Section 01
Introduction and Scope
This Privacy Policy describes how Meduit Labs, operating under the brand name “The Second Order” (hereinafter referred to as “we,” “us,” or “our”), collects, processes, stores, and protects information when you install and use The Second Order Shopify application (hereinafter referred to as the “App”).
This Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025 notified by the Ministry of Electronics and Information Technology (MeitY), Government of India. It is also designed to satisfy the privacy policy requirements set forth by Shopify Inc. for applications distributed through the Shopify App Store, and to align with the General Data Protection Regulation (GDPR) of the European Union and the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) to the extent that merchants or their customers may be located in those jurisdictions.
By installing the App on your Shopify store, you (“Merchant” or “Data Principal”) consent to the practices described in this Policy. If you do not agree with any part of this Policy, please do not install or use the App.
Section 02
Definitions
- Data Principal: The individual to whom the personal data relates, as defined under Section 2(j) of the DPDPA. In the context of this App, this includes Merchants who install the App and end-customers whose order data may be processed.
- Data Fiduciary: Meduit Labs, which determines the purpose and means of processing personal data through the App, as defined under Section 2(i) of the DPDPA.
- Data Processor: Any entity that processes personal data on behalf of Meduit Labs, including cloud infrastructure providers.
- Personal Data: Any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDPA.
- Processing: Any operation performed on digital personal data, including collection, storage, use, analysis, retrieval, or erasure, as defined under Section 2(x) of the DPDPA.
- Store Data: Aggregate and transactional data retrieved from your Shopify store through the Shopify Admin API, including order records, product catalogues, and customer purchase histories.
Section 03
Information We Collect
3.1 Data Collected Through Shopify APIs
Upon installation and with your explicit consent (granted through the Shopify OAuth authorisation flow), the App accesses the following data from your Shopify store using read-only API scopes:
- Order Data (read_orders): Order identifiers, order dates, order values, line items, product references, fulfilment status, discount codes applied, and refund records. This data is used to compute repeat purchase rates, reorder timing, cohort behaviour, and revenue attribution for the retention diagnostic.
- Product Data (read_products): Product identifiers, titles, types, collections, variant information, and pricing. This data is used to classify products into consumption categories, identify replenishable versus one-time products, and map category physics for the diagnostic.
- Customer Data (read_customers): Customer identifiers (Shopify internal IDs), order counts, total spend, and date of first and last order. This data is used to segment customers by purchase frequency and identify second-purchase drop-off patterns.
3.2 Data We Do NOT Collect
The App does NOT access, collect, or store:
- Customer names, email addresses, phone numbers, or physical addresses
- Payment information, credit card details, or billing addresses
- Customer browsing behaviour, cookies, or session data
- Customer IP addresses or geolocation data
- Passwords or authentication credentials of the Merchant or their customers
- Any data from Shopify scopes not explicitly listed above
3.3 Data Collected Directly from the Merchant
During the installation process and while using the App, we may collect:
- Your Shopify store domain (myshopify.com URL)
- Your Shopify access token (issued by Shopify during OAuth, used solely for API access)
- Your store name and email address associated with the Shopify account
Section 04
Purpose of Data Processing
We process the data described in Section 3 strictly for the following purposes:
- Retention Diagnostic Generation: To analyse your store’s order data and produce a structured retention health diagnostic, including a second-purchase constraint map, retention health score, and prioritised recommendations. This is the primary and sole purpose of the App.
- Diagnostic Report Delivery: To present the results of the analysis within the App interface, accessible only to authorised users of your Shopify admin.
- App Functionality and Maintenance: To authenticate your store, maintain session state, handle API requests, and ensure the technical functioning of the App.
- Product Improvement: To understand usage patterns in aggregate (not individual store data) for the purpose of improving diagnostic accuracy and the App experience.
We do NOT use your data for:
- Advertising, targeted marketing, or behavioural profiling
- Sale, rental, or transfer to any third party for their independent use
- Building customer profiles for use outside the App
- Training machine learning models on your identifiable store data
- Any purpose unrelated to the retention diagnostic service
Section 05
Legal Basis for Processing
5.1 Under the DPDPA, 2023
The legal basis for processing your data is explicit consent, obtained through the Shopify OAuth authorisation flow at the time of App installation, as required under Section 6 of the DPDPA. When you install the App and approve the requested API scopes, you provide free, specific, informed, and unambiguous consent to the processing described in this Policy.
