This policy explains what personal data the RentalOps app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.
RentalOps is operated by DiLight Entertainment UG (haftungsbeschränkt) ("RentalOps", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.
When RentalOps is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and RentalOps acts as a data processor on the merchant's behalf, processing store data only to provide the app's rental-operations features. For our own account and billing records, we act as the controller.
RentalOps turns paid Shopify orders into rental bookings and keeps a live availability calendar. To do that it reads and stores the minimum data needed:
.myshopify.com domain, the OAuth access token
issued at install (stored encrypted and never shown to us in plain text in the UI), your plan and billing
status, and app settings (which products are rentable, pool sizes, buffer times, deposit and reminder
configuration).The QR / customer status page shows a single booking (dates, deposit and pickup information) to whoever holds
its unguessable link; it never enumerates other bookings. Access to store data is limited to the Shopify scopes
granted at install (read_customers, read_inventory, read_locations,
read_orders, read_products, write_products).
write_products).Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing and securing the service. For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.
We do not sell personal data. We share data only with the providers needed to run the service:
Terminal bookings (returned or cancelled) are automatically deleted by a retention sweep after
365 days by default (configurable by the merchant); active and overdue bookings are never
auto-deleted. Aggregated, non-identifying statistics may be kept longer. In general we keep data only as long as
needed to provide the service, and we purge a store's data when the app is uninstalled or on a Shopify
shop/redact request, as described below.
RentalOps implements Shopify's mandatory compliance webhooks (verified by HMAC over the raw request body):
customers/data_request — we report the bookings matching the requested order ids so the
merchant can fulfil the data-subject access request. RentalOps does not keep a customer profile beyond the
booking data described above.customers/redact — we anonymize the stored customer name on matching bookings (cleared and
flagged as redacted); the operational booking record survives without the personal data.shop/redact — we purge all of the store's data: bookings, rental items, and its billing record,
notification outbox and back-write records. This runs after the store uninstalls the app.Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.
The app uses Shopify's OAuth for install, verifies inbound webhooks with HMAC signatures over the raw body, stores access tokens encrypted, signs outbound reminder payloads, and serves all traffic over TLS. The customer status page is protected by an App Proxy signature (with an unguessable, rate-limited token fallback). Access to store data is scoped to the permissions granted at install.
The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.
We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.
DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website