Shopify App — Privacy Policy

GivePro — Privacy Policy

Effective: May 11, 2026 · Last updated: May 14, 2026 · Version 1.1

Publisher: CivSec Protection B.V., trading as CivSec S.M.A.R.T (KvK 98045768)

1. Introduction

This Privacy Policy describes how CivSec S.M.A.R.T ("GivePro", "we", "us", "our") collects, uses, stores, and shares personal data when you (a Shopify merchant or a donor on a merchant's storefront) interact with the GivePro application available on the Shopify App Store.

CivSec Protection B.V., trading as CivSec S.M.A.R.T, is a Dutch private limited company (Besloten Vennootschap) registered with the Netherlands Chamber of Commerce (KVK) under number 98045768, with its registered office in the Netherlands. Our Data Protection Officer (DPO) is reachable at dpo@civsecsmart.com.

We comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the California Consumer Privacy Act (CCPA, as amended by the CPRA), the Dutch UAVG (Uitvoeringswet AVG), and applicable additional jurisdiction-specific privacy laws.

2. Scope and applicability

This policy applies to:

  • Merchants — Shopify store owners who install GivePro
  • Donors — end-customers who interact with the GivePro modal, complete a donation, or receive a tax receipt on a merchant's storefront
  • Visitors — anyone visiting civsecsmart.com/apps/givepro informational pages

It does not apply to:

  • Personal data merchants collect on their own storefront outside the GivePro application — that data is governed by the merchant's own privacy policy
  • Personal data Shopify processes as the platform operator — see shopify.com/legal/privacy

3. Data we collect

3.1 From merchants

CategoryExamplesSourcePurpose
Shop identificationShop domain, name, primary locale, currencyShopify OAuth on installApp functionality
OAuth credentialsShopify access token (offline session), API scopesShopify OAuthAuthenticate API calls
Charity registrationANBI name, RSIN (NL) / charity number (UK) / EIN (US), addressMerchant onboarding formTax-receipt generation
ConfigurationModal styling, donation amounts, copy overrides, recurring frequencies, integrationsMerchant admin UIApp functionality
BillingPlan tier, billing-cycle status, install/uninstall timestampsShopify Managed PricingPlan enforcement

3.2 From donors (end-customers on merchant storefronts)

CategoryExamplesWhenPurposeOptional?
Donation detailsAmount, currency, cause, frequency, payment methodModal interactionReceipt + analyticsRequired
EmailDonor emailModal personal-info stepReceipt delivery + recurring contractRequired for receipt
NameDonor full nameModal personal-info stepReceipt + recognition wall (opt-in)Required for receipt
Postal addressStreet, postcode, city, countryModal personal-info stepUK Gift Aid HMRC declaration; NL ANBI onderhandse akteOptional unless jurisdiction requires
Date of birthDOBModal (NL ANBI recurring only)Onderhandse akte signing-party identificationOptional unless NL_ANBI + recurring
UK Gift Aid declarationTax-payer confirmation checkbox + IP + timestampModal personal-info (UK only, >£30)HMRC complianceRequired for Gift Aid claims
Honor / memorial dedicationRecipient name, optional message, optional notify-emailModal honor-memorial stepDonation attributionOptional
Match-funding employerEmployer nameModal match-funding stepEmployer-match trackingOptional
Recurring contractSubscription contract ID, schedule, statusShopify subscription webhooksRecurring lifecycleRequired for recurring

We do not collect:

  • Payment card numbers, CVC, or bank account details — these are handled by Shopify's PCI-DSS compliant payment infrastructure and never reach GivePro servers
  • Donor location data via geolocation APIs
  • Cross-site tracking cookies, advertising identifiers, or third-party trackers

3.3 Cookies and similar technologies

GivePro sets two functional cookies on storefront donor browsers:

CookieTypeLifetimePurpose
gp_variantFirst-party, functional30 daysA/B testing variant stickiness
gp_sessionFirst-party, functional30 daysSession identifier for experiment-event correlation (no PII linkage)

These cookies are strictly necessary for the functionality the donor explicitly chose (donating via the modal) and qualify as "essential" under the EU ePrivacy Directive — no consent banner is required for these specific cookies. We do not set advertising or analytics cookies.

3.4 Server-side analytics

We collect aggregate, non-identifying metrics:

  • Modal impressions, amount-tile clicks, conversions (event-level via ExperimentEvent table)
  • Donation completion rates, drop-off points in multi-step flow
  • Average gift size, recurring uptake percentage

These metrics are bound to the merchant's shop ID and the donor's gp_session cookie value — not to donor email, name, or any other directly identifying field.

