ShipkinEspañol

Privacy policy

Last updated: September 27, 2026

1. Who we are

Shipkin is an app for Shopify stores that creates shipments and labels with the store's own contracts with its carriers (Correos, the Spanish postal service, MRW and Correos Express), marks orders as fulfilled with their tracking number and keeps their delivery status up to date.

Owner: [pending], tax ID [pending], [pending]. Contact: [pending].

2. Our role

3. What data we process and why

Buyer data. When the store creates a shipment or a return, Shipkin reads the recipient's name, company, address, phone number and email from the Shopify order and sends them to the carrier chosen for that shipment (Correos, MRW or Correos Express) to register it and generate the label. We do not store them. For each order we only keep its number, the carrier, the shipment status, the tracking codes and, if the carrier rejects the shipment, its error message, which may quote the rejected value (for example, the postal code). Also the destination zone (same province, mainland, Balearic Islands…) and the shipping amounts (what it cost with the store's rates and what the buyer paid), excluding VAT. Before creating the label, Shipkin checks the address (that the postal code matches the province and that it has a number and a phone) without storing it. If the shipment crosses customs (between mainland Spain or the Balearic Islands and the Canary Islands, Ceuta or Melilla), Shipkin also reads the items in the order (description, quantity, weight and value) and sends them to Correos for the customs declaration (CN23), again without storing them.

Buyer notices. If the store turns it on in Settings and the shipment was created with customer notifications, when the carrier cannot deliver the parcel or leaves it at a pickup office, Shipkin emails the buyer on the store's behalf so they can collect it or arrange another delivery. To do so it reads the buyer's email and name from the Shopify order at that moment, without storing them. After a failed delivery attempt, the email asks the buyer whether they were at home; if they answer, Shipkin stores only that answer (yes or no) with the shipment, so the store can raise it with the carrier.

Store data. The store domain and the access Shopify grants to the app, the details of its carrier contracts and its access credentials (for Correos ID, MRW and Correos Express), stored encrypted, the sender address, its contract rates, the subscribed plan and the number of labels created each month. Also the email address we use to alert the store if a carrier rejects its credentials, stops responding or has stalled shipments: the one it enters in Settings or, if it enters none, the store's email in Shopify. These alerts can be turned off in Settings. If the store turns it on, each shipment has a public tracking page, at an address that is hard to guess, showing the store name and email, the order number, the status and the tracking code, without any buyer data. And the messages the store sends us from the app's help page, together with the latest logged failures of its carriers.

Technical log. Every call to the carriers (operation, order number or tracking code, result and duration), without buyer data, to support the store and monitor the reliability of the service.

We do not use the data for advertising, we do not build profiles and we do not sell it.

4. Legal basis

5. Who we share it with

We do not share the data with anyone else unless required by law.

6. How long we keep it

7. Security

All connections are encrypted (HTTPS), carrier credentials are stored encrypted and access to the data is limited to what is needed to provide the service. We meet Shopify's requirements for access to protected customer data.

8. Your rights

If you bought from a store that uses Shipkin, contact that store to exercise your rights: it is the controller of your data and we will help it respond. If you are a store, you can ask us for access, rectification, erasure, restriction or portability of your data, or object to its processing, by writing to [pending]. You can also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

9. Cookies

The app runs inside the Shopify admin and does not set analytics or advertising cookies.

10. Changes

If we change this policy, we will publish the new version here with its update date.