Skip to content
Valido

Privacy Policy

Last updated:

This policy explains what personal data Valido collects, why, who we share it with and how long we keep it. It applies to the Valido Shopify app, the Cash on Delivery form it adds to merchant stores, and this website. If anything is unclear, write to [email protected].

1. Who we are

Valido ("Valido", "we", "us") is a Shopify app that lets Shopify merchants verify Cash on Delivery (COD) orders and share fraud signals about buyers with other merchants who use Valido.

We play two different roles, and the difference matters for your rights:

  • For order data collected in a merchant's store, the merchant is the controller and Valido is a processor acting on the merchant's instructions.
  • For the shared buyer reputation network, Valido is the controller, because we decide how reputation signals are combined and shared across stores.

2. What data we collect

From merchants, through Shopify

When a merchant installs Valido, Shopify gives us access to the data needed to run the app:

  • Store details: store name, domain, contact email, country, currency and plan status.
  • Products and variants needed to show the COD button and create orders.
  • Orders created through Valido, and their fulfillment status.
  • Settings you configure in the app, such as delivery zones and fees.
  • Reports you submit to the reputation network. Each report is stored with your store's identity as an audit record, which only Valido can see.
  • Staff account details Shopify shares when you log in, such as name and email, used only to authenticate you.

From buyers, through the COD form

When a buyer places a Cash on Delivery order on a store that uses Valido, the form collects:

  • Full name.
  • Phone number, which is also used for WhatsApp verification.
  • Email address, if the buyer chooses email verification or provides one.
  • Delivery address, delivery zone and a landmark to help the courier find the place.
  • GPS location, only if the buyer taps the location button and allows it in their browser. It is optional.
  • The products, quantities and price of the order.

Standard server logs may record technical data such as IP addresses and browser type.

One time code verification

To confirm an order, we send a one time code to the buyer's WhatsApp number, or to their email address as an automatic backup if WhatsApp cannot deliver. We store the code in hashed form, with a limit on the number of attempts, only long enough to check it. Codes expire after 5 minutes and are then deleted. We record whether verification succeeded, the channel used and the time.

From visitors to this website

This website does not use advertising or analytics cookies. Our hosting provider may keep standard server logs, such as IP address and pages requested, for security and reliability.

3. How we use data

  • To show the COD form, verify the buyer's contact details and create the order in the merchant's Shopify store.
  • To calculate delivery fees and produce delivery sheets the merchant can share with couriers.
  • To show merchants a buyer's reputation status before they ship.
  • To operate the shared reputation network described in section 4.
  • To prevent abuse of the service, such as code flooding or automated fake orders, through rate limiting.
  • To provide support, bill merchants through Shopify and meet our legal obligations.

We do not sell personal data. We do not use buyer data for advertising, and we do not contact buyers for any purpose other than verifying their order.

4. The shared buyer reputation network

Valido helps merchants avoid repeat fake orders by sharing limited fraud signals across all stores that use the app. This is the part of Valido that affects buyers most, so we explain it in full.

What is shared

  • The buyer's phone number, which identifies them on the network.
  • Incident reports made by merchants, with the type of incident and the date. There are four incident types: refused parcel, invalid number, unreachable and fake order.
  • The number of different stores that have reported the buyer, and the number of confirmed deliveries.
  • The resulting status: trusted, new, flagged or blocked.

Other merchants see the buyer's status, the number of incidents, how many different stores reported them, their confirmed deliveries and the dates. They never see which store made a report, and they do not see the buyer's name, address or order history from other stores. Reports are not anonymous to Valido: we keep the identity of the reporting store with each report as an audit record, and only Valido can see it.

How statuses are decided

  • A buyer reported by 2 different stores is flagged.
  • A buyer reported by 3 different stores is blocked, which means they are refused Cash on Delivery on Valido stores.
  • Several reports from the same store count as one. A single store can never flag or block a buyer on its own.

