Privacy Policy

How We Handle Your Data

The Second Order — Retention Diagnostic Application
Operated by Meduit Labs (Proprietorship of Ankit Dikshit)

Effective Date: 30 March 2026  •  Last Updated: 30 March 2026

Section 01

Introduction and Scope

This Privacy Policy describes how Meduit Labs, operating under the brand name “The Second Order” (hereinafter referred to as “we,” “us,” or “our”), collects, processes, stores, and protects information when you install and use The Second Order Shopify application (hereinafter referred to as the “App”).

This Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025 notified by the Ministry of Electronics and Information Technology (MeitY), Government of India. It is also designed to satisfy the privacy policy requirements set forth by Shopify Inc. for applications distributed through the Shopify App Store, and to align with the General Data Protection Regulation (GDPR) of the European Union and the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) to the extent that merchants or their customers may be located in those jurisdictions.

By installing the App on your Shopify store, you (“Merchant” or “Data Principal”) consent to the practices described in this Policy. If you do not agree with any part of this Policy, please do not install or use the App.

Section 02

Definitions

Section 03

Information We Collect

3.1 Data Collected Through Shopify APIs

Upon installation and with your explicit consent (granted through the Shopify OAuth authorisation flow), the App accesses the following data from your Shopify store using read-only API scopes:

3.2 Data We Do NOT Collect

The App does NOT access, collect, or store:

  • Customer names, email addresses, phone numbers, or physical addresses
  • Payment information, credit card details, or billing addresses
  • Customer browsing behaviour, cookies, or session data
  • Customer IP addresses or geolocation data
  • Passwords or authentication credentials of the Merchant or their customers
  • Any data from Shopify scopes not explicitly listed above

3.3 Data Collected Directly from the Merchant

During the installation process and while using the App, we may collect:

Section 04

Purpose of Data Processing

We process the data described in Section 3 strictly for the following purposes:

We do NOT use your data for:

  • Advertising, targeted marketing, or behavioural profiling
  • Sale, rental, or transfer to any third party for their independent use
  • Building customer profiles for use outside the App
  • Training machine learning models on your identifiable store data
  • Any purpose unrelated to the retention diagnostic service
Section 05

Legal Basis for Processing

5.1 Under the DPDPA, 2023

The legal basis for processing your data is explicit consent, obtained through the Shopify OAuth authorisation flow at the time of App installation, as required under Section 6 of the DPDPA. When you install the App and approve the requested API scopes, you provide free, specific, informed, and unambiguous consent to the processing described in this Policy.

You may withdraw your consent at any time by uninstalling the App from your Shopify admin, as described in Section 9 below.

5.2 Under the GDPR (for EU/EEA Merchants)

For Merchants located in the European Economic Area or whose customers are located in the EEA, the legal basis for processing is: (a) consent under Article 6(1)(a) GDPR, obtained through the Shopify installation flow; and (b) performance of a contract under Article 6(1)(b) GDPR, as the processing is necessary to deliver the retention diagnostic service you have engaged.

5.3 Under the CCPA/CPRA (for California-based Merchants)

We do not “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act and the California Privacy Rights Act. The data we process is used solely for the business purposes described in Section 4.

Section 06

Data Storage, Retention, and Security

6.1 Storage Infrastructure

The App is deployed on Railway (railway.app) with a PostgreSQL database hosted on Neon.tech. Both infrastructure providers are subject to their own privacy policies and maintain industry-standard security certifications.

6.2 Data Retention Policy

6.3 Security Measures

We implement the following security measures to protect your data, in accordance with Section 8 of the DPDPA which requires reasonable security safeguards:

Section 07

Data Sharing and Disclosure

7.1 We Do Not Sell Your Data

We do not sell, rent, lease, trade, or otherwise transfer your personal data or store data to any third party for monetary or other valuable consideration. This is an absolute commitment.

7.2 Service Providers (Data Processors)

We use the following categories of service providers who may process data on our behalf, strictly for the purposes of operating the App:

We do not share your data with any analytics providers, advertising networks, marketing platforms, or data brokers.

7.3 Legal and Regulatory Disclosure

We may disclose your data if required to do so by law, regulation, legal process, or enforceable governmental request, including compliance with orders from the Data Protection Board of India established under Section 18 of the DPDPA, or any court of competent jurisdiction.

Section 08

Cross-Border Data Transfers

Our infrastructure providers may store or process data on servers located outside India, including in the United States. Under Section 16 of the DPDPA, transfer of personal data outside India is permitted except to countries specifically restricted by the Central Government through notification. As of the date of this Policy, no such restricted list has been notified.

For Merchants in the EEA, any transfer of data outside the EEA is protected by Standard Contractual Clauses or adequacy decisions, as maintained by our infrastructure providers.

We will update this Policy if the Central Government of India notifies any restrictions on cross-border data transfers that affect the operation of this App.

Section 09

Your Rights

9.1 Under the DPDPA, 2023

As a Data Principal under the DPDPA, you have the following rights under Chapter III of the Act:

9.2 Under the GDPR (for EU/EEA Merchants)

If you are located in the EEA, you additionally have the right to: access your personal data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing; and the right to lodge a complaint with a supervisory authority.

9.3 Under the CCPA/CPRA (for California-based Merchants)

If you are a California resident, you have the right to: know what personal information is collected; request deletion; opt out of the sale of personal information (which we do not engage in); and non-discrimination for exercising your rights.

9.4 How to Exercise Your Rights

You may exercise any of the above rights by contacting us at the details provided in Section 14 of this Policy. We will respond to verifiable requests within the timeframes prescribed by applicable law (7 days under the DPDP Rules, 30 days under the GDPR).

9.5 Uninstallation and Data Deletion

The simplest way to cease all data processing and trigger deletion of your data is to uninstall the App from your Shopify admin (Settings → Apps and sales channels → The Second Order → Uninstall). Upon uninstallation, we will delete your store session, access token, and diagnostic data within 48 hours. You may also request data deletion without uninstallation by contacting us directly.

Section 10

Shopify Mandatory Compliance Webhooks

In compliance with Shopify’s requirements for all App Store applications, we subscribe to and respond to the following mandatory compliance webhooks:

Section 11

Children’s Data

The App is a business-to-business service designed for Shopify Merchants. It is not directed at individuals under the age of 18 years. We do not knowingly collect personal data from children as defined under Section 9 of the DPDPA. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete such data.

Section 12

Data Breach Notification

In the event of a personal data breach that affects the personal data processed through this App, we will:

Section 13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the functionality of the App. When we make material changes:

We encourage you to review this Policy periodically.

Section 14

Contact Information and Grievance Officer

For any questions, concerns, or requests related to this Privacy Policy or the processing of your data, please contact:

Data Fiduciary Meduit Labs

Proprietor Ankit Dikshit

Address Meerut, Uttar Pradesh, India

Email ankit@meduit.in

Website thesecondorder.meduit.in

Grievance Officer (as required under Section 8(10) of the DPDPA and Rule 6 of the DPDP Rules):

Name Ankit Dikshit

Email grievance@meduit.in

Response Time We will acknowledge your grievance within 24 hours and resolve it within 7 days, or within such extended period as may be communicated to you with reasons.

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India established under the DPDPA.

Section 15

Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and any rules, regulations, or notifications issued thereunder. Any disputes arising from or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Meerut, Uttar Pradesh, India.

For Merchants located in the European Economic Area, this Policy is additionally governed by the General Data Protection Regulation (EU) 2016/679 to the extent applicable.