Privacy Policy — EU Withdrawal Button

Last updated: August 2026

EU Withdrawal Button helps Shopify merchants comply with Article 11a of the EU Consumer Rights Directive (Directive (EU) 2023/2673) by providing an online withdrawal function for their customers.

Data we process

Merchant data: store domain, app settings, plan status. Withdrawal requests: customer name, email, order reference, selected items, optional reason, timestamps and technical metadata (IP, user agent) required as legal evidence. Order data: accessed via the Shopify API solely to match a withdrawal request to an order and, on merchant request, to create a refund; only a minimal snapshot is stored.

Purpose and legal basis

Providing the withdrawal function required by EU law: recording declarations, sending confirmations on a durable medium, assisting the merchant. Legal basis: Art. 6(1)(b) and (c) GDPR.

Storage and retention

All data is stored and processed exclusively in the EU (AWS eu-central-1, Frankfurt). Records are kept while the app is installed; on uninstall all shop data is deleted within 48 hours via Shopify's mandatory GDPR webhooks. Customer redaction requests result in anonymisation while preserving the legal record.

Sharing and contact

No sale or sharing of personal data. Sub-processor: Amazon Web Services EMEA SARL (EU region only). Contact: humans@fuori.ai.