4. Lawful bases for processing (GDPR Art 6)

Processing activityLawful basis
Generating + sending tax receiptsArt 6.1.c — legal obligation (tax law in NL/UK/US)
Storing donation records for auditArt 6.1.c — legal obligation (NL Belastingdienst 7-year retention; UK HMRC 6-year for Gift Aid; US IRS 7-year)
Creating + executing recurring contractsArt 6.1.b — performance of a contract with the donor
Sending GivePro service emails to merchantsArt 6.1.b — performance of a contract with the merchant
Improving GivePro features (aggregate analytics)Art 6.1.f — legitimate interest, balanced against donor expectations of minimum-data collection
Donor recognition wall displayArt 6.1.a — explicit donor consent (default OFF; opt-in required)
CRM event push (Klaviyo / Mailchimp / HubSpot)Merchant's lawful basis under their own privacy policy — GivePro acts as data processor
Customer Account UI extension donor portalArt 6.1.b — donor accessing their own data
Custom CSS injectionMerchant configuration; no donor data involved

5. Data retention

Data categoryRetentionReason
Merchant configuration (non-donor)Lifetime of installation; deleted 48h after uninstall via shop/redact webhookOperational
Donor PII (email, name, address)Default 7 yr for NL (Belastingdienst); 6 yr for UK (HMRC Gift Aid); 7 yr for US (IRS); 5 yr for GenericTax-law mandated
Donation records (anonymised after donor redact)Same retention; donor PII scrubbed on customers/redact while financial record retained for auditGDPR balance against legal obligation
Receipt PDFs (Vercel Blob)Same retention as donation recordsTax-audit availability
WebhookLog audit trail24 monthsOperational + GDPR audit
ExperimentEvent aggregate analytics24 monthsStatistical significance windows
Session cookies (gp_variant, gp_session)30 daysCookie max-age
OAuth access tokensUntil uninstall or rotationOperational

Per-shop retention overrides: merchants may configure a longer retention period via ShopConfig.receiptRetentionYears (admin → Receipts → Settings) up to a maximum of 10 years. Reductions below the legally required minimum are not permitted.

6. Data sharing and sub-processors

We share data only with the following sub-processors, all under Data Processing Agreements (DPAs) and (where applicable) EU Standard Contractual Clauses (SCCs):

Sub-processorRoleLocationDPA / SCC
Shopify, Inc.App platform host; OAuth + billing + theme extensionsCA (data residency varies per merchant primary region)DPA via Shopify Partner Program Agreement
Vercel, Inc.Application hosting (admin app + widget CDN)US (East/West) + EU (Frankfurt for EU shops)DPA + SCCs
Neon, Inc.PostgreSQL database (donor records, donations, receipts)EU Frankfurt (eu-central-1)DPA + SCCs
Resend, Inc.Transactional email (receipts, recurring confirmations)USDPA + SCCs
Sentry (Functional Software, Inc.)Error monitoring (de.sentry.io EU instance)EU (Germany)DPA
Klaviyo, Inc. (optional, merchant-enabled)CRM event pushUSMerchant's DPA with Klaviyo
Mailchimp (Intuit Mailchimp, optional)CRM event pushUSMerchant's DPA with Mailchimp
HubSpot, Inc. (optional, merchant-enabled)CRM contact upsertUSMerchant's DPA with HubSpot
Google LLC (Analytics)App Store listing analytics (GA4) for pre-install merchant traffic on apps.shopify.com. Receives install-funnel events forwarded by Shopify (shop_id, shop_name, surface attribution). Not used for the donor flow on merchant storefronts.USGoogle Cloud DPA + SCCs

We do not sell, rent, or trade donor or merchant personal data to third parties for any purpose, including marketing.

The GivePro App Store listing page on apps.shopify.com is hosted by Shopify, not by us. Shopify forwards a small set of install-funnel events (listing view, click on Install button, completed install, arrival from a Shopify App Store ad) to our Google Analytics 4 property so we can measure listing performance. Those events are governed by Shopify privacy policy on apps.shopify.com. The listing analytics flow is fully separated from the donor flow described in sections 3.3 and 3.4 and does not affect the donor cookies or the no-analytics-cookies statement made for the storefront modal.

7. International data transfers

Donor PII originating in the EU is stored primarily on Neon's eu-central-1 (Frankfurt) database to keep data in the EU/EEA. Where data necessarily transits to a sub-processor outside the EU (e.g. Resend in the US for transactional email delivery), we rely on:

  • EU Standard Contractual Clauses (SCCs) — Module 3 (processor-to-processor) where applicable
  • Adequacy decisions for jurisdictions with EU Commission adequacy (e.g. UK)
  • Transfer Impact Assessments for the US, Canada, and other non-adequate destinations, including supplementary measures (encryption-in-transit + at-rest, contractual restrictions)

Where the GivePro merchant is located outside the EU and serves donors outside the EU, data may be hosted in regional Vercel + Neon endpoints to optimise latency, again under DPAs and SCCs.

