Voidless
Privacy policy
What Voidless reads from a Shopify store, what it keeps, and what it never learns.
Last updated 9 September 2026
Who is responsible
Voidless is operated by Jaime Andia Cintora, Fueros de Aragón 58, 50500 Tarazona, Zaragoza, Spain. Questions about this policy, or about data held on your behalf, go to privacy@voidless.shop.
Voidless is a Shopify app. It is installed by a merchant on their own store, and everything it processes belongs to that merchant. For that data the merchant is the controller and Voidless is the processor: we act on their instructions and for no other purpose.
What the app reads
From the merchant's catalogue: product and variant titles, SKUs, weights, and any dimension metafields already present. These are what the audit measures.
From the merchant's orders, over the last sixty days: the order's identifier, when it was created, whether it was cancelled, whether it was a test, and for each line the quantity and which variant it was. That is the entire list.
There is no customer in that list. The app does not read names, email addresses, phone numbers, shipping addresses or billing addresses of a merchant's customers, and does not request permission to. It knows the shape of what shipped and nothing about who it shipped to.
From the shop record: the store's name and business address, used to name the economic operator on a declaration of conformity, and frozen into that document when it is issued. That is the merchant's own business information, not a customer's.
What the app stores, and what it does not
Stored: the boxes a merchant tells us they ship in, the measurements confirmed for each variant, the declarations they issue, and a record of each audit run — the number of orders assessed, how many breached, how many could not be assessed and why, and the window the audit covered.
Not stored: orders. They are read, measured, and discarded. No order identifier, no line item and no order total is written to our database. An audit leaves counts behind, not a copy of the orders it counted.
Also stored: the access token Shopify issues when a merchant installs the app. It is a credential, not personal data, and it is what lets the app read the catalogue at all. It is deleted when the app is uninstalled.
Where it lives, and who else touches it
The database is in Frankfurt and the app's server functions run in Frankfurt. Data is encrypted at rest, and connections to the database are refused unless encrypted in transit.
The services we rely on to run the app, and what each one gets:
Vercel Inc. — hosting. The app's server functions run in Frankfurt (eu-central-1).
Supabase Inc. — the database, hosted on AWS in Frankfurt (eu-central-1), encrypted at rest, and reachable only over TLS.
Anthropic PBC — optional, and off unless the merchant's installation has been given a key. When on, it receives a product title, a variant title and a weight in order to guess packed dimensions. It never receives order or customer data.
Nothing is sold, shared for advertising, or combined across merchants. There is no analytics or tracking product embedded in the app.
How long it is kept
Order data is not kept at all, so the question of how long does not arise for it.
Everything else — boxes, measurements, audits, declarations — is kept while the app is installed, because it is the merchant's compliance record and losing it would defeat the purpose. When the app is uninstalled, or when Shopify sends a shop redaction request, every row belonging to that shop is deleted.
Shopify's three mandatory privacy webhooks are implemented and answer as required: a correctly signed request is honoured, an unsigned or forged one is refused.
Rights
A merchant can ask us at any time what we hold for their shop, ask for it to be corrected, or ask for it to be deleted. Uninstalling the app does the last of those on its own.
A customer of a merchant's store who wants to exercise their rights should contact that merchant, who is the controller. If the request reaches us, we act on the merchant's instruction — and in practice there is little to act on, because we hold nothing that identifies a customer.
Either way, privacy@voidless.shop reaches us.
Changes
If what the app reads or stores changes, this document changes with it, and the date at the top changes too. Material changes are announced to installed merchants before they take effect.