Privacy policy

Last updated 12 September 2026

Despatchly connects a Shopify store to the merchant's own Royal Mail Click & Drop account. This policy describes exactly what the app reads, what it stores, and for how long.

What Despatchly reads from Shopify

What Despatchly never reads

Why

Royal Mail requires a recipient name and address to create an order. That is the only reason the data is read. It is sent to Royal Mail's Click & Drop API under the merchant's own API key and is never sold, shared with advertisers, or used to train anything.

Where it is stored

Sync records are stored in an isolated per-shop database on Cloudflare Workers. The merchant's Click & Drop API key is encrypted with AES-256-GCM before it is written, and is decrypted only to make a request to Royal Mail. Recipient details never appear in application logs.

Access logging

Despatchly keeps an audit trail of every time an order's delivery details are read from Shopify, sent to Royal Mail, or used to write a fulfilment back. The trail records the order identifier, the action and the time only. It never contains a name or an address, and it is deleted on the same 90-day schedule as everything else.

How long it is kept

Processors

Your rights

The merchant is the data controller for their customers' data; Despatchly acts as a processor. Requests to access or erase data can be made through the Shopify admin, or by email to privacy@keelcroft.com, and are answered within 30 days.