Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how REQUR ("we", "us") handles information when you install and use the DHL Shipping by REQUR Shopify app (the "App"). The App creates DHL Parcel labels from Shopify orders and synchronizes shipment tracking and fulfillment.
The merchant is the data controller for customer personal data. REQUR acts as a data processor and processes this data only on the merchant's instructions to provide the App.
1. Information we process
| Category | Examples | Purpose |
|---|---|---|
| Store and account | Myshopify domain, Shopify access token, DHL API user ID, API key, account number, sender address, and optional distinct return address | Authenticate the App and create shipments under the merchant's DHL contract |
| Order data | Shopify order ID and number, line items, shipping method, weight, value, currency, and order status | Select shipping settings, prevent duplicate labels, and display shipment status |
| Customer delivery data | Name, company, email, phone number, and delivery address | Create outbound and return labels with DHL |
| Shipment data | DHL shipment and label IDs, tracking number, delivery events, fulfillment ID, and private label PDF | Provide labels, tracking, returns, and Shopify fulfillment synchronization |
2. How data is used
We process data only to provide label creation, returns, tracking, Shopify fulfillment synchronization, security, and support. We do not sell merchant or customer data and do not use it for advertising.
3. Sub-processors
- Shopify - source of store and order data and destination for fulfillment updates.
- DHL Parcel Benelux - receives shipment and recipient data to create labels and deliver parcels under the merchant's DHL contract.
- Hosting infrastructure - secure application, database, queue, email, and private file storage.
4. Retention and deletion
We retain data only while needed to operate the installed App and comply with applicable obligations. Shopify customer redaction requests remove matching contact, address, purchase, tracking, label, and fulfillment details and delete related label files. Keyed, non-reversible identifier hashes may be retained only to prevent delayed webhooks from restoring deleted data. Shop redaction deletes all private label files and removes the shop and related DHL account, return setting, shipping profile, Shopify import, order, shipment, rule, and webhook records.
5. Customer data requests
When Shopify sends a customers/data_request webhook, the App compiles the matching application data into a JSON export for REQUR privacy operations so the merchant can receive the requested information.
6. Security
Data is transmitted over encrypted connections. Shopify tokens and DHL API keys are encrypted at rest. Label PDFs are stored on a private filesystem and are available only through an authenticated, shop-authorized download route. Shopify notifications are checked for authenticity, duplicate deliveries are ignored, and processing is handled securely in the background.
7. Your rights
Depending on your location, merchants and customers may have rights to access, correct, delete, restrict, or port personal data and to object to processing. Customer requests are normally submitted to the merchant through Shopify. You can also contact us at info@requr.nl.
8. Changes and contact
We may update this policy from time to time. The date above identifies the current version.
REQUR - based in the Netherlands.
Email: info@requr.nl