Merchant terms and data processing agreement. Authorised merchants can review and accept the identified version in the app’s Settings. Acceptance is recorded separately from installation and billing.
Vanilla Consent is provided by Vanilla Telecoms Ltd, company registration number C34939, with registered office at 162, Cannon Road, Santa Venera, Malta. For privacy requests and security incidents concerning Vanilla Consent, contact our Data Protection Officer at gdpr@vanilla.net.mt.
Vanilla Consent stores merchant settings, consent choices, visitor-generated consent IDs, country and device categories, store scan findings, and privacy requests. We do not sell this data. Store access tokens and requester email addresses are encrypted at rest by the app.
Consent records are kept for the merchant’s selected retention period, up to 365 days. Merchant-imported consent history is stored separately with the original IDs, dates, choices and source labels. Only mapped fields are imported; unmapped IP addresses and other columns are discarded in the browser. Imported records expire using their original consent date and never activate tracking permission or enter current consent reports. App data is removed after uninstall or a Shopify shop erasure request. Merchants handle privacy requests and must verify identity before delivering data or completing deletion.
Merchant-imported privacy-request history is kept in a separate archive. Source IDs, dates, type/status labels and source verification labels are preserved. Emails, order references, request messages and handling notes are encrypted at rest. Importing does not verify identity, send email, run customer actions or add to current request reports. Retention uses the original completion date when provided, otherwise the original request date. Shopify customer erasure notices remove matching archived email records; records without a matching email require merchant review and can be removed in the archive. Merchants can export a summary or explicitly include private details. A separate reviewed transfer can copy unfinished work into the inbox while keeping its original receipt date and reviewed deadline. Source verification is not carried over; a fresh email link is required. The transfer keeps the archive intact and sends no email or customer action. Inbox provenance records link the provider and original request ID. Transferred private details and new storefront messages and order references are encrypted at rest; legacy private fields are upgraded when handling notes are saved. The active copy follows inbox retention and erasure rules independently of archive expiry.
When a merchant requests AI cookie suggestions, we send only scanned cookie names and domains, with temporary reference numbers, to Cloudflare Workers AI. We do not send cookie values or shopper details. Suggestions are stored with the cookie inventory and require merchant review before use. They are removed when the inventory entry or shop data is removed.
For optional image descriptions, the merchant chooses a Shopify image and we send a resized copy to Cloudflare AI. We store its URL, a content fingerprint, the original and suggested description, and the review outcome. Only a merchant-approved description is written to the Shopify file. When a merchant starts a bulk draft batch, selected image files are processed in the background. We store the selected file references, initiating merchant reference, progress and failures for up to 30 days after completion; unfinished batches expire after seven days. Cancelling keeps completed drafts and discards later results. Image reviews and batch records are removed with shop data. This feature requires optional Shopify file access.
When a merchant requests a translation, we send only the selected banner and preference wording, the default cookie-policy text and custom policy sections, the default accessibility-statement wording, reading-control labels, default age-check labels, the default privacy-form, confirmation-page, secure-download page and email-template wording, or an individual cookie’s purpose and duration to Cloudflare AI. Reading-control translations do not include visitor preferences or profile choices. Reading preferences stay in the visitor’s browser. If a merchant enables optional reading-tool reports, visitors who have granted analytics consent can send tool-interaction counts. These records contain only the store, UTC date, a tool name and a random single-action ID used to prevent duplicates. No visitor ID, chosen setting, selected profile name, image description or precise event time is included. Records last for at most 90 days, or the merchant’s shorter retention period. A short-lived keyed hash of the network address is used only for rate limiting, outside the usage records. Age-check translations never include birth dates or visitor receipts. Full cookie inventories, cookie values, shopper records, recipient lists and verification tokens are not included in these translation requests. Drafts require review and a separate save or publish action. Cookie-description translations are saved with their source wording and stop appearing if that source changes; they are removed with the cookie or shop data. Translation requests are recorded by language code without logging their text. New privacy requests retain their chosen language so later messages can use it.
