Shopify App — Privacy Policy
GivePro — Privacy Policy
Effective: May 11, 2026 · Last updated: May 14, 2026 · Version 1.1
Publisher: CivSec Protection B.V., trading as CivSec S.M.A.R.T (KvK 98045768)
1. Introduction
This Privacy Policy describes how CivSec S.M.A.R.T ("GivePro", "we", "us", "our") collects, uses, stores, and shares personal data when you (a Shopify merchant or a donor on a merchant's storefront) interact with the GivePro application available on the Shopify App Store.
CivSec Protection B.V., trading as CivSec S.M.A.R.T, is a Dutch private limited company (Besloten Vennootschap) registered with the Netherlands Chamber of Commerce (KVK) under number 98045768, with its registered office in the Netherlands. Our Data Protection Officer (DPO) is reachable at dpo@civsecsmart.com.
We comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the California Consumer Privacy Act (CCPA, as amended by the CPRA), the Dutch UAVG (Uitvoeringswet AVG), and applicable additional jurisdiction-specific privacy laws.
2. Scope and applicability
This policy applies to:
- Merchants — Shopify store owners who install GivePro
- Donors — end-customers who interact with the GivePro modal, complete a donation, or receive a tax receipt on a merchant's storefront
- Visitors — anyone visiting
civsecsmart.com/apps/giveproinformational pages
It does not apply to:
- Personal data merchants collect on their own storefront outside the GivePro application — that data is governed by the merchant's own privacy policy
- Personal data Shopify processes as the platform operator — see shopify.com/legal/privacy
3. Data we collect
3.1 From merchants
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Shop identification | Shop domain, name, primary locale, currency | Shopify OAuth on install | App functionality |
| OAuth credentials | Shopify access token (offline session), API scopes | Shopify OAuth | Authenticate API calls |
| Charity registration | ANBI name, RSIN (NL) / charity number (UK) / EIN (US), address | Merchant onboarding form | Tax-receipt generation |
| Configuration | Modal styling, donation amounts, copy overrides, recurring frequencies, integrations | Merchant admin UI | App functionality |
| Billing | Plan tier, billing-cycle status, install/uninstall timestamps | Shopify Managed Pricing | Plan enforcement |
3.2 From donors (end-customers on merchant storefronts)
| Category | Examples | When | Purpose | Optional? |
|---|---|---|---|---|
| Donation details | Amount, currency, cause, frequency, payment method | Modal interaction | Receipt + analytics | Required |
| Donor email | Modal personal-info step | Receipt delivery + recurring contract | Required for receipt | |
| Name | Donor full name | Modal personal-info step | Receipt + recognition wall (opt-in) | Required for receipt |
| Postal address | Street, postcode, city, country | Modal personal-info step | UK Gift Aid HMRC declaration; NL ANBI onderhandse akte | Optional unless jurisdiction requires |
| Date of birth | DOB | Modal (NL ANBI recurring only) | Onderhandse akte signing-party identification | Optional unless NL_ANBI + recurring |
| UK Gift Aid declaration | Tax-payer confirmation checkbox + IP + timestamp | Modal personal-info (UK only, >£30) | HMRC compliance | Required for Gift Aid claims |
| Honor / memorial dedication | Recipient name, optional message, optional notify-email | Modal honor-memorial step | Donation attribution | Optional |
| Match-funding employer | Employer name | Modal match-funding step | Employer-match tracking | Optional |
| Recurring contract | Subscription contract ID, schedule, status | Shopify subscription webhooks | Recurring lifecycle | Required for recurring |
We do not collect:
- Payment card numbers, CVC, or bank account details — these are handled by Shopify's PCI-DSS compliant payment infrastructure and never reach GivePro servers
- Donor location data via geolocation APIs
- Cross-site tracking cookies, advertising identifiers, or third-party trackers
3.3 Cookies and similar technologies
GivePro sets two functional cookies on storefront donor browsers:
| Cookie | Type | Lifetime | Purpose |
|---|---|---|---|
gp_variant | First-party, functional | 30 days | A/B testing variant stickiness |
gp_session | First-party, functional | 30 days | Session identifier for experiment-event correlation (no PII linkage) |
These cookies are strictly necessary for the functionality the donor explicitly chose (donating via the modal) and qualify as "essential" under the EU ePrivacy Directive — no consent banner is required for these specific cookies. We do not set advertising or analytics cookies.
3.4 Server-side analytics
We collect aggregate, non-identifying metrics:
- Modal impressions, amount-tile clicks, conversions (event-level via
ExperimentEventtable) - Donation completion rates, drop-off points in multi-step flow
- Average gift size, recurring uptake percentage
These metrics are bound to the merchant's shop ID and the donor's
gp_session cookie value — not to donor email, name,
or any other directly identifying field.
