Packward
Privacy Policy
Packward prints pick lists and packing slips for Shopify stores, published by Coreyard. This policy describes what data the app touches and what happens to it. Last updated September 17, 2026.
What we access
When a merchant installs Packward, the app reads one thing through the Shopify Admin API, with the merchant's authorization: orders that are not yet fulfilled, and only to print them, order number, date, items, quantities, SKUs, the shipping address and the order note. The app does not request access to products or customer records, and writes nothing back to the store.
What we store
Order content is read from Shopify each time a document is printed and is never written to our database. What we store is a print batch (a list of Shopify order IDs and an expiry) and, per printed order, its order number and the date it was printed. We never store customer names, email addresses, shipping addresses, phone numbers, items or payment details.
Print links
A batch opens at a link carrying a random token. Anyone holding that link can see the addresses in that batch until it expires, two hours after it was created. Do not forward it outside your team.
Where it lives
Data is stored in a European data center, encrypted in transit (TLS) and covered by encrypted backups. Access is limited to the app itself.
Deletion
Uninstalling the app revokes its access immediately. Shopify then sends us a deletion request, and all stored data for the store is permanently removed within 48 hours. Merchants can also email us for immediate deletion.
Data processing (DPA)
This section is the data processing agreement between you (the merchant, as controller) and Coreyard (as processor), and it takes effect when you install the app.
Subject and purpose. We read your unfulfilled orders, order number, date, items, quantities, SKUs, the shipping address and the order note, at the moment you print, to render a pick list and packing slips. We store per order only its number and the date you printed it.
Instructions. We process this data only to provide the service described above, only on your instructions, and never for our own purposes, advertising, resale or model training.
Sub-processors. netcup GmbH (hosting, Germany), Cloudflare (DNS and TLS termination), Google Drive (encrypted off-site backups), and Resend (transactional email, used only when you write to us from the app). We will tell you before adding one.
Confidentiality. Access is limited to the single operator of Coreyard, over key-based authentication, with per-app database credentials.
Retention and deletion. Described above. Uninstalling revokes access immediately; Shopify then sends a deletion request and everything stored for your shop is removed within 48 hours. You can also ask us to delete it sooner.
Security incidents. If we become aware of a breach affecting your data, we will tell you without undue delay and in any case within 72 hours, with what happened, what data was concerned and what we did about it. Our response runs: contain, revoke credentials, restore from an encrypted backup, notify you, then publish what changed so it does not happen twice.
Audit. On request we will answer questions about this processing in writing, including the list of what we store and where.
International transfers. Data stays in the European Union. Backups are encrypted before they leave the server.
Contact
Questions or requests: hello@bycoreyard.com