Scope of this policy
This policy covers the public Bidson websites, contact requests and all Bidson apps. The sections below describe the current product-specific processing for Bidson CRM Sync. Future apps will be added as separate product sections.
Website contact requests
When a visitor submits the contact form, Bidson processes the company name, first and last name, email address, optional phone number, permanent Shopify store domain for CRM Sync beta and support requests, selected topic, message, contact preference and site language to receive, secure and answer the request and, for beta requests, grant store-specific access. The form does not use the submitted address for marketing and open or click tracking is disabled for these notifications.
The website sends the request through Mailgun's EU API to Bidson's Google Workspace inbox. If the visitor keeps the copy option selected, Mailgun also sends a transactional copy to the submitted email address. Mailgun processes message data in the selected EU region, while limited account information can be handled globally. Contact correspondence is retained in the business inbox only while needed for the request, security, record-keeping or legal obligations; Mailgun keeps delivery logs according to the active account plan.
CRM Sync support and import emails
Bidson CRM Sync sends support requests through Mailgun's EU API to Bidson's Google Workspace inbox. These emails contain the contact name, reply email address, message, Shopify shop domain and technical diagnostics such as the support ID, CRM provider, error, status, time and app version.
Import-completion notifications are sent through Mailgun to the merchant's email address and contain the shop domain, CRM provider, aggregate import counts and a link to the app. The generated summary does not include individual customer records. These are service emails; open and click tracking is disabled.
Mailgun processes delivery data and logs under the active account plan. Support correspondence and replies received by Bidson are retained in Google Workspace while needed for support, security, record-keeping or legal obligations. Import notifications are delivered to the merchant's mailbox, whose retention is controlled by the merchant and their email provider.
1. Operator and scope
This policy explains how Bidson CRM Sync handles personal data. The operator's legal name, organization number, physical address and VAT number (if applicable) must be inserted before the Service is offered to external merchants. Until then, this page is a pre-launch disclosure and not a complete statutory business notice.
The operator is generally an independent controller for merchant contact, account, billing, support and website data. For Shopify customer data synchronized on a merchant's instructions, the merchant is the controller and the operator is its processor.
2. Personal data handled
The Service does not intentionally persist complete raw Shopify customer or order data received through automatic updates. Shopify session secrets and credentials for the selected CRM are encrypted by the application before storage. Shopify credentials are retained only as required to operate the installed app.
- Merchant and administrator data, including shop domain, Shopify session details, staff name and email where supplied by Shopify, billing state, CRM connection configuration and support correspondence.
- Shopify customer data processed for synchronization, including name, email address, phone number, tags, marketing-consent status, Shopify identifiers and aggregated order count, spend, currency and latest-order information.
- Technical data, including linkage identifiers, job state, timestamps, error categories, opaque support IDs and security events. Logs are designed to exclude access tokens and customer payloads.
3. Sources, purposes and legal bases
Data comes from the merchant, Shopify, the merchant-selected CRM workspace or account and normal use of the Service. It is used to authenticate installations, provide and secure synchronization, administer plans, diagnose failures, answer support requests, meet legal obligations and improve service reliability.
For data controlled by the operator, processing is based as applicable on performance of the merchant agreement, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent where the law requires it. Customer data is processed only on the merchant's documented instructions under the data processing agreement. The merchant remains responsible for its own legal basis and privacy notices.
5. International transfers
Production workloads are configured for a European Railway deployment region, but Railway states that its primary processing operations take place in the United States and that authorized subprocessors may operate in other countries. Railway's DPA provides transfer mechanisms including the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
The merchant controls the Shopify and selected CRM accounts and should assess the locations and transfer mechanisms applicable under its own agreements. Use of an EU hosting region does not mean that every processing operation or support access remains in the EEA.
6. Retention and deletion
- Import and automatic-update history is normally deleted after 90 days.
- Fulfilled privacy-request metadata is normally deleted after 30 days.
- Active credentials, configuration and customer-to-CRM linkages are retained while needed to provide the installed Service.
- Failed import and automatic-update jobs are normally deleted after 30 days. Unresolved privacy obligations remain actionable until resolved or terminal shop redaction.
- Uninstallation and verified privacy requests trigger application-level deletion or redaction, subject to legal obligations, security needs and technically necessary backup cycles.
7. Security
The Service uses data minimization, application-encrypted Shopify session secrets and CRM credentials, restricted technical logging, idempotent processing and provider security controls. No system can guarantee absolute security. Hosting-level transport, storage and access controls are verified separately from application code before broad commercial launch.
The Service does not sell customer data or use it for advertising or training AI models. It does not make decisions producing legal or similarly significant effects about individuals.
8. Individual rights and complaints
A Shopify customer should normally contact the merchant that controls the data. The operator assists merchants with access, deletion and redaction requests through Shopify's mandatory privacy processes. Merchant users may contact support about operator-controlled personal data and, where applicable, request access, correction, deletion, restriction, portability or objection.
Individuals may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority. Rights can be limited by applicable law and the operator may need to verify identity before acting.
10. Contact and changes
Questions and privacy requests can be sent to the support address below. A dedicated privacy/security contact and the operator's complete statutory identity must be published before external production use. Material changes will be reflected on this page with an updated date.