4. Lawful bases for processing (GDPR Art 6)
| Processing activity | Lawful basis |
|---|---|
| Generating + sending tax receipts | Art 6.1.c — legal obligation (tax law in NL/UK/US) |
| Storing donation records for audit | Art 6.1.c — legal obligation (NL Belastingdienst 7-year retention; UK HMRC 6-year for Gift Aid; US IRS 7-year) |
| Creating + executing recurring contracts | Art 6.1.b — performance of a contract with the donor |
| Sending GivePro service emails to merchants | Art 6.1.b — performance of a contract with the merchant |
| Improving GivePro features (aggregate analytics) | Art 6.1.f — legitimate interest, balanced against donor expectations of minimum-data collection |
| Donor recognition wall display | Art 6.1.a — explicit donor consent (default OFF; opt-in required) |
| CRM event push (Klaviyo / Mailchimp / HubSpot) | Merchant's lawful basis under their own privacy policy — GivePro acts as data processor |
| Customer Account UI extension donor portal | Art 6.1.b — donor accessing their own data |
| Custom CSS injection | Merchant configuration; no donor data involved |
5. Data retention
| Data category | Retention | Reason |
|---|---|---|
| Merchant configuration (non-donor) | Lifetime of installation; deleted 48h after uninstall via shop/redact webhook | Operational |
| Donor PII (email, name, address) | Default 7 yr for NL (Belastingdienst); 6 yr for UK (HMRC Gift Aid); 7 yr for US (IRS); 5 yr for Generic | Tax-law mandated |
| Donation records (anonymised after donor redact) | Same retention; donor PII scrubbed on customers/redact while financial record retained for audit | GDPR balance against legal obligation |
| Receipt PDFs (Vercel Blob) | Same retention as donation records | Tax-audit availability |
WebhookLog audit trail | 24 months | Operational + GDPR audit |
ExperimentEvent aggregate analytics | 24 months | Statistical significance windows |
Session cookies (gp_variant, gp_session) | 30 days | Cookie max-age |
| OAuth access tokens | Until uninstall or rotation | Operational |
Per-shop retention overrides: merchants may configure a longer
retention period via ShopConfig.receiptRetentionYears (admin → Receipts
→ Settings) up to a maximum of 10 years. Reductions below the legally required
minimum are not permitted.
6. Data sharing and sub-processors
We share data only with the following sub-processors, all under Data Processing Agreements (DPAs) and (where applicable) EU Standard Contractual Clauses (SCCs):
| Sub-processor | Role | Location | DPA / SCC |
|---|---|---|---|
| Shopify, Inc. | App platform host; OAuth + billing + theme extensions | CA (data residency varies per merchant primary region) | DPA via Shopify Partner Program Agreement |
| Vercel, Inc. | Application hosting (admin app + widget CDN) | US (East/West) + EU (Frankfurt for EU shops) | DPA + SCCs |
| Neon, Inc. | PostgreSQL database (donor records, donations, receipts) | EU Frankfurt (eu-central-1) | DPA + SCCs |
| Resend, Inc. | Transactional email (receipts, recurring confirmations) | US | DPA + SCCs |
| Sentry (Functional Software, Inc.) | Error monitoring (de.sentry.io EU instance) | EU (Germany) | DPA |
| Klaviyo, Inc. (optional, merchant-enabled) | CRM event push | US | Merchant's DPA with Klaviyo |
| Mailchimp (Intuit Mailchimp, optional) | CRM event push | US | Merchant's DPA with Mailchimp |
| HubSpot, Inc. (optional, merchant-enabled) | CRM contact upsert | US | Merchant's DPA with HubSpot |
| Google LLC (Analytics) | App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for the donor flow on merchant storefronts. | US | Google Cloud DPA + SCCs |
We do not sell, rent, or trade donor or merchant personal data to third parties for any purpose, including marketing.
The GivePro App Store listing page on
apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a
small set of install-funnel events (listing view, click on Install button, completed
install, arrival from a Shopify App Store ad) to our Google Analytics 4 property so
we can measure listing performance. Those events are governed by Shopify privacy
policy on apps.shopify.com. The listing analytics flow is fully separated from the
donor flow described in sections 3.3 and 3.4 and does not affect the donor cookies
or the no-analytics-cookies statement made for the storefront modal.
7. International data transfers
Donor PII originating in the EU is stored primarily on Neon's
eu-central-1 (Frankfurt) database to keep data in the EU/EEA. Where
data necessarily transits to a sub-processor outside the EU (e.g. Resend in the US
for transactional email delivery), we rely on:
- EU Standard Contractual Clauses (SCCs) — Module 3 (processor-to-processor) where applicable
- Adequacy decisions for jurisdictions with EU Commission adequacy (e.g. UK)
- Transfer Impact Assessments for the US, Canada, and other non-adequate destinations, including supplementary measures (encryption-in-transit + at-rest, contractual restrictions)
Where the GivePro merchant is located outside the EU and serves donors outside the EU, data may be hosted in regional Vercel + Neon endpoints to optimise latency, again under DPAs and SCCs.
