kaparo

Privacy policy

Last updated 9 October 2026

Kaparo: Preorders & Deposits is a Shopify app that lets a store take pre-orders, with the full price or a deposit at checkout and the balance later. This page says what the app stores, why, where it is kept and for how long.

Kaparo is provided by Mykyta Troiepolskyi, NIP 8993064787, Wrocław, Poland. Questions go to support@kaparo.app.

Whose data, and who decides

A store's customers are the store's, not ours. For their data the merchant decides what happens and Kaparo acts on the merchant's instructions, as a processor in the words of the GDPR. The data processing agreement sets that out. For the few details about the merchant and the store that we need to run the service, we are the controller.

What Kaparo stores

About a store that installs the app:

  • The store's myshopify.com address, its Kaparo plan and its settings in the app.
  • The access tokens Shopify issues to the app, stored encrypted.
  • The sender address and domain the merchant chooses for customer emails, and the logo and colour for them.
  • Each pre-order setup: the product or variant, the deposit, the balance date and the ship date text.

We read the store owner's email address from Shopify when we need to email the merchant about a failed charge or a data request. We don't keep it.

About a customer, and only for an order placed as a pre-order through Kaparo:

  • The customer's name and email address, stored encrypted.
  • The order's number, its lines, the deposit paid, the balance owed and its date, and the status of the balance.
  • Which emails Kaparo sent about that order and when.

Kaparo doesn't ask Shopify for addresses or phone numbers, and it never sees card details: the card stays with Shopify, which makes the charge when Kaparo asks for the balance. Orders that aren't pre-orders are not stored, with one exception: when a product on pre-order is bought without its pre-order terms, Kaparo keeps that order's number and lines, with no customer details, so the merchant can put it right.

The pre-order block on the storefront sets no cookies, makes no network requests and tracks nobody. The app inside the Shopify admin uses Shopify's session tokens, not cookies of its own.

What we use it for

  • To record each pre-order and show the merchant what is paid and what is owed.
  • To charge the balance on its date or when the order ships, through Shopify.
  • To email the customer about their own order: a confirmation of the deposit, a notice before the balance is charged, a change of date, and a message if the charge fails. The merchant can switch each of these off except the change of date.
  • To answer a customer who replies to one of those emails. An email sent from Kaparo's address can't take replies, so a reply gets one automatic answer saying where to write to the shop instead. Our email provider receives the reply and tells Kaparo which address it was sent to. Kaparo doesn't fetch the message, read it, store it or pass it on; it keeps only the record that it sent the answer. The provider deletes the message under its own retention period.
  • To apply a limit per customer, when the merchant sets one.
  • To work out which plan's monthly limit a store is within.
  • To answer support requests and fix faults.

Nothing else. Kaparo sends no marketing, builds no profiles, doesn't sell or rent data and doesn't use it to train anything.

Who else handles it

These companies process data for Kaparo, each for the one job named:

ProviderWhat it doesDataWhere
Fly.io, Inc.Runs the app and its databaseEverything Kaparo storesUnited States (Virginia)
Resend (Plus Five Five, Inc.)Delivers the emails Kaparo sends and receives replies to themThe customer's name and email address and the text of the email; a reply a customer sends to one of those emails; the shop owner's address for emails to the merchantUnited States
Functional Software, Inc. (Sentry)Error reports from the appThe shop's address and technical details of the error. No customer names or emailsEuropean Union (Germany); its account records and job check-ins are kept in the United States
Cloudflare, Inc.DNS for kaparo.app and forwarding of mail sent to the support addressWhatever a merchant writes to supportUnited States and wherever its network is

Shopify is where the orders, payments and customers live in the first place. Kaparo reads from it and writes to it on the merchant's behalf, under Shopify's own terms with the merchant.

Where it is kept

The database is in the United States. For data that comes from the European Economic Area, the United Kingdom or Switzerland, our providers there rely on the EU-U.S. Data Privacy Framework or on the European Commission's standard contractual clauses.

How long we keep it

  • A customer's name and email are erased 90 days after their pre-order is closed (paid in full, cancelled or refunded), and from any pre-order that nothing has touched for a year. The order's amounts and status stay, so the merchant's records still add up.
  • When Shopify passes on a customer's erasure request, that customer's name and email are erased at once and their closed pre-orders are deleted. A pre-order that still owes its balance is kept, without the name or email, until it is settled or 90 days old, and then deleted; its balance is still charged as agreed.
  • When a store uninstalls Kaparo, the app stops working on its orders at once. Shopify asks us to erase the store's data 48 hours later, and everything in Kaparo's database about the store and its customers is deleted when that request arrives.
  • Technical records of background work are deleted after 30 days.
  • The log of each time the app read a customer's name or email is kept for 12 months. It records that a read happened and why, never the name or the address.
  • Backups made by our hosting provider follow the same deletions as they roll over.

How it is protected

  • Everything travels over HTTPS.
  • Names, email addresses and Shopify tokens are encrypted by the app before they reach the database, and the database and its backups are encrypted by the host as well.
  • One person has access to the production systems. The host and the database are behind two-factor sign-in.
  • Error reports carry the store's address and technical details, not customer names or emails.

If personal data is ever exposed or lost, we tell Shopify and each affected merchant within 24 hours of confirming it.

Your rights

If you bought from a store that uses Kaparo, ask that store first: it decides what happens to your data, and a request it makes through Shopify to see or erase your data reaches Kaparo automatically. You can also write to us and we will pass the request to the store.

If you are a merchant, write to support@kaparo.app to see, correct, export or erase what Kaparo holds about you and your store. We answer within 30 days.

Wherever you are, you can also complain to your data protection authority.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change affects how customer data is used, or adds a provider to the list above, merchants are told by email at least 14 days before it takes effect.