Privacy policy
How Helm Connect handles data. Last updated 8 August 2026.
What this app is
Helm Connect connects a Shopify store to that merchant's own dedicated order-management instance, used to book parcels with courier companies, track deliveries, and reconcile cash-on-delivery payments. Each merchant has a separate instance with its own database; no merchant's data is mixed with another's.
What the app stores
- Your store's domain
- For example
your-brand.myshopify.com, to identify the install. - An access token, encrypted
- The Shopify access token granted at install, encrypted at rest with AES-256-GCM. It is what allows your order-management instance to read your orders and products.
- The address of your instance
- The endpoint your store's order notifications are delivered to.
- A record of privacy requests
- When Shopify notifies us of a customer data or deletion request, we record the store, the customer and order reference numbers involved, and the date. We do not record customer names, email addresses or phone numbers in that log.
What the app does not store
No customer data is stored by this app. When you receive an order, Shopify sends the order details to this app, which passes them straight through to your own instance and keeps nothing. Order and customer details exist inside this app only for the moment it takes to forward them — they are never written to its database, and the app keeps no logs of order contents.
Your customers' names, addresses and phone numbers are held in your own instance, because that is what a courier needs on an airway bill to deliver the parcel.
Why we process it
Solely to operate the order-management service you have signed up for: booking couriers, tracking parcels, and reconciling COD payments. We do not use your data or your customers' data for advertising, profiling, enrichment or automated decision-making, and we never sell it or share it with anyone for their own purposes.
Who else is involved
Two infrastructure providers process data on our behalf, under their own security and confidentiality obligations:
- Vercel — hosting. Order notifications pass through Vercel's network in transit.
- Supabase — the database that holds the encrypted access token and the install record.
All data is transmitted over TLS.
How long we keep it
The encrypted access token is kept until you uninstall the app, at which point it is erased and delivery to your instance stops. If Shopify sends us a shop erasure request, the store's record is deleted from this app entirely. Privacy request records are retained as an audit trail of requests received and fulfilled.
Your customers' rights
If one of your customers asks for a copy of their data or asks to be erased, Shopify notifies us and we act on it within 30 days. Because this app stores no customer data, those requests are fulfilled in your own order-management instance.
Security
Access tokens are encrypted at rest. Every incoming request from Shopify is cryptographically verified before it is processed. Access to infrastructure is limited to the operator, and each merchant instance has its own role-based logins.
Contact
Questions, or a privacy request: mominmaqsood7@gmail.com