8. Donor and merchant rights
You have the following rights under GDPR (and equivalents under CCPA / UAVG / UK GDPR):
| Right | How to exercise |
|---|---|
| Access (Art 15) | Email dpo@civsecsmart.com with subject "Access request — [shop domain]". We respond within 30 days. Donors may also request access via the merchant's storefront contact. |
| Rectification (Art 16) | Email dpo@civsecsmart.com or correct via the Customer Account UI extension donor portal (Pro shops). |
| Erasure / Right to be forgotten (Art 17) | Email dpo@civsecsmart.com. Note: financial records subject to legal-retention obligation are not erasable until the retention period expires; PII is anonymised while the donation record is retained for audit. |
| Restriction (Art 18) | Email dpo@civsecsmart.com. |
| Portability (Art 20) | Pro-tier merchants can export donor data as ZIP via admin /app/donors/export/[id]. Donors without merchant assistance may email dpo@civsecsmart.com. |
| Objection (Art 21) | Email dpo@civsecsmart.com. |
| Automated decisions (Art 22) | We do not engage in automated decision-making with legal/significant effect on donors. |
Donors of US shops have additional CCPA rights including:
- Right to know what personal information is collected and shared
- Right to delete personal information
- Right to opt-out of sale (we do not sell personal information; opt-out automatic)
- Right to non-discrimination for exercising rights
We respond to all rights requests within 30 days (GDPR), 45 days (CCPA), or sooner.
9. Security measures
We implement technical and organisational measures appropriate to the risk:
- Encryption in transit: TLS 1.2+ for all admin and storefront endpoints, Vercel-managed certificates with auto-renewal
- Encryption at rest: Neon Postgres encrypts data at rest using AES-256 (provider-managed keys). Vercel Blob storage uses S3-compatible AES-256
- Access controls: Engineering access to production data is limited to authorised personnel via multi-factor authentication. CivSec S.M.A.R.T employees with production access are documented in our internal access register
- OWASP Top 10 mitigation: Standard practice review of injection, broken auth, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialization, vulnerable components, insufficient logging
- Webhook HMAC verification: All Shopify webhooks verified via HMAC-SHA256 before processing. Replay-attacks mitigated via SHA-256 payload-hash idempotency in
WebhookLog - Custom CSS sandbox: Pro-tier custom CSS validated server-side AND client-side, scoped via shadow-DOM, no
@import/url(http)/expression()/javascript:permitted - Subscription scope-approval: Recurring donations gated behind Shopify's separate Subscription APIs scope-approval process before activation
- Vulnerability disclosure: Responsible-disclosure contact at security@civsecsmart.com, per /.well-known/security.txt (RFC 9116)
We comply with the Shopify Built for Shopify security standards where relevant to the badge program.
10. Children's data
GivePro is intended for use by Shopify merchants and adult donors. We do not knowingly collect personal data from individuals under the age of 16 (EU/EEA), 13 (US), or the equivalent local age of digital consent. If we become aware that a child has submitted personal data, we will delete it without undue delay. Parents or guardians who believe their child has interacted with GivePro may contact dpo@civsecsmart.com.
11. Data breach notification
In the event of a personal data breach likely to result in a risk to donors' or merchants' rights and freedoms, we will notify the relevant Supervisory Authority (the Dutch Autoriteit Persoonsgegevens for our establishment) within 72 hours of becoming aware of the breach (GDPR Art 33), and notify affected merchants and donors without undue delay where the breach is likely to result in a high risk (Art 34).
12. Changes to this policy
We may update this policy to reflect changes in law, our practices, or the GivePro feature set. Material changes will be notified via:
- Email to merchants (developer-account email on file)
- Banner notification in GivePro admin (
/app) - Updated "Last updated" date at the top of this page
A revision history is maintained:
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-05-11 | Initial publication |
| 1.1 | 2026-05-14 | Added Google LLC (Analytics) subprocessor row in section 6 plus App Store listing analytics paragraph covering GA4 tracking activated 2026-05-14. Donor flow unchanged. |
13. Contact
| Topic | Contact |
|---|---|
| Privacy questions / DPO | dpo@civsecsmart.com |
| Data subject access requests | dpo@civsecsmart.com |
| Security disclosure | security@civsecsmart.com |
| Legal / contractual | legal@civsecsmart.com |
| Support / billing | givepro-support@civsecsmart.com |
| Postal address | CivSec Protection B.V. (trading as CivSec S.M.A.R.T), available on request via dpo@civsecsmart.com, Netherlands |
| EU Representative | n/a (we are EU-established) |
| KVK | 98045768 |
Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change.