Legal · App supplement

Privacy Policy: Batch Dispatch

Supplement to the Megatronic Ltd Privacy Policy  |  Company No. 17202380

Last updated: 18 September 2026Version 2.0

Read this with the master policy

This supplement forms part of, and must be read together with, the Privacy Policy. The master sets out who we are, your rights, how to complain, security measures, this website’s cookies and everything else common to all our apps. This supplement adds what is specific to Batch Dispatch. Where the two differ, this supplement applies to Batch Dispatch.

1. About Batch Dispatch

Batch Dispatch is a shipping label automation tool. It connects a merchant’s Shopify store directly to courier APIs (currently Evri and DHL) to generate, format, and distribute print-ready shipping labels. The App also enables collection point and parcel shop label generation on standard Shopify plans, without requiring a Shopify Plus subscription.

By installing Batch Dispatch, the merchant agrees to this Privacy Policy. If you do not agree, please do not install or use the App.

2. Who This Supplement Covers

Batch Dispatch involves two distinct groups with different legal relationships to Megatronic Ltd:

Merchants

Shopify store owners who install and subscribe to Batch Dispatch. Megatronic Ltd is the data controller for merchant account data.

End Customers

Consumers who place orders in a merchant’s Shopify store. Megatronic Ltd acts as a data processor on the merchant’s behalf when handling end customer shipping data. The merchant remains the data controller.

We have no direct relationship with end customers. We process their shipping data solely to fulfil the merchant’s instruction to generate a shipping label. We never contact end customers, sell their data, profile them, or use their data for any purpose beyond label generation and delivery.

3. What Data We Handle and Why

3.1 Merchant Account Data (we are data controller)

When a merchant installs and uses Batch Dispatch, we collect and store the following:

  • Shopify store domain and store ID, received via Shopify OAuth at installation
  • Merchant contact name and email address, received via Shopify OAuth
  • Subscription tier and label volume counts, used for billing via Shopify's native billing system
  • App configuration settings and courier preferences
  • Courier API credentials for Evri, DHL, and any future couriers, stored encrypted at rest; after initial entry the key is obfuscated so only the final four characters are visible
  • Merchant-provided FTP or Amazon S3 connection credentials, where configured on paid tiers, stored encrypted and obfuscated in the same manner
  • Tracking numbers generated for each order, stored in our database linked to the Shopify order ID only, not to any customer personal data
Legal basis: Performance of a contract (Article 6(1)(b) UK GDPR).

3.2 End Customer Shipping Data (we are data processor)

When a merchant triggers label generation, the following end customer data is retrieved from Shopify and processed:

  • Customer full name
  • Delivery address (including postcode)
  • Email address

This data is used exclusively to:

  • Transmit to the selected courier API (Evri or DHL) to generate a shipping label and obtain a tracking number
  • Render the label as a print-ready PDF to the courier's exact print specification
  • Deliver the PDF to the merchant's configured storage location, or make it available for manual download on the free Starter tier

This data is not stored in our database. It transits our servers for processing only.

Legal basis: Performance of a contract (Article 6(1)(b) UK GDPR).

3.3 Parcel Shop and Collection Point Lookups

The App queries the Evri courier API using a customer’s delivery postcode to retrieve the relevant parcel shop ID. This is a live lookup only. The postcode is transmitted to Evri’s API and is not stored in our database. If a postcode is captured in an error log during a failed lookup, it is deleted with those logs at 30 days.

3.4 Error Logs and Retry Data

When a failure occurs, the system logs the Shopify order ID and the error cause, executes an automatic retry sequence, and surfaces unresolved failures in the merchant’s console. Error logs may contain fragments of customer data if the failure originated within a courier or Shopify API response. These logs are held on our Hostinger VPS server and are permanently deleted at 30 days.

Legal basis: Legitimate interests (Article 6(1)(f) UK GDPR). Retention limited to 30 days.

3.5 Generated Label PDFs

TierRetention
Starter (free)Fixed 30 days. Not configurable. Labels available for manual download within the App.
Paid tiers30, 60, or 90 days as selected by the merchant. Default is 30 days. Where external storage is configured, PDFs are also pushed to the merchant’s S3 bucket or FTP server.

3.6 Tracking Number Write-back

Once a tracking number is obtained from the courier, the App writes it back into the Shopify order record via the Shopify API. The tracking number is also stored in our database linked to the Shopify order ID only. No customer personal data is stored alongside the tracking number in our database.

3.7 Usage and Performance Analytics

We collect server-side, first-party operational analytics: label counts per merchant per billing period, and API success and failure rates. No personal data is included in analytics. No individual order details, customer names, addresses, or postcodes are used. We do not use third-party analytics platforms within the App. (Our marketing website uses consent-based Google Analytics, see the master policy.)

4. Where Data Is Stored

All Megatronic Ltd server infrastructure is located in the United Kingdom (Hostinger VPS, UK datacentre). No personal data processed by Batch Dispatch is transferred outside the United Kingdom or the European Economic Area (EEA).

LocationWhat's stored
Our databaseMerchant account data, encrypted API credentials, tracking numbers linked to order IDs only. No customer personal data.
Our VPS server (UK)Generated label PDFs (30–90 days) and error logs (30 days fixed).
Merchant storage (S3/FTP)Paid tiers only. Label PDFs delivered to merchant-owned storage. Megatronic Ltd does not control this storage.
ShopifyOrder data, tracking numbers written back by the App. Governed by Shopify's own privacy policy.
Courier APIsShipping data transmitted for label generation. Governed by each courier's data processing agreement.

