Privacy Policy
PayVeto Blacklist COD — a Shopify embedded app by AdFeed Studio · Effective date: August 23, 2026
This Privacy Policy describes how PayVeto Blacklist COD (“we”, “us”, “our”) collects, uses, stores, and deletes information when merchants install and use our Shopify embedded application (“the App”). It applies to the merchant’s use of the App and to the personal data we process on the merchant’s behalf.
Summary. PayVeto Blacklist COD helps merchants control who is offered Cash on Delivery (COD) at checkout. Merchants keep a list of customers who should not see COD, and the App hides the COD payment method for those shoppers (and, optionally, for guests or for customers carrying chosen tags). To do this we process shop account data, the merchant’s block list, and order data received from Shopify. At checkout, shoppers are matched against a hashed representation of the list. We do not sell personal data, and we do not use it for advertising.
1. Who we are
PayVeto Blacklist COD is a Shopify app that lets merchants hide the Cash on Delivery payment method at checkout for selected customers, guests, or tagged customers, and track repeat COD offenders. The App is developed and operated by AdFeed Studio.
Questions about this policy: support@adfeedstudio.com
2. Information we collect
When you install or use the App, we may process:
- Shop and account identifiers — your
*.myshopify.comdomain, Shopify shop ID, and the OAuth access tokens required to call the Shopify Admin API on your behalf. - Your block list — the customer identifiers you add to the App to control COD: email addresses, phone numbers, an optional note you write, the rule assigned to each entry (for example “hide COD” and/or “tag the customer”), and whether the entry is enabled.
- App configuration — payment rules, the tags that trigger a rule, the “hide COD for guests” setting, COD payment-method names, billing/plan state, language, and other options you save in the admin.
- Order data — Shopify order IDs, order numbers, order contact details (email/phone), and related fields received via Shopify APIs and the
orders/createwebhook. We use these to match orders against your block list and to count distinct orders placed by a blocked customer (repeat-offender tracking). - Customer data (Admin) — where you tag customers or match them against your list, we read and write customer records (name, email, phone, tags) through the Shopify Admin API using the
read_customersandwrite_customersscopes. - Checkout evaluation data — at checkout, a Shopify payment-customization function evaluates the buyer against your list to decide whether to hide COD. The list is delivered to the function as a hashed (one-way) filter of contacts, not as plain emails or phone numbers, and the function’s per-checkout evaluation is not stored by us as a separate record.
- Operational logs — request, webhook, job, and error logs (shop domain, order IDs, timestamps) kept for reliability, security, and support. Logs are not used for advertising.
3. Information we do not collect
- Payment card numbers — subscription billing and checkout payments are handled entirely by Shopify; we never receive or store card data.
- Passwords or account credentials for your staff or your customers.
- Buyer data for advertising, profiling, or resale of any kind.
4. How we use information
We use the information above solely to:
- Provide and operate the App’s COD-blocking and tagging features;
- Hide the COD payment method at checkout for the shoppers you specify;
- Match orders against your list and report repeat COD offenders;
- Enforce plan limits and billing through Shopify;
- Respond to support requests and diagnose errors;
- Comply with legal obligations and Shopify platform requirements.
We do not sell merchant or buyer personal data, and we do not use it for advertising.
5. Legal bases (EEA/UK merchants)
Where applicable, we process data to perform our contract with you (providing the App), on your instructions as the data controller for the block-list and order data you provide, and where necessary for our legitimate interests in securing and improving the service. You are responsible for having a lawful basis to add a given customer to your block list and to tag customers under applicable law.
6. Sharing and subprocessors
We share data only as needed to run the App:
- Shopify — platform APIs, authentication, billing, checkout, payment customizations, and webhooks.
- Infrastructure providers — hosting, database, and backup services that store data at rest on servers we operate or contract, secured in transit and at rest.
We do not share your data with advertisers or data brokers. We require subprocessors to protect data consistent with this policy and applicable law.
7. Retention and deletion
- Data is retained while the App is installed and as needed to provide the service.
- When you uninstall the App, we mark your shop as uninstalled and stop routine processing.
- Shopify sends mandatory compliance webhooks (
customers/data_request,customers/redact,shop/redact). We honor each: we export or delete the buyer personal data we hold when required, and onshop/redactwe delete every tenant-scoped record for your shop — block-list entries, rules, configuration, and stored order references — within the timeframe required by Shopify’s partner policies. - Backups may persist for a limited period before automatic purge.
8. Security
We use HTTPS/TLS for data in transit, access controls on production systems, and Shopify’s required webhook HMAC verification. Contacts used for checkout matching are delivered to the payment function in a hashed form. No method of transmission or storage is 100% secure; contact us if you suspect unauthorized access.
9. Your rights and Shopify compliance webhooks
Merchants may request access, correction, or deletion of shop-level data by contacting support@adfeedstudio.com or by uninstalling the App, which triggers Shopify’s redaction flow.
Where we hold buyer personal data tied to your orders, we respond to the Shopify customers/data_request and customers/redact webhooks as required. You remain the controller of your customers’ data and are responsible for your own privacy obligations to them under applicable law.
10. International transfers
If you access the App from outside the country where our servers are located, your information may be transferred internationally. We take steps to ensure appropriate safeguards where required by law.
11. Changes to this policy
We may update this page from time to time. The “Effective date” above will change when we do. Continued use of the App after an update means you accept the revised policy.
12. Contact
Email: support@adfeedstudio.com
Policy: https://adfeedstudio.com/apps/pay-veto-blacklist-cod/privacy
App: https://blacklist-cod.adfeedstudio.com
This document is provided for transparency about PayVeto Blacklist COD’s data practices. It is not legal advice. Merchants remain responsible for their own privacy obligations to their customers under applicable law and Shopify’s terms.