Privacy Policy — Pay & Upload
Effective date: 31 August 2026
Last updated: 31 August 2026
This Privacy Policy explains how DELUNA LIMITED ("DELUNA", "we", "us", or "our") collects, uses, discloses, stores, and deletes personal data when merchants install or use the Pay & Upload Shopify application (the "App"), when merchant staff contact us, and when customers interact with the App on a merchant’s post-checkout pages.
Company details
DELUNA LIMITED
Privacy contact: itsupport@lovedeluna.com
1. Our role
For receipt images and order-linked information submitted through a merchant’s store, the merchant generally decides why and how that information is collected. The merchant is normally the data controller or data user, and DELUNA processes that information on the merchant’s behalf to provide the App.
DELUNA acts as a controller or data user for information needed to manage merchant accounts, subscriptions, support, product security, legal compliance, and our own business records.
Customers should normally direct questions about an order, receipt, or payment to the merchant from whom they purchased. We will assist merchants with valid privacy requests as required by applicable law and Shopify’s platform requirements.
2. Information we process
2.1 Merchant store and staff information
We may process:
- Shopify store domain, store identifier, installation status, selected plan, usage counters, and application settings;
- Shopify session and authorization information required to operate the App;
- merchant staff identifiers and, where Shopify provides them, name, email address, locale, and account attributes;
- configured manual payment method names, customer-facing labels, payment instructions, links, QR settings, currencies, display order, and feature settings;
- encrypted third-party service credentials entered by a merchant, where a supported integration requires them;
- billing status and subscription identifiers received from Shopify;
- support correspondence and diagnostic information.
2.2 Order and receipt information
We may process:
- Shopify order identifiers, order display numbers, payment-method labels, currency, amount, financial status, cancellation status, and checkout or customer-account access tokens needed for the post-checkout experience;
- receipt files uploaded by customers or merchants, including the filename, file type, file size, storage key, upload time, review status, merchant note, and rejection reason;
- information visible inside an uploaded image. A receipt may contain a name, bank or wallet reference, transaction reference, amount, date, or other information chosen by the uploader;
- short-lived access grants used to authorize receipt upload or viewing;
- audit records showing actions such as upload, approval, rejection, configuration changes, and the staff identifier associated with an action.
The App is not designed to collect full payment-card numbers, card security codes, online-banking passwords, government identity documents, or unrelated sensitive information. Merchants should tell customers not to include unnecessary information in uploaded files.
2.3 Technical information
We may process server logs, request timestamps, IP addresses where included in infrastructure logs, browser or device information, error reports, security events, and other information reasonably required to operate and protect the App.
3. Why we use information
We process information to:
- install, authenticate, maintain, and provide the App;
- display merchant-configured payment instructions after checkout;
- accept, store, retrieve, and display order-linked receipt files;
- let authorized merchant staff approve or reject receipts;
- enforce plan limits, storage limits, and receipt-retention settings;
- provide customer and merchant support;
- prevent abuse, investigate errors, maintain audit trails, and protect the App;
- administer subscriptions through Shopify Billing;
- comply with law, lawful requests, Shopify platform obligations, and the enforcement of our Terms;
- improve reliability and product usability using appropriately limited operational data.
Where a legal basis is required, processing may be based on performance of our contract with a merchant, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where applicable. Merchants are responsible for establishing the appropriate legal basis and notice for customer information they direct us to process.
4. How information is disclosed
We may disclose information:
- to the merchant and authorized staff of the store connected to the order;
- to Shopify as required to operate the App and comply with Shopify policies;
- to infrastructure, database, private object-storage, monitoring, customer-support, and other service providers acting under our instructions;
- to professional advisers, insurers, auditors, regulators, courts, or law-enforcement authorities where reasonably necessary or legally required;
- in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal safeguards;
- where the merchant or affected person instructs or authorizes us to do so.
We do not sell personal data. We do not use receipt contents for third-party advertising.
We use service providers for cloud application hosting, managed databases, private object storage, monitoring, security, and customer support. These providers process information only as needed to provide their services to us and are subject to applicable contractual, confidentiality, security, and data-protection obligations. We may change providers as our service develops. Merchants may request current information about the relevant categories of providers by contacting itsupport@lovedeluna.com.