With optional Shopify privacy access, verified requests can be matched by email to customer profiles. The app can prepare an export of profile details, addresses and accessible orders for merchant review. Ordinary merchant downloads are generated on demand without server storage. A merchant can separately prepare a secure delivery copy, encrypted with an expiry of up to 24 hours and limited to 512,000 bytes. After downloading and reviewing that exact copy, the merchant can email its verified requester a private, single-use link lasting up to 30 minutes. The file itself is not attached to email or sent to AI. Opening the link page does not consume it; an explicit download does. Download and revocation clear the file contents. Expiry blocks access immediately and the next hourly cleanup clears the expired file. Request or shop erasure removes the record. Download status records a server response, not proof that the requester saved the file. Copies already downloaded are outside the app’s control. Reviewed corrections, sale opt-outs and erasure submissions are recorded with request and customer references; correction values are encrypted at rest. Action records are removed with the privacy request, including its retention deadline and Shopify erasure events. Shopify controls its own erasure schedule, and submitting a request does not mean the data has already been erased.
When a merchant checks a verified order-withdrawal request, the app matches its order reference and verified email to an accessible Shopify order. It saves an encrypted snapshot of the order reference, item names and quantities, country, order tags, delivery dates and the configured review result. If product exemption tags are configured and optional product access is granted, the snapshot also includes current product identifiers, tags and update dates. Missing product access or unavailable products require merchant review; tags do not automatically reject a request. After email verification, a short-lived secure browser session lets the requester choose matched order items and confirm quantities. The app stores their encrypted confirmation separately from the original request date and can email a receipt through Mailgun. The session expires after 30 minutes; its hashed credential is removed on expiry. A requester can ask for a fresh single-use email link using their original request reference and matching email. Renewal links expire after 30 minutes, are rate limited, and replace the prior session only after fresh email confirmation. They do not change the original receipt date or confirmed items. These snapshots and item confirmations follow the related request’s retention and erasure lifecycle. They are not sent to AI and do not cancel an order, issue a refund or make a legal eligibility decision.
For optional Klaviyo profile deletions, a merchant can save a private API key encrypted at rest. The app sends only the verified requester email to Klaviyo’s Data Privacy API after a reviewed action, or after a fresh email confirmation when the merchant explicitly enables automatic handling. Automatic handling is off by default. We store the connection label, submission attempt, provider status and request reference, without copying requester emails into these action records. A provider acceptance is not proof of completed deletion. Uncertain submissions are not retried automatically. Disconnecting removes the stored key and stops future submissions; it cannot cancel an action already sent. Action records follow the privacy request’s retention and erasure lifecycle, and connection keys are removed with shop data.
An optional Microsoft Clarity integration loads session recording only after an explicit analytics choice confirmed by Shopify. Its public project ID and setup review are stored with merchant settings. Ad storage additionally needs marketing and sale/sharing permission and is denied with Global Privacy Control. The app does not load this integration in previews or on account, checkout, password, challenge or app-page routes. Once loaded, Microsoft processes the website interaction data under the merchant’s Clarity configuration and masking rules; recordings are not stored by Vanilla Consent. Withdrawal sends denied signals and reloads the page, but cannot recall data already sent. This feature is off by default and other Clarity installations remain the merchant’s responsibility.
Optional consent sharing links merchant-reviewed stores under one main domain. Each store must confirm the same privacy purposes and providers. A secure parent-domain cookie holds the consent choices, group and policy references, and expiry dates, without shopper IDs, customer details or fingerprints. Each receiving store checks the signed choice and records it using its own consent ID. Invalid choices fall back to that store’s banner. Sharing is checked on page load; already-open pages and tags outside the app’s control may require a reload. Group membership and domain checks are stored until the group or store is removed, with short-lived invitation hashes. Policy changes, removal, uninstall or failed domain checks pause sharing. Domain checks normally refresh hourly, and an unrefreshed check expires after 24 hours.
