Shopify App — Privacy Policy
Effective: May 11, 2026 · Last updated: May 14, 2026 · Version 1.1
Publisher: CivSec S.M.A.R.T B.V. (KvK 98045768)
This Privacy Policy describes how CivSec S.M.A.R.T B.V. ("GivePro", "we", "us", "our") collects, uses, stores, and shares personal data when you (a Shopify merchant or a donor on a merchant's storefront) interact with the GivePro application available on the Shopify App Store.
CivSec S.M.A.R.T B.V. is a Dutch private limited company (Besloten Vennootschap) registered with the Netherlands Chamber of Commerce (KVK) under number 98045768, with its registered office in the Netherlands. Our Data Protection Officer (DPO) is reachable at dpo@civsecsmart.com.
We comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the California Consumer Privacy Act (CCPA, as amended by the CPRA), the Dutch UAVG (Uitvoeringswet AVG), and applicable additional jurisdiction-specific privacy laws.
This policy applies to:
civsecsmart.com/apps/givepro informational pagesIt does not apply to:
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Shop identification | Shop domain, name, primary locale, currency | Shopify OAuth on install | App functionality |
| OAuth credentials | Shopify access token (offline session), API scopes | Shopify OAuth | Authenticate API calls |
| Charity registration | ANBI name, RSIN (NL) / charity number (UK) / EIN (US), address | Merchant onboarding form | Tax-receipt generation |
| Configuration | Modal styling, donation amounts, copy overrides, recurring frequencies, integrations | Merchant admin UI | App functionality |
| Billing | Plan tier, billing-cycle status, install/uninstall timestamps | Shopify Managed Pricing | Plan enforcement |
| Category | Examples | When | Purpose | Optional? |
|---|---|---|---|---|
| Donation details | Amount, currency, cause, frequency, payment method | Modal interaction | Receipt + analytics | Required |
| Donor email | Modal personal-info step | Receipt delivery + recurring contract | Required for receipt | |
| Name | Donor full name | Modal personal-info step | Receipt + recognition wall (opt-in) | Required for receipt |
| Postal address | Street, postcode, city, country | Modal personal-info step | UK Gift Aid HMRC declaration; NL ANBI onderhandse akte | Optional unless jurisdiction requires |
| Date of birth | DOB | Modal (NL ANBI recurring only) | Onderhandse akte signing-party identification | Optional unless NL_ANBI + recurring |
| UK Gift Aid declaration | Tax-payer confirmation checkbox + IP + timestamp | Modal personal-info (UK only, >£30) | HMRC compliance | Required for Gift Aid claims |
| Honor / memorial dedication | Recipient name, optional message, optional notify-email | Modal honor-memorial step | Donation attribution | Optional |
| Match-funding employer | Employer name | Modal match-funding step | Employer-match tracking | Optional |
| Recurring contract | Subscription contract ID, schedule, status | Shopify subscription webhooks | Recurring lifecycle | Required for recurring |
We do not collect:
GivePro sets two functional cookies on storefront donor browsers:
| Cookie | Type | Lifetime | Purpose |
|---|---|---|---|
gp_variant | First-party, functional | 30 days | A/B testing variant stickiness |
gp_session | First-party, functional | 30 days | Session identifier for experiment-event correlation (no PII linkage) |
These cookies are strictly necessary for the functionality the donor explicitly chose (donating via the modal) and qualify as "essential" under the EU ePrivacy Directive — no consent banner is required for these specific cookies. We do not set advertising or analytics cookies.
We collect aggregate, non-identifying metrics:
ExperimentEvent table)These metrics are bound to the merchant's shop ID and the donor's gp_session cookie value — not to donor email, name, or any other directly identifying field.
| Processing activity | Lawful basis |
|---|---|
| Generating + sending tax receipts | Art 6.1.c — legal obligation (tax law in NL/UK/US) |
| Storing donation records for audit | Art 6.1.c — legal obligation (NL Belastingdienst 7-year retention; UK HMRC 6-year for Gift Aid; US IRS 7-year) |
| Creating + executing recurring contracts | Art 6.1.b — performance of a contract with the donor |
| Sending GivePro service emails to merchants | Art 6.1.b — performance of a contract with the merchant |
| Improving GivePro features (aggregate analytics) | Art 6.1.f — legitimate interest, balanced against donor expectations of minimum-data collection |
| Donor recognition wall display | Art 6.1.a — explicit donor consent (default OFF; opt-in required) |
| CRM event push (Klaviyo / Mailchimp / HubSpot) | Merchant's lawful basis under their own privacy policy — GivePro acts as data processor |
| Customer Account UI extension donor portal | Art 6.1.b — donor accessing their own data |
| Custom CSS injection | Merchant configuration; no donor data involved |
| Data category | Retention | Reason |
|---|---|---|
| Merchant configuration (non-donor) | Lifetime of installation; deleted 48h after uninstall via shop/redact webhook | Operational |
| Donor PII (email, name, address) | Default 7 yr for NL (Belastingdienst); 6 yr for UK (HMRC Gift Aid); 7 yr for US (IRS); 5 yr for Generic | Tax-law mandated |
| Donation records (anonymised after donor redact) | Same retention; donor PII scrubbed on customers/redact while financial record retained for audit | GDPR balance against legal obligation |
| Receipt PDFs (Vercel Blob) | Same retention as donation records | Tax-audit availability |
WebhookLog audit trail | 24 months | Operational + GDPR audit |
ExperimentEvent aggregate analytics | 24 months | Statistical significance windows |
Session cookies (gp_variant, gp_session) | 30 days | Cookie max-age |
| OAuth access tokens | Until uninstall or rotation | Operational |
Per-shop retention overrides: merchants may configure a longer retention period via ShopConfig.receiptRetentionYears (admin → Receipts → Settings) up to a maximum of 10 years. Reductions below the legally required minimum are not permitted.
