, rule conditions such as cart-value thresholds, country codes,
customer-tag names, and product or collection IDs with their labels —
and the selected app language. The App requests only the
write_payment_customizations permission from Shopify. The
legal basis is the performance of a contract (Art. 6(1)(b) GDPR / UK
GDPR).
b) End-customer checkout data (not on the App's servers)
The App stores no end-customer data: no orders, no names, addresses or email addresses, no payment data. Rule evaluation at checkout runs as a Shopify Function directly on Shopify's infrastructure — the checkout's cart and customer data never reach the App's servers and are neither stored nor logged there. The controller for processing this data at checkout is the respective merchant, with Shopify as their processor.
c) Merchant contact data
Through the Shopify session, the name and email address of the user logged into the Shopify admin may technically occur (standard session fields of the Shopify SDK). No storage or use beyond this takes place.
4. Recipients and processors
Fly.io Inc. (USA) operates the server infrastructure of the App's admin interface as hosting provider, including the Postgres database and log storage. The server location is Frankfurt am Main, Germany (EU region); as Fly.io is a US company, it is engaged on the basis of EU Standard Contractual Clauses (SCCs). The logs contain no personal data of end customers.
Shopify, as the e-commerce platform, is the technical origin of all data and executes the App's Shopify Function on its own infrastructure. Shopify's privacy policy applies to processing by Shopify.
There are no other recipients — the App uses no analytics, tracking, error-tracking or email services.
5. International transfers
The controller is established in the United Kingdom; an adequacy decision of the European Commission exists for transfers from the EU. For the US provider Fly.io, EU Standard Contractual Clauses apply with a server location in Germany.
6. Retention and deletion
End-customer data: not stored (see above). Shop and configuration data
is stored for as long as the App is installed in the shop. After
uninstallation, Shopify sends the deletion request
(shop/redact, usually 48 hours later) — upon which all
stored data of the shop is deleted completely and irreversibly: rules,
settings, session data and the access token. Shopify removes the payment
customizations created by the App with the uninstallation.
7. Shopify privacy webhooks
The App implements all privacy endpoints mandated by Shopify: data
requests (customers/data_request) and deletion requests
(customers/redact) are answered — since the App does not
store end-customer data, there is nothing to hand over or delete. The
shop deletion request (shop/redact) leads to the complete
deletion described in section 6.
8. Your rights
Data subjects have — within the scope of the applicable law (GDPR / UK GDPR) — the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Please contact info@kevin-metzdorf.com. You also have the right to lodge a complaint with a data protection supervisory authority — in the United Kingdom the Information Commissioner's Office (ICO), in the EU the authority responsible for you.
Note for end customers of shops using the App: the controller for the processing of your order data is primarily the respective merchant. Please direct data subject requests about an order to the shop you ordered from.
9. Changes to this privacy policy
This privacy policy is updated when the App or legal requirements change. The version published here applies.