You may withdraw your consent at any time by uninstalling the App from your Shopify admin, as described in Section 9 below.
5.2 Under the GDPR (for EU/EEA Merchants)
For Merchants located in the European Economic Area or whose customers are located in the EEA, the legal basis for processing is: (a) consent under Article 6(1)(a) GDPR, obtained through the Shopify installation flow; and (b) performance of a contract under Article 6(1)(b) GDPR, as the processing is necessary to deliver the retention diagnostic service you have engaged.
5.3 Under the CCPA/CPRA (for California-based Merchants)
We do not “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act and the California Privacy Rights Act. The data we process is used solely for the business purposes described in Section 4.
Section 06
Data Storage, Retention, and Security
6.1 Storage Infrastructure
The App is deployed on Railway (railway.app) with a PostgreSQL database hosted on Neon.tech. Both infrastructure providers are subject to their own privacy policies and maintain industry-standard security certifications.
6.2 Data Retention Policy
- Session and Authentication Data: Your Shopify access token and store session data are stored for as long as the App remains installed on your store. Upon uninstallation, this data is deleted within 48 hours.
- Diagnostic Results: The computed retention diagnostic report is stored for as long as the App is installed, to allow you to access your results without re-running the analysis. This data is deleted within 48 hours of uninstallation.
- Raw Order and Customer Data: Raw transactional data retrieved from Shopify APIs is processed in memory during the diagnostic computation. We do not permanently store raw order-level or customer-level data from your store beyond what is necessary for the diagnostic computation. Once the diagnostic is generated, raw data is not retained in its original form.
- Aggregate Statistical Data: We may retain anonymised, aggregate statistical data (such as average repeat rates across categories, without any store or customer identifiers) for the purpose of improving diagnostic benchmarks. This data cannot be traced back to any individual store or customer.
6.3 Security Measures
We implement the following security measures to protect your data, in accordance with Section 8 of the DPDPA which requires reasonable security safeguards:
- All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
- Database access is restricted by IP whitelisting and credential-based authentication
- Shopify access tokens are stored encrypted and are never exposed in logs, URLs, or client-side code
- The App uses Shopify’s session token authentication mechanism, which does not rely on third-party cookies
- Administrative access to infrastructure is limited to authorised personnel at Meduit Labs
- We conduct periodic reviews of our access controls and data handling practices
Section 07
Data Sharing and Disclosure
7.1 We Do Not Sell Your Data
We do not sell, rent, lease, trade, or otherwise transfer your personal data or store data to any third party for monetary or other valuable consideration. This is an absolute commitment.
7.2 Service Providers (Data Processors)
We use the following categories of service providers who may process data on our behalf, strictly for the purposes of operating the App:
- Cloud Infrastructure: Railway (deployment hosting) and Neon.tech (database hosting) process data as part of providing the computing and storage infrastructure on which the App operates.
- Shopify Inc.: As the platform provider, Shopify facilitates the OAuth authorisation and API data access. Shopify’s own handling of data is governed by the Shopify Privacy Policy and the Shopify Data Processing Addendum.
We do not share your data with any analytics providers, advertising networks, marketing platforms, or data brokers.
7.3 Legal and Regulatory Disclosure
We may disclose your data if required to do so by law, regulation, legal process, or enforceable governmental request, including compliance with orders from the Data Protection Board of India established under Section 18 of the DPDPA, or any court of competent jurisdiction.
Section 08
Cross-Border Data Transfers
Our infrastructure providers may store or process data on servers located outside India, including in the United States. Under Section 16 of the DPDPA, transfer of personal data outside India is permitted except to countries specifically restricted by the Central Government through notification. As of the date of this Policy, no such restricted list has been notified.
For Merchants in the EEA, any transfer of data outside the EEA is protected by Standard Contractual Clauses or adequacy decisions, as maintained by our infrastructure providers.
