Privacy Policy: IWV// CSV Exporter Orders
Last updated: 2026-09-24
This policy explains how personal data is processed when a Shopify merchant uses the app "IWV// CSV Exporter Orders" (the "App") and when anyone visits this website. A German version is published at /datenschutz.
1. Who is responsible
IWV DIGITALAGENTUR, Nikolaos Valkanis, Unter den Linden 4, 72762 Reutlingen, Germany. Email: kontakt@iwv-online.com. VAT ID: DE 251 816 595.
Contact for this App and for data protection questions: support@iwv-plugins.de.
2. What the App does, and the two roles IWV has
The App reads a merchant's orders from Shopify and turns them into CSV files in a layout the merchant defines. The merchant downloads the files or has them delivered on a schedule by SFTP, FTPS, FTP or email.
- For the order and customer data inside the exports, the merchant is the controller and IWV is the merchant's processor under a Data Processing Agreement (/dpa) that every merchant accepts before using the App. If you are a customer of a shop that uses the App, please contact that shop: it decides what is exported and where it goes. Requests you make to the shop reach IWV through Shopify, and IWV helps the shop answer them.
- For the data needed to run the App for the merchant — the shop's account, its configuration, its staff's use of the App, security and support — IWV is the controller. Sections 3 to 6 describe both.
3. Data processed
3.1 The merchant's shop
Shop domain, shop name, shop email address, Shopify shop id, the store's language, currency and time zone, the access scopes the shop granted, the Shopify access token (stored encrypted), installation and uninstallation dates, the plan and trial status Shopify reports for the App, and the record of the shop's acceptance of the Data Processing Agreement.
3.2 The merchant's staff
When a staff member uses the App inside the Shopify admin, Shopify identifies them to the App by a Shopify staff user id. The App records that id, and the IP address, with actions on personal data (generating, downloading, delivering or deleting an export; changing a delivery connection; accepting the Data Processing Agreement, where the browser's user agent is recorded as well). The admin sets a session cookie that holds the shop and that staff user id; it is technically necessary and expires with the session.
3.3 The merchant's configuration
Export profiles (column layouts and filters), schedules, delivery connections (server address, user name, remote directory, and the password or private key, stored encrypted; for plain FTP, who confirmed that it is unencrypted and when), and the merchant's own outgoing mail server settings (with the password stored encrypted).
3.4 Order and customer data (processed on the merchant's behalf)
Depending on the columns the merchant chooses, export files contain customers' and recipients' names, email addresses, phone numbers, billing and shipping addresses, and order details (products, quantities, prices, taxes, discounts, statuses, shipping method, notes, tags). The App also keeps:
- the Shopify ids of orders a profile has already exported, when the merchant uses "only orders not exported before" (the "export history");
- for a customer data request Shopify sends, the Shopify customer id and the order ids it names. The customer's email and phone number, which Shopify sends with the request, are not stored.
3.5 Server logs
Errors and warnings are written to log files on the server. Request bodies and server variables are deliberately not logged, so form contents such as passwords do not reach the logs.
3.6 This website
The public pages set no cookies, use no analytics or tracking, and load no third-party resources. The web server processes the IP address to deliver the page.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the App to the merchant: reading orders, generating, storing and delivering exports, the merchant's configuration, the plan | Art. 6(1)(b) GDPR (contract with the merchant); for customer data, on the merchant's instructions under Art. 28 GDPR |
| Security, integrity and traceability: the audit trail, access control, server logs | Art. 6(1)(f) GDPR — legitimate interest in operating the App securely and being able to show who accessed personal data |
| Answering data subject requests and shop and customer erasure requests from Shopify | Art. 6(1)(c) GDPR, and on the merchant's instructions |
| Support requests from merchants | Art. 6(1)(b) GDPR |
The App does not use personal data for advertising, profiling, sale or training AI models, and makes no automated decisions about anyone.
5. Recipients
- Shopify, which the App connects to on the merchant's behalf, whose admin the App runs inside (the admin loads Shopify's App Bridge and Polaris scripts from Shopify's servers), and which bills the merchant for the App.
- Service providers for hosting, database, file storage and email delivery that IWV engages as processors. The current list, with the location of processing, is available at support@iwv-plugins.de.
- Destinations the merchant configures: the merchant's own SFTP, FTPS or FTP servers, the email recipients they enter, and — if the merchant sets one up — the merchant's own outgoing mail server. These receive export files on the merchant's instruction.
6. How long data is kept
A nightly job enforces these periods automatically:
| Data | Retention |
|---|---|
| Export files | 30 days after creation |
| Export history (order ids) | 400 days after the export |
| Audit trail | 365 days |
| Customer data requests | until answered, then 365 days |
| Decrypted copy made for a delivery | deleted immediately after sending, at the latest after one hour |
| Shopify access token | deleted when the App is uninstalled |
| Everything else about the shop (configuration, history, requests, audit trail, the shop record) | deleted when Shopify sends the shop erasure request, 48 hours after uninstallation |
When Shopify sends a customer erasure request, the App removes that customer's orders from the export history at once; export files are removed when their period above ends, because a file the merchant has already downloaded cannot be edited after the fact. Files delivered to the merchant's destinations are kept there under the merchant's control. Server log files are rotated by size and overwritten.
7. Security
Export files are encrypted at rest (XChaCha20-Poly1305), as are Shopify access tokens and delivery and mail passwords; the key is kept outside the database. Communication with Shopify and the App's admin uses TLS, and every Shopify webhook is verified by its signature. The admin can only be used from inside the merchant's Shopify admin, and every request is authenticated by Shopify. Export files are stored outside the web server's document root and are never cached on the way to the merchant. Plain FTP is available only after the merchant confirms that it is unencrypted.
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To exercise them, write to support@iwv-plugins.de. If you are a customer of a shop, please contact the shop first; IWV supports the shop in answering you.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
9. Changes
This policy is updated when the App's processing changes. The date at the top shows the current version.