Optional Google Drive backups send only merchant-selected consent records and privacy requests to the reviewed Google account. Requester emails, order references, messages and notes are excluded unless separately enabled. Google connection credentials and account details are encrypted at rest. The app requests access to files it creates or the merchant selects. Backup progress and file references remain for 30 days after a run finishes. Merchants can opt into completion or failure notices sent through Mailgun to the connected Google account’s email address. Notices contain the store name and backup outcome, without exported records; uncertain email sends are not repeated automatically. Incomplete runs expire after seven days; unused connection attempts expire within 30 minutes. Disconnecting removes saved credentials and stops future uploads. An upload already in flight may finish. Copies already stored in Google Drive remain under the merchant’s control and are not removed by app retention or erasure. Merchants must manage access and deletion of those copies separately.
Mailgun delivers privacy-request emails and optional merchant scan alerts. Sender and recipient addresses, message content and delivery status are processed for delivery. Message payloads are encrypted in the delivery queue and cleared after Mailgun accepts them. Delivery records held by the app follow the related request or scan retention period. For our managed Mailgun sending service, storage of messages for later retrieval is turned off and delivery-event logs are retained for five days. Temporary delivery processing, security records and suppression lists are separate: Mailgun retains critical security logs for 365 days, and suppression entries are kept while needed to honour opt-outs and avoid sending to rejected recipients. We review relevant erasure requests without silently removing an opt-out. If a merchant connects its own Mailgun account, that account’s provider settings apply. Scan alerts start only after a merchant enables them; the alert recipient is omitted from public storefront settings.
Before authenticated staff access privacy requests, customer tools, consent records, imported history, email delivery records, scans, backup controls or the audit history, the app records the store, Shopify staff reference, time, operation and data area. Individual path references are keyed hashes. These access records do not include requester emails, messages, query strings, passwords, tokens or export contents. If an access record cannot be saved, the protected operation is refused. The record describes an attempted access, not proof that the action succeeded. Audit records follow the store’s selected retention period and are removed with shop data.
Emails sent to our privacy address, gdpr@vanilla.net.mt, and support address, helpdesk@vanilla.net.mt, are hosted in Google Workspace and handled in Commslayer to respond to privacy, security and support requests. These services process the contact details, message contents and attachments you send. Our retention period is one year for email in Google Workspace and one year for emails and attachments in Commslayer, subject to applicable legal retention requirements. This correspondence is handled separately from store records in the app; uninstalling the app does not automatically delete these email records.
Authenticated merchants can prepare a private, paginated download of app-held store records before uninstalling. This includes readable request details, retained customer-action and withdrawal records, consent history, settings, scans and operational records. Passwords, access keys, verification links and queued email bodies are excluded. The download describes its coverage and does not fetch new records from Shopify or include provider logs, support correspondence or connected-service files. Preparation is bound to the store and staff account for up to 24 hours. Download parts are built in the merchant’s browser; we do not create a stored server archive. Access and preparation are audited without copying file contents into logs. Downloading does not delay retention or Shopify erasure. Hourly maintenance removes app records once a store has been uninstalled for more than 48 hours; Shopify shop erasure can remove them earlier. Contact our Data Protection Officer before uninstalling if assistance with return or separate support records is needed. When a published merchant agreement is explicitly accepted, we record the store, Shopify staff reference, version, document fingerprint and time. Installation alone is not acceptance. Acceptance records are included in the store download and removed with shop data.
We keep monthly per-store processing counters and cost estimates for scans and AI for about one year to enforce plan allowances and monitor service costs. These counters contain no customer identifiers, prompts or generated text, and are removed with shop data.
Vanilla Telecoms Ltd holds the Google Workspace account used for our privacy and support mailboxes. The Cloudflare, Mailgun and Commslayer accounts supporting Vanilla Consent are held by Maltashopper Ltd, company registration number C53942. Cloudflare provides hosting and storage, Mailgun provides managed email delivery, and Commslayer handles privacy and support correspondence. Vanilla Telecoms Ltd remains the supplier of Vanilla Consent and the contact for this notice. Shopify supplies store authentication and privacy controls. Support: helpdesk@vanilla.net.mt.