We will update this Policy if the Central Government of India notifies any restrictions on cross-border data transfers that affect the operation of this App.
Section 09
Your Rights
9.1 Under the DPDPA, 2023
As a Data Principal under the DPDPA, you have the following rights under Chapter III of the Act:
- Right to Access (Section 11): You may request a summary of the personal data we process and the processing activities associated with it.
- Right to Correction and Erasure (Section 12): You may request correction of inaccurate personal data or erasure of personal data that is no longer necessary for the purpose for which it was collected.
- Right to Grievance Redressal (Section 13): You may raise a grievance with our Grievance Officer (details in Section 14 below) regarding any issue related to the processing of your personal data.
- Right to Nominate (Section 14): You may nominate any individual to exercise your data rights on your behalf in the event of your death or incapacity.
9.2 Under the GDPR (for EU/EEA Merchants)
If you are located in the EEA, you additionally have the right to: access your personal data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing; and the right to lodge a complaint with a supervisory authority.
9.3 Under the CCPA/CPRA (for California-based Merchants)
If you are a California resident, you have the right to: know what personal information is collected; request deletion; opt out of the sale of personal information (which we do not engage in); and non-discrimination for exercising your rights.
9.4 How to Exercise Your Rights
You may exercise any of the above rights by contacting us at the details provided in Section 14 of this Policy. We will respond to verifiable requests within the timeframes prescribed by applicable law (7 days under the DPDP Rules, 30 days under the GDPR).
9.5 Uninstallation and Data Deletion
The simplest way to cease all data processing and trigger deletion of your data is to uninstall the App from your Shopify admin (Settings → Apps and sales channels → The Second Order → Uninstall). Upon uninstallation, we will delete your store session, access token, and diagnostic data within 48 hours. You may also request data deletion without uninstallation by contacting us directly.
Section 10
Shopify Mandatory Compliance Webhooks
In compliance with Shopify’s requirements for all App Store applications, we subscribe to and respond to the following mandatory compliance webhooks:
- customers/data_request: When Shopify forwards a customer data request to us, we respond with the data we hold about that customer (if any). Given that we do not store personal customer identifiers such as names or email addresses, our response will typically confirm that we do not hold identifiable data for the requested customer.
- customers/redact: When Shopify sends a customer redaction request, we erase any data associated with the specified customer identifier within our systems.
- shop/redact: When Shopify sends a shop redaction request (typically 48 hours after uninstallation), we erase all data associated with the specified store, including sessions, tokens, and diagnostic results.
Section 11
Children’s Data
The App is a business-to-business service designed for Shopify Merchants. It is not directed at individuals under the age of 18 years. We do not knowingly collect personal data from children as defined under Section 9 of the DPDPA. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete such data.
Section 12
Data Breach Notification
In the event of a personal data breach that affects the personal data processed through this App, we will:
- Notify the Data Protection Board of India as required under Section 8(6) of the DPDPA, within the timeframe prescribed by the DPDP Rules
- Notify affected Merchants (Data Principals) of the breach, the nature of data affected, and the remedial measures taken
- Where applicable, notify the relevant supervisory authority under the GDPR within 72 hours of becoming aware of the breach
- Take immediate technical measures to contain the breach and prevent further unauthorised access
Section 13
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the functionality of the App. When we make material changes:
- We will update the “Last Updated” date at the top of this Policy
- For significant changes that alter the scope of data collection or the purposes of processing, we will notify Merchants through the App interface or via email
- Continued use of the App after the effective date of any changes constitutes your acceptance of the updated Policy
We encourage you to review this Policy periodically.
Section 14
Contact Information and Grievance Officer
For any questions, concerns, or requests related to this Privacy Policy or the processing of your data, please contact:
Grievance Officer (as required under Section 8(10) of the DPDPA and Rule 6 of the DPDP Rules):
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India established under the DPDPA.
Section 15
Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and any rules, regulations, or notifications issued thereunder. Any disputes arising from or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Meerut, Uttar Pradesh, India.
For Merchants located in the European Economic Area, this Policy is additionally governed by the General Data Protection Regulation (EU) 2016/679 to the extent applicable.