Merchants must only report real incidents. We reserve the right to restrict or end access for merchants who misuse the network.

Legal basis

We process reputation signals on the basis of legitimate interests: preventing fraud and protecting merchants from the cost of fake Cash on Delivery orders. We have weighed this against buyers' interests and limit the data to what is needed. A blocked buyer is refused Cash on Delivery only. Valido never changes a store's normal online checkout, which stays available to them.

6. Who we share data with

We use the following service providers (sub processors) to run Valido. Each one only receives the data it needs for its task and is bound by a data processing agreement.

  • Shopify: app platform, merchant authentication, order creation and subscription billing.
  • Meta Platforms (WhatsApp Business Platform): delivery of one time codes by WhatsApp. Receives the buyer's phone number and the message content.
  • Resend: delivery of one time codes and service emails. Receives the recipient's email address and the message content.
  • DigitalOcean: hosting of the application, database and this website.
  • Upstash: temporary storage used for one time codes, sessions and rate limiting.

Buyer order data is shared with the merchant whose store the order was placed in. Reputation signals are shared with other Valido merchants as described in section 4.

We may also disclose data if required by law, or to protect the rights and safety of Valido, merchants or buyers.

7. Where data is stored

Our application and database are hosted on DigitalOcean's infrastructure. Some sub processors, including Shopify, Meta and Resend, may process data in other countries, including the United States.

When data leaves the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.

8. How long we keep data

  • One time codes: deleted when they expire, 5 minutes after they are sent.
  • Buyer order details (name, email, address, landmark, GPS): kept while the merchant uses Valido so they can manage and deliver orders, then deleted as described below.
  • Merchant store data: deleted within 48 hours of Shopify's shop deletion request, which Shopify sends after a merchant uninstalls the app.
  • Billing records: kept as long as the law requires.
  • Reputation signals: kept for up to 24 months after the most recent incident, then deleted.

Deletion requests and reputation signals

When a buyer asks a merchant to delete their data, Shopify sends us a customer deletion request. We then erase the buyer's identifying details held for that store: name, email, address, landmark, GPS location and order details.

We keep the buyer's reputation signals, meaning their phone number, incident counts, the dates of incidents and their resulting status. We keep these on the basis of our legitimate interest in preventing fraud. Erasing them on request would let anyone reset their record after a fake order, which would defeat the purpose of the network and harm the merchants who rely on it.

These signals are kept only for the retention period above and are never used for any other purpose.

9. Your rights

Depending on where you live, including under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate.
  • Ask us to delete your data, subject to the fraud prevention exception in section 8.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive your data in a portable format.
  • Withdraw consent where processing is based on consent.
  • Complain to your local data protection authority.

How buyers make a request

Because buyers place orders with a merchant, the simplest route is to contact the store where you placed your order. The merchant can submit your request through Shopify, which forwards it to us automatically as a data request or a deletion request. We respond within the time Shopify and the law require, and within 30 days at the latest.

If you believe you were flagged in error

A buyer who believes they were flagged in error can contact [email protected]. Their case is reviewed manually against the incident history.

You can also write to us directly at [email protected]. For requests about the reputation network, include your phone number so we can find your record. We may ask you to confirm you own that number before we act.

How merchants make a request

Merchants can manage most data in the app. For anything else, or to request deletion of your store data before uninstalling, contact [email protected].

10. Security

We use encryption in transit (HTTPS) for all traffic, rely on our hosting provider, DigitalOcean, to encrypt data at rest, and restrict access to people who need it, hash verification codes and rate limit sensitive actions. No system is perfectly secure, but we work to protect your data and will notify affected merchants and authorities of a breach as the law requires.

11. Children

Valido is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided data through a COD form, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the app changes or the law requires. We will change the date at the top of this page and, for significant changes, notify merchants by email or in the app.

13. Contact

Questions, requests or complaints about privacy: [email protected].

Back to top