1. Overview
Super Uber Local Delivery (the “app”) is a Shopify app that lets a merchant dispatch paid Shopify orders to a courier through the merchant’s own Uber Direct account, and track those deliveries back onto the Shopify order. This Privacy Policy explains what information the app processes, why it processes it, who it is shared with, and how long it is kept.
This policy covers the app itself. It does not cover a merchant’s own store, Shopify’s platform, or Uber’s services, each of which is governed by its own privacy policy.
The app processes order and customer information on behalf of the merchant who installed it, and only for the purpose of arranging and tracking that merchant’s deliveries. We do not sell personal information, and we do not use it for advertising or profiling.
2. Information we process
Store and merchant information
- Shop domain and the session and authentication data issued by Shopify.
- App settings the merchant configures: pickup address and phone number, proof-of-delivery and hand-off preferences, undeliverable-order instructions, courier tip rules, shipping cost caps, and whether automatic dispatch is enabled.
- Subscription plan, billing status, and billing period, as reported by Shopify.
- Dispatch counts used to apply the plan’s monthly dispatch limit.
Uber Direct credentials
The merchant supplies their own Uber Direct customer ID, client ID, client secret, and webhook signing key. These values, and the access token the app caches from them, are encrypted at rest with AES-256-GCM and are used only to call Uber Direct on the merchant’s behalf and to verify Uber’s webhook signatures. They are never displayed back in full and are never shared with third parties.
Order and customer information
To quote and dispatch a delivery, the app receives and stores the following from the merchant’s Shopify orders:
- Order identifier, order name, order date, and order total.
- Line item names and quantities, used to build the courier manifest.
- The customer’s name, phone number, delivery address, and any delivery notes or instructions on the order.
This is Shopify protected customer data. The app requests only the fields that Uber Direct requires to collect and deliver a package, and uses them for no other purpose.
Delivery information from Uber
- Quoted delivery fee, currency, and estimated pickup and drop-off times.
- Delivery status, courier name, the customer-facing tracking link, and delivery completion or failure details.
Technical information
- Webhook payloads received from Shopify and Uber, stored briefly so that retries are processed exactly once.
- Application logs and diagnostics used to keep the service reliable and secure. We avoid recording credentials and customer contact details in logs.
3. How we use information
- To authenticate the merchant and run the app inside Shopify admin.
- To determine which paid orders are eligible for local delivery and to request a quote from Uber Direct.
- To create, cancel, retry, and track deliveries with Uber Direct.
- To display delivery status, courier details, and tracking links in the app and on the Shopify order page.
- To record Shopify fulfillment and tracking once a delivery completes.
- To count dispatches and apply the limits of the merchant’s plan.
- To diagnose errors, prevent abuse, secure the service, and meet legal obligations.
4. How information is shared
We share information only where it is needed to provide the service:
- Uber Technologies, Inc. — the customer’s name, phone number, delivery address, delivery notes, order contents, and order value are sent to Uber Direct so a courier can collect and deliver the order. Uber processes this information under its own terms and privacy policy, and under the merchant’s Uber Direct account.
- Shopify — for authentication, app hosting inside admin, subscription billing, and writing fulfillment back to the order.
- Infrastructure providers — the hosting and database providers that run the app, acting under contract and only to operate the service.
- Legal and safety — where required by law or legal process, or to protect the rights, safety, and integrity of the service.
We do not sell personal information, share it for cross-context behavioural advertising, or use it to train machine-learning models.
5. Retention and deletion
We keep information only as long as it is needed to operate the app and to meet billing, legal, and dispute-resolution obligations. In practice:
- Delivery records, including the customer details attached to them, are retained while the app is installed so the merchant can see delivery history against their orders.
- Stored webhook payloads are retained briefly for duplicate protection and are then cleared.
- On uninstall, Shopify sessions for the store are deleted immediately.
We support Shopify’s mandatory privacy webhooks:
- Customer data request — we record the request and make the data the app holds for that customer available to the store owner so they can respond.
- Customer redaction — we delete the delivery records for that customer’s orders, along with any related usage records and queued webhook payloads holding their details.
- Shop redaction — we delete everything we hold for that store, including deliveries, settings, Uber Direct credentials, usage records, billing records, and sessions.
6. Security
- Uber Direct credentials and access tokens are encrypted at rest with AES-256-GCM.
- All traffic to and from the app is served over TLS.
- Incoming webhooks from Shopify and Uber are verified by signature before any payload is processed.
- Data is scoped per store, so one merchant’s data is never returned to another.
No system is completely secure, but we apply reasonable administrative, technical, and organisational measures to limit access and reduce risk.
7. International transfers
The app, its infrastructure providers, Shopify, and Uber may process information in countries other than the one where an order was placed. Where required, we rely on appropriate safeguards for those transfers.
8. Merchant responsibilities
The merchant is the controller of their customers’ personal information. Merchants are responsible for having a lawful basis to share delivery details with a courier network, for giving their customers any notice required by law, and for keeping their own privacy policy accurate about the use of third-party delivery providers.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or restrict the use of your personal information, or to object to certain processing.
- If you are a shopper, contact the store you ordered from. They are the controller of your information and can submit a request to us through Shopify’s privacy channels.
- If you are a merchant, you can uninstall the app or contact us at the address below to have your store’s data deleted.
10. Children
The app is a business tool for merchants and is not directed at children. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and revise the dates above. Material changes will be communicated through the app or the Shopify App Store listing.
12. Contact
Questions about this Privacy Policy, or requests about your information, can be sent to [email protected].