8. Donor and merchant rights

You have the following rights under GDPR (and equivalents under CCPA / UAVG / UK GDPR):

RightHow to exercise
Access (Art 15)Email dpo@civsecsmart.com with subject "Access request — [shop domain]". We respond within 30 days. Donors may also request access via the merchant's storefront contact.
Rectification (Art 16)Email dpo@civsecsmart.com or correct via the Customer Account UI extension donor portal (Pro shops).
Erasure / Right to be forgotten (Art 17)Email dpo@civsecsmart.com. Note: financial records subject to legal-retention obligation are not erasable until the retention period expires; PII is anonymised while the donation record is retained for audit.
Restriction (Art 18)Email dpo@civsecsmart.com.
Portability (Art 20)Pro-tier merchants can export donor data as ZIP via admin /app/donors/export/[id]. Donors without merchant assistance may email dpo@civsecsmart.com.
Objection (Art 21)Email dpo@civsecsmart.com.
Automated decisions (Art 22)We do not engage in automated decision-making with legal/significant effect on donors.

Donors of US shops have additional CCPA rights including:

  • Right to know what personal information is collected and shared
  • Right to delete personal information
  • Right to opt-out of sale (we do not sell personal information; opt-out automatic)
  • Right to non-discrimination for exercising rights

We respond to all rights requests within 30 days (GDPR), 45 days (CCPA), or sooner.

9. Security measures

We implement technical and organisational measures appropriate to the risk:

  • Encryption in transit: TLS 1.2+ for all admin and storefront endpoints, Vercel-managed certificates with auto-renewal
  • Encryption at rest: Neon Postgres encrypts data at rest using AES-256 (provider-managed keys). Vercel Blob storage uses S3-compatible AES-256
  • Access controls: Engineering access to production data is limited to authorised personnel via multi-factor authentication. CivSec S.M.A.R.T employees with production access are documented in our internal access register
  • OWASP Top 10 mitigation: Standard practice review of injection, broken auth, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialization, vulnerable components, insufficient logging
  • Webhook HMAC verification: All Shopify webhooks verified via HMAC-SHA256 before processing. Replay-attacks mitigated via SHA-256 payload-hash idempotency in WebhookLog
  • Custom CSS sandbox: Pro-tier custom CSS validated server-side AND client-side, scoped via shadow-DOM, no @import / url(http) / expression() / javascript: permitted
  • Subscription scope-approval: Recurring donations gated behind Shopify's separate Subscription APIs scope-approval process before activation
  • Vulnerability disclosure: Responsible-disclosure contact at security@civsecsmart.com, per /.well-known/security.txt (RFC 9116)

We comply with the Shopify Built for Shopify security standards where relevant to the badge program.

10. Children's data

GivePro is intended for use by Shopify merchants and adult donors. We do not knowingly collect personal data from individuals under the age of 16 (EU/EEA), 13 (US), or the equivalent local age of digital consent. If we become aware that a child has submitted personal data, we will delete it without undue delay. Parents or guardians who believe their child has interacted with GivePro may contact dpo@civsecsmart.com.

11. Data breach notification

In the event of a personal data breach likely to result in a risk to donors' or merchants' rights and freedoms, we will notify the relevant Supervisory Authority (the Dutch Autoriteit Persoonsgegevens for our establishment) within 72 hours of becoming aware of the breach (GDPR Art 33), and notify affected merchants and donors without undue delay where the breach is likely to result in a high risk (Art 34).

12. Changes to this policy

We may update this policy to reflect changes in law, our practices, or the GivePro feature set. Material changes will be notified via:

  • Email to merchants (developer-account email on file)
  • Banner notification in GivePro admin (/app)
  • Updated "Last updated" date at the top of this page

A revision history is maintained:

VersionDateChanges
1.02026-05-11Initial publication
1.12026-05-14Added Google LLC (Analytics) subprocessor row in section 6 plus App Store listing analytics paragraph covering GA4 tracking activated 2026-05-14. Donor flow unchanged.

13. Contact

TopicContact
Privacy questions / DPOdpo@civsecsmart.com
Data subject access requestsdpo@civsecsmart.com
Security disclosuresecurity@civsecsmart.com
Legal / contractuallegal@civsecsmart.com
Support / billinggivepro-support@civsecsmart.com
Postal addressCivSec Protection B.V. (trading as CivSec S.M.A.R.T), available on request via dpo@civsecsmart.com, Netherlands
EU Representativen/a (we are EU-established)
KVK98045768

Document version: 1.1 · Last updated: May 14, 2026 · Subject to NL legal-counsel revision before any material claim change.