We share data only with the following sub-processors, all under Data Processing Agreements (DPAs) and (where applicable) EU Standard Contractual Clauses (SCCs):
| Sub-processor | Role | Location | DPA / SCC |
|---|---|---|---|
| Shopify, Inc. | App platform host; OAuth + billing + theme extensions | CA (data residency varies per merchant primary region) | DPA via Shopify Partner Program Agreement |
| Vercel, Inc. | Application hosting (admin app + widget CDN) | US (East/West) + EU (Frankfurt for EU shops) | DPA + SCCs |
| Neon, Inc. | PostgreSQL database (donor records, donations, receipts) | EU Frankfurt (eu-central-1) | DPA + SCCs |
| Resend, Inc. | Transactional email (receipts, recurring confirmations) | US | DPA + SCCs |
| Sentry (Functional Software, Inc.) | Error monitoring (de.sentry.io EU instance) | EU (Germany) | DPA |
| Klaviyo, Inc. (optional, merchant-enabled) | CRM event push | US | Merchant's DPA with Klaviyo |
| Mailchimp (Intuit Mailchimp, optional) | CRM event push | US | Merchant's DPA with Mailchimp |
| HubSpot, Inc. (optional, merchant-enabled) | CRM contact upsert | US | Merchant's DPA with HubSpot |
| Google LLC (Analytics) | App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for the donor flow on merchant storefronts. | US | Google Cloud DPA + SCCs |
We do not sell, rent, or trade donor or merchant personal data to third parties for any purpose, including marketing.
The GivePro App Store listing page on apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a small set of install-funnel events (listing view, click on Install button, completed install, arrival from a Shopify App Store ad) to our Google Analytics 4 property so we can measure listing performance. Those events are governed by Shopify privacy policy on apps.shopify.com. The listing analytics flow is fully separated from the donor flow described in sections 3.3 and 3.4 and does not affect the donor cookies or the no-analytics-cookies statement made for the storefront modal.
Donor PII originating in the EU is stored primarily on Neon's eu-central-1 (Frankfurt) database to keep data in the EU/EEA. Where data necessarily transits to a sub-processor outside the EU (e.g. Resend in the US for transactional email delivery), we rely on:
Where the GivePro merchant is located outside the EU and serves donors outside the EU, data may be hosted in regional Vercel + Neon endpoints to optimise latency, again under DPAs and SCCs.
You have the following rights under GDPR (and equivalents under CCPA / UAVG / UK GDPR):
| Right | How to exercise |
|---|---|
| Access (Art 15) | Email dpo@civsecsmart.com with subject "Access request — [shop domain]". We respond within 30 days. Donors may also request access via the merchant's storefront contact. |
| Rectification (Art 16) | Email dpo@civsecsmart.com or correct via the Customer Account UI extension donor portal (Pro shops). |
| Erasure / Right to be forgotten (Art 17) | Email dpo@civsecsmart.com. Note: financial records subject to legal-retention obligation are not erasable until the retention period expires; PII is anonymised while the donation record is retained for audit. |
| Restriction (Art 18) | Email dpo@civsecsmart.com. |
| Portability (Art 20) | Pro-tier merchants can export donor data as ZIP via admin /app/donors/export/[id]. Donors without merchant assistance may email dpo@civsecsmart.com. |
| Objection (Art 21) | Email dpo@civsecsmart.com. |
| Automated decisions (Art 22) | We do not engage in automated decision-making with legal/significant effect on donors. |
Donors of US shops have additional CCPA rights including:
We respond to all rights requests within 30 days (GDPR), 45 days (CCPA), or sooner.
We implement technical and organisational measures appropriate to the risk:
WebhookLog@import / url(http) / expression() / javascript: permittedWe comply with the Shopify Built for Shopify security standards where relevant to the badge program.
GivePro is intended for use by Shopify merchants and adult donors. We do not knowingly collect personal data from individuals under the age of 16 (EU/EEA), 13 (US), or the equivalent local age of digital consent. If we become aware that a child has submitted personal data, we will delete it without undue delay. Parents or guardians who believe their child has interacted with GivePro may contact dpo@civsecsmart.com.
In the event of a personal data breach likely to result in a risk to donors' or merchants' rights and freedoms, we will notify the relevant Supervisory Authority (the Dutch Autoriteit Persoonsgegevens for our establishment) within 72 hours of becoming aware of the breach (GDPR Art 33), and notify affected merchants and donors without undue delay where the breach is likely to result in a high risk (Art 34).
We may update this policy to reflect changes in law, our practices, or the GivePro feature set. Material changes will be notified via:
/app)A revision history is maintained:
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-05-11 | Initial publication |
| 1.1 | 2026-05-14 | Added Google LLC (Analytics) subprocessor row in section 6 plus App Store listing analytics paragraph covering GA4 tracking activated 2026-05-14. Donor flow unchanged. |
| Topic | Contact |
|---|---|
| Privacy questions / DPO | dpo@civsecsmart.com |
| Data subject access requests | dpo@civsecsmart.com |
| Security disclosure | security@civsecsmart.com |
| Legal / contractual | legal@civsecsmart.com |
| Support / billing | givepro-support@civsecsmart.com |
| Postal address | CivSec S.M.A.R.T B.V., available on request via dpo@civsecsmart.com, Netherlands |
| EU Representative | n/a (we are EU-established) |
| KVK | 98045768 |
Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change.