5. Third-Party Sub-Processors

We use the following sub-processors. Each is contractually bound to handle data only as instructed and in accordance with applicable data protection law:

Sub-processorRole
Hostinger (VPS Hosting)UK-based server hosting. All data encrypted at rest.
Evri (Hermes Europe Ltd)Courier API. End customer name, address, email, and postcode transmitted for label generation and parcel shop lookup.
DHL (DHL Parcel UK Ltd)Courier API. End customer name, address, and email transmitted for label generation.
ShopifyPlatform provider. Subscription billing processed by Shopify. Tracking numbers written back to Shopify order records.
Google WorkspaceBusiness email used to communicate with merchant account holders only. End customer data is never shared via email.
Amazon Web Services S3 (optional)Paid tiers only. Merchant-configured storage. Megatronic Ltd facilitates the connection but does not access data in the merchant's own S3 bucket.

Additional couriers will be named in this policy before any integration goes live. Merchants may request an up-to-date list of sub-processors at any time by contacting hello@mega-tronic.com

6. Merchant-Owned Storage (Amazon S3 and FTP)

Available on paid tiers (Growth, Professional, Scale) only. Not available on the Starter free tier.

  • The connection is established between the App and the merchant's storage, facilitated by Megatronic Ltd
  • Megatronic Ltd does not access, read, or process any data held within the merchant's storage beyond delivering the label PDF
  • The merchant is solely responsible for the security, configuration, and data protection compliance of their own storage environment
  • Megatronic Ltd strongly recommends merchants use a dedicated, isolated S3 bucket or FTP location entirely separate from any other business infrastructure
  • S3 access keys and FTP credentials are stored encrypted in our database and obfuscated after initial entry; only the final four characters remain visible
  • Merchants are responsible for rotating their own credentials. Megatronic Ltd accepts no liability for data held in or accessed via merchant-controlled storage environments

7. Data Retention

DataRetention period
Label PDFs (Starter tier)Fixed 30 days from label creation. Not configurable. Deleted automatically.
Label PDFs (paid tiers)30, 60, or 90 days as selected by the merchant. Default 30 days. Deletion is automatic.
Error logsFixed 30 days. Not configurable. Deleted automatically.
Merchant account dataDuration of subscription plus 12 months after cancellation or uninstallation, then permanently deleted.
Tracking numbers (our DB)Duration of merchant subscription. Deleted on receipt of shop/redact webhook or 12 months post-cancellation.
Analytics (non-personal)Retained indefinitely in aggregated, anonymised form.
Email correspondenceGoogle Workspace standard retention, subject to our internal business records policy.

Note: “deletion” means removed from our active systems and databases. Server infrastructure backups are purged on a rolling 30-day cycle.

7A. Merchant Retention Responsibility

Label PDFs stored by Megatronic Ltd on behalf of a merchant contain personal data belonging to that merchant’s customers. Megatronic Ltd acts as data processor; the merchant is the data controller.

Paid tier merchants who select a retention period beyond the 30-day default confirm that they have identified a specific operational purpose justifying the extended period, and accept responsibility for that retention decision in their capacity as data controller.

Shopify compliance redact webhooks override the merchant’s configured retention period. On receipt of a valid customers/redact or shop/redact request, the relevant data is deleted immediately.

8. Security Measures

  • All data is encrypted in transit using TLS/HTTPS
  • All data stored on our servers is encrypted at rest
  • Courier API keys, FTP credentials, and S3 access keys are encrypted in our database; only the final four characters are visible after initial entry
  • Access to production systems and personal data is restricted to authorised Megatronic Ltd personnel only
  • Access logs are maintained for all systems that hold personal data
  • In the event of a personal data breach we will notify the ICO within 72 hours and affected merchants without undue delay, as required by UK GDPR Article 33

9. Shopify Mandatory Compliance Webhooks

Batch Dispatch subscribes to and verifies all three mandatory Shopify compliance webhooks:

customers/redact

Upon receipt, all personal data associated with the identified customer is deleted from our active systems immediately, overriding any merchant-configured retention period.

shop/redact

Sent 48 hours after app uninstallation. Upon receipt, all data associated with the merchant's store is permanently deleted from our active systems.

customers/data_request

Upon receipt, all personal data held for the identified customer is compiled and returned to the merchant within the required timeframe.

10. Cookies in the App

Batch Dispatch uses a small number of cookies that are strictly necessary for the App to function. No tracking, analytics, advertising, or preference cookies are used in the App. Because these cookies are strictly necessary, they do not require consent under UK PECR.

Cookie namePurposeDuration
laravel_sessionMaintains your authenticated merchant session within the App120 minutes
XSRF-TOKENProtects against cross-site request forgery (CSRF) attacksSession
Sanctum sessionAuthenticates API requests made from the App interfaceSession

Cookies on this website are described in the Privacy Policy.

11. Our Position on Children’s Data

Batch Dispatch is a business-to-business tool for Shopify merchants. Megatronic Ltd has no direct relationship with end customers and no mechanism to identify the age of any end customer whose shipping data is processed through the App.

The merchant is the data controller for their customers’ data and is solely responsible for ensuring that their store’s data collection and processing practices are lawful, including any obligations relating to customers who may be under the age of 18.

12. Changes to This Supplement

Where changes affecting Batch Dispatch are material, we will:

  • Notify merchants via email at least 14 days before the change takes effect
  • Update the version number and last updated date at the top of this document
  • Require merchants to acknowledge the updated policy on their next login before continued use

Who we are, your data subject rights, and how to complain are set out in the Privacy Policy. Privacy contact: hello@mega-tronic.com.

Megatronic Ltd  |  Batch Dispatch supplement  |  Version 2.0  |  Company No. 17202380  |  ICO Registration No. ZC156233  |  Last updated 18 September 2026