5. International transfers
Our service providers may process information outside the location of the merchant or customer, including in jurisdictions where they or their infrastructure operate. Where information is transferred internationally, we use contractual, organizational, technical, or other safeguards required by applicable law. Information about applicable transfer safeguards may be requested by contacting itsupport@lovedeluna.com.
6. Retention and deletion
Receipt files and their associated records are retained according to the merchant’s selected plan and settings:
- Free: up to 30 days;
- Lite: up to 60 days;
- Growth: up to 90 days;
- Pro: up to 365 days.
The merchant may select a shorter period where the plan allows it. When the selected receipt-retention period expires, the receipt stops being available to customers and merchant staff. The private receipt image is held in restricted storage for a further 90 days and is then permanently deleted. The remaining receipt database record, which may include metadata such as filename, payment method, status, notes, and timestamps, is held for a further 730 days after the selected retention period expires and is then permanently deleted. These periods may be shortened when required by a validated Shopify privacy request or extended only where law, a dispute, fraud prevention, or the establishment of legal rights requires it. Temporary order access grants are generally retained for up to 90 days unless deleted earlier.
When the App is uninstalled, active application sessions are removed and the store is marked as uninstalled. Shopify normally sends the mandatory shop-redaction request after its platform waiting period. When we receive and validate that request, we delete the store record, its dependent configuration and receipt records, and the corresponding private receipt files, except information we must retain to comply with law, resolve disputes, prevent fraud, or establish legal rights.
Infrastructure backups may retain deleted information for up to 30 days before automatic secure expiry and permanent deletion under the applicable backup lifecycle. Data retained in a backup is not restored for ordinary business use and remains protected until deletion.
Merchant support, operational billing, security, and legal case records are normally retained for up to three years after the relevant interaction, transaction, incident, case, or account relationship ends. Records may be retained for longer where reasonably necessary to comply with applicable law, taxation or accounting requirements, resolve disputes, prevent fraud, or establish, exercise, or defend legal claims. In particular, financial and business records are retained for any longer minimum period required by applicable law.
7. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted network transport, private object storage, authorization checks, tenant separation, file type and size validation, protected secret storage, audit records, and restricted production access.
No internet service can guarantee absolute security. Merchants are responsible for safeguarding their Shopify accounts, limiting staff permissions, reviewing configured payment instructions, and contacting us promptly if they suspect unauthorized access.
Security reports may be sent to itsupport@lovedeluna.com.
8. Privacy rights and requests
Depending on applicable law, a person may have rights to request access to or correction of personal data, ask for deletion or restriction, object to certain processing, withdraw consent, or receive information about how data is used.
Customers should first contact the merchant that collected the receipt or order information. Merchants may contact us at itsupport@lovedeluna.com with sufficient information to identify the store and relevant order. We may need to verify identity and authority before responding.
We will cooperate with Shopify’s mandatory privacy webhooks and valid merchant instructions. We aim to complete verified requests within the period required by applicable law and Shopify’s requirements.
For a Shopify customer data request, we record the request identifier and the order identifiers supplied by Shopify. An authorized merchant administrator can use the App’s Privacy requests page to download an export of the order-linked receipt metadata and any receipt files that remain in private storage, then mark the request complete. We do not store customer profile fields beyond the request reference needed to process the request. If Shopify supplies no order identifier, the merchant should contact us at itsupport@lovedeluna.com so that we can investigate the request within the required period.
Individuals may also complain to their local data-protection authority. In Hong Kong, information about privacy rights is available from the Office of the Privacy Commissioner for Personal Data.
9. Children
The App is a business service for Shopify merchants and is not directed to children. We do not knowingly ask children to create an account with DELUNA. Merchants remain responsible for the age and privacy requirements applicable to their stores and customers.
10. Merchant responsibilities
Merchants using the App must:
- provide customers with an appropriate privacy notice before collecting receipts;
- collect only information that is necessary and not excessive for confirming payment;
- avoid requesting full card details, passwords, identity documents, or unrelated sensitive data;
- configure suitable retention periods and restrict staff access;
- respond to customer privacy requests and notify DELUNA when our assistance is required;
- use receipt information only for lawful order, payment, accounting, fraud-prevention, or support purposes.
11. Changes to this Policy
We may update this Policy to reflect product, legal, or operational changes. We will update the “Last updated” date and provide additional notice where a material change requires it. Earlier versions will be archived where reasonably practicable.
12. Contact
For privacy questions or requests:
DELUNA LIMITED
itsupport@lovedeluna.com