Privacy policy
Last updated 12 September 2026
Despatchly connects a Shopify store to the merchant's own Royal Mail Click & Drop account. This policy describes exactly what the app reads, what it stores, and for how long.
What Despatchly reads from Shopify
- Order details needed to create a Royal Mail order: order name and date, line items, SKUs, quantities, weights, prices, taxes, shipping charged, currency, shipping method and order tags.
- The delivery address: recipient name, company name, address lines, town or city, county, postcode and country.
- Optionally, and only if the merchant turns on customs data from products: product titles, commodity codes and country of origin.
What Despatchly never reads
- Customer email addresses and phone numbers.
- Payment details, card data or bank information.
- Customer accounts, marketing consent or analytics profiles.
- Themes, files or storefront content.
Why
Royal Mail requires a recipient name and address to create an order. That is the only reason the data is read. It is sent to Royal Mail's Click & Drop API under the merchant's own API key and is never sold, shared with advertisers, or used to train anything.
Where it is stored
Sync records are stored in an isolated per-shop database on Cloudflare Workers. The merchant's Click & Drop API key is encrypted with AES-256-GCM before it is written, and is decrypted only to make a request to Royal Mail. Recipient details never appear in application logs.
Access logging
Despatchly keeps an audit trail of every time an order's delivery details are read from Shopify, sent to Royal Mail, or used to write a fulfilment back. The trail records the order identifier, the action and the time only. It never contains a name or an address, and it is deleted on the same 90-day schedule as everything else.
How long it is kept
- Order sync records and their audit history are deleted 90 days after the order is despatched or cancelled.
- Everything belonging to a shop, including the encrypted API key, is deleted when the app is uninstalled.
- A
shop/redactrequest from Shopify deletes all remaining shop data. Acustomers/redactrequest deletes the sync records for the orders named in the request.
Processors
- Cloudflare, Inc. — application hosting and per-shop storage.
- Royal Mail Group Ltd — recipient of the order data, under the merchant's own Click & Drop account.
- Shopify Inc. — source of the order data.
Your rights
The merchant is the data controller for their customers' data; Despatchly acts as a processor. Requests to access or erase data can be made through the Shopify admin, or by email to privacy@keelcroft.com, and are answered within 30 days.