Privacy Policy
Last updated: January 1, 2025
1. Data Controller
CODShipEurope Lda, a company incorporated under Portuguese law, with its registered office in Lisbon, Portugal, is responsible for processing personal data collected through the CODShipEurope platform. Contact: privacy@codshipeurope.com
2. Data Collected
When you register and use the platform, we collect:
- Identity data: first name, last name, email address, phone number
- Professional data: your store name, country of activity, URLs of your Shopify stores
- Financial data: bank account details for transfers (IBAN/BIC), transaction history
- Browsing data: IP address, browser type, pages visited, session duration
- Order data: your end customers' information (name, address, phone) in the context of the COD delivery service
3. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Account creation and management | Contract performance |
| Order processing and deliveries | Contract performance |
| Bank transfers | Contract performance |
| Transactional emails | Contract performance |
| Marketing communications | Consent |
| Service improvement and analytics | Legitimate interest |
| Legal and accounting compliance | Legal obligation |
4. Data Sharing
Your data is never sold to third parties. It may be shared with:
- Technical providers: hosting (Vercel/AWS), database (Supabase), transactional emails
- Logistics partners: carriers in Europe for package delivery
- Banking institutions: for transfer processing
- Competent authorities: upon judicial or legal request
All our sub-processors are bound by a GDPR-compliant data processing agreement.
5. Retention Periods
- Account data: duration of contractual relationship + 3 years
- Financial and billing data: 10 years (legal obligation)
- Browsing data and logs: 13 months
- Order data: 5 years after the last order
6. Cookies
CODShipEurope uses only strictly necessary cookies for the service to function:
- Authentication session cookie (duration: session)
- Language preference cookie (duration: 1 year)
No advertising or third-party tracking cookies are used without your explicit consent.
7. Your Rights
Under the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to data portability: receive your data in a structured format
- Right to object: object to certain processing operations
- Right to restriction: limit the processing of your data
To exercise your rights, send an email to privacy@codshipeurope.com with a copy of your ID. We will respond within 30 days.
8. Security
CODShipEurope implements appropriate technical and organizational measures to protect your data: TLS encryption in transit, encryption at rest, restricted access on a least-privilege basis, secure authentication, and access logging.
9. Contact and Complaints
For any questions regarding the protection of your data: privacy@codshipeurope.com
You also have the right to lodge a complaint with the CNPD (National Data Protection Commission), the competent supervisory authority in Portugal.