Tendor Tendor
Legal

Privacy Policy

How Tendor apps handle personal data — for the merchants who install them and the shoppers who use their stores.

Last updated: 23 September 2026

Tendor is a suite of Shopify apps operated by datadir s. r. o. ("Datadir", "we", "us"). This policy explains what personal data we process, why, and the rights you have. It covers our apps and this website.

1. Who we are

datadir s. r. o., Bauerova 1205/7, 040 23 Košice, Slovakia (IČO 57 582 904; registered at the Municipal Court Košice, section Sro, insert no. 65729/V). Full company details are on our Legal notice. For any privacy question or to exercise your rights, contact hello@datadir.co.

2. The two relationships

We process personal data in two distinct roles:

  • As a processor, on behalf of a merchant who installs one of our apps. The merchant is the controller of their store and customer data; we act on their documented instructions. This is governed by our Data Processing Agreement.
  • As a controller, for the merchant's own account and billing data, and for visitors to this website.

3. What we process

CategoryExamplesRole
Merchant accountStore domain, contact name and email, plan and billing statusController
Store dataProducts, inventory, prices, orders and metadata accessed via the Shopify API to provide the app's functionProcessor
Shopper dataWhere an app requires it (e.g. a back-in-stock email address, a wishlist), the minimum needed to deliver that featureProcessor
Usage & logsApp events, audit-log entries, and technical logs used to operate and secure the serviceController / Processor
WebsiteStandard request logs; no advertising or cross-site tracking cookiesController

4. Why, and on what legal basis

  • To provide the service you or the merchant asked for — performance of a contract.
  • To secure and improve it — our legitimate interest in a reliable, safe product. For data we hold as a processor on a merchant's behalf, any improvement use is limited to the merchant's instructions or to aggregated / anonymised data.
  • To meet legal obligations — tax, accounting, and responding to lawful requests.

5. Where data lives

Application data is hosted in the European Union — on Hetzner (Germany), with encrypted backups on Scaleway (France). The only routine transfer outside the EEA is to Shopify, which processes under its own DPA relying on an adequacy decision and/or Standard Contractual Clauses. See the full sub-processor list in our DPA.

6. Retention

Store and shopper data processed on a merchant's behalf is retained only while the app is installed, and is deleted (or returned) within 30 days after uninstall (and in any event on Shopify's shop/redact), subject to the periods in the DPA. Billing records are kept as long as the law requires. Audit-log entries are retained to preserve the tamper-evident record for the life of the account, then deleted or irreversibly anonymised within 12 months of termination.

7. Your rights

Subject to your role and applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. Shoppers should contact the merchant (the controller); we will assist that merchant. Merchants and website visitors can contact us directly at hello@datadir.co. You may also complain to your local data-protection authority.

8. Shopify's mandatory data requests

We honour Shopify's customers/data_request, customers/redact, and shop/redact webhooks, returning or deleting the relevant data on the platform's schedule.

9. Changes

We'll post any changes here and update the date above. Material changes affecting merchants will be notified by email.