PackFlow - Returns
Last updated: 24 April 2026
Timmgard GmbH (“we”, “us”, “our”) operates the PackFlow - Returns Shopify application (“the App”), which provides merchants with a customer-facing returns portal and DHL return label generation. This Privacy Policy describes how we collect, use, store, and protect personal data when merchants and their customers use the App.
We process personal data in three categories: merchant data, customer data (accessed on behalf of the merchant via the Shopify Admin API), and technical analytics data.
We use the collected data exclusively to provide the App's functionality:
We share personal data only with the sub-processors listed below. Each is engaged under a data processing agreement per Art. 28 GDPR; the full DPA is available at https://tg-ai.de/en/dpa. We do not sell, rent, or share personal data with any other third parties for marketing, advertising, or profiling purposes.
Shopify is our primary sub-processor. All order, customer, product, fulfillment, returns, and draft order data originates from and resides at Shopify; PackFlow accesses it via the Shopify Admin API. As Merchant of Record, Shopify also handles merchant billing. Transfers outside the EEA are safeguarded under EU Standard Contractual Clauses per Implementing Decision (EU) 2021/914 within the Shopify DPA.
DHL processes data via three distinct APIs, each limited to the minimum fields required:
DHL processes this data on EU infrastructure according to its own privacy policy.
Hosting provider for the application and the PostgreSQL database. Render operates the infrastructure but does not actively process personal data on our behalf beyond storage. Database backups are encrypted.
PackFlow implements appropriate technical and organisational measures under Art. 32 GDPR:
The following retention periods apply:
If you are a customer of a merchant using the App, you have the following rights regarding your personal data:
To exercise these rights, please contact the merchant (shop owner) directly as they are the controller. The merchant can forward data subject requests to us, which we handle via Shopify's mandatory compliance webhooks.
The App implements all Shopify-required GDPR compliance webhooks:
The App does not set cookies or use browser local storage for identification. Authentication within the embedded admin is handled via Shopify session tokens.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the App after changes constitutes acceptance of the updated policy.
For questions about this Privacy Policy or data processing:
For data subject requests, please contact the merchant (shop owner) who installed the App on their Shopify store.