Scope
Safarx Courier is a Shopify app that lets merchants book Shopify orders for delivery with Safarx, a courier service operating in Pakistan. This policy explains what data the app accesses, why, and how it's handled — for merchants who install the app and the customers whose orders pass through it.
By installing Safarx Courier, the merchant agrees to the collection and use of information as described here. This policy is written to satisfy Shopify's app requirements and applicable data protection law, including the Pakistan Personal Data Protection framework and, where relevant, GDPR principles for stores serving EU customers.
Information we collect
The app reads two categories of data: order details needed to create a courier booking, and the merchant's own Safarx account settings.
Order & customer data (from Shopify)
| Field | Why it's read |
|---|---|
| Order number & ID | Reference for the courier booking and fulfillment sync |
| Customer name, phone, address | Passed to Safarx as the delivery recipient |
| Line items & quantities | Included in the parcel's product description |
| Order total & payment status | Sets the cash-on-delivery amount for the booking |
| Tags, notes, fulfillment status | Updated after booking to reflect the Safarx tracking number |
Merchant account data
| Field | Why it's stored |
|---|---|
| Safarx Auth Key & Client Code | Authenticates booking requests to the merchant's own Safarx account |
| Shipper name, phone, address, city | Used as the "from" details on every booking |
| Booking preferences | Default product/service, auto-tag, auto-fulfill, and similar settings the merchant configures |
| Shopify access token & shop domain | Required by Shopify to keep the app installed and authenticated |
We do not collect payment card numbers, passwords, or government ID numbers. We do not access a customer's order history beyond the specific order being booked.
How we use it
- To create, look up, and cancel parcel bookings through the Safarx API on the merchant's behalf.
- To write the resulting Safarx tracking number back onto the Shopify order, and optionally tag, fulfill, or add an order note.
- To show the merchant a list of their bookings and statuses inside the app.
- To keep the merchant's Safarx connection configured correctly (testing the connection, showing account status).
We do not use order or customer data for advertising, profiling, or any purpose unrelated to fulfilling the booking the merchant requests.
Storage & retention
Order and customer details are not stored in our database. Each time the merchant opens the booking screen, order data is fetched live from Shopify, sent to Safarx to create the booking, and then discarded from our servers — nothing about the customer or the order contents persists afterward.
What we do store, for as long as the app stays installed, is limited to the merchant's own account data listed in Section 02 — Safarx credentials, shipper details, and preferences — plus the Shopify session needed to keep the app authenticated. All of it is deleted automatically when the merchant uninstalls the app.
Security
- All data in transit — between Shopify, our servers, and Safarx — is encrypted over HTTPS/TLS.
- Webhook requests from Shopify are verified with HMAC signatures before being processed.
- Access to stored merchant settings is restricted to the app's own backend; no dashboard or third party can browse it directly.
- Shopify access tokens are never exposed to the browser or logged in plain text.
Your rights
In line with Shopify's mandatory compliance requirements, the app responds to three data requests automatically:
- Customer data request — because we don't retain customer data after a booking is made, there is nothing on our side to return; any records live with Shopify and Safarx directly.
- Customer redaction — acknowledged immediately; there is no stored customer record to erase.
- Shop redaction — when a merchant uninstalls, their stored settings and session are permanently deleted within 48 hours.
Merchants can also disconnect their Safarx account at any time from the app's Settings page, or contact us directly to request early deletion of their stored settings.
Cookies & tracking
Safarx Courier runs embedded inside Shopify admin and authenticates using Shopify's session tokens, not tracking cookies. We do not use analytics pixels, advertising cookies, or cross-site tracking of any kind.
Children's data
This app is a business tool for merchants and is not directed at children. We do not knowingly process data belonging to children under 13.
Changes to this policy
If this policy changes, the "Effective" date at the top of this page will be updated. Material changes affecting how customer data is handled will also be communicated to merchants through the app.
Contact
Questions about this policy or a request relating to your data can be sent to: