Koombiyo Delivery
Privacy PolicyTerms of Service
Legal

Privacy Policy

Last updated: March 20, 2026

Contents

1 Information we collect2 How we use your information3 Data sharing & disclosure4 Data retention5 GDPR & merchant rights6 Security7 Children's privacy8 Changes to this policy9 Contact us

1. Information we collect

When you install and use Koombiyo Delivery through the Shopify App Store, we collect the following information:

From your Shopify store

  • Store domain and shop name
  • OAuth access token (to call the Shopify Admin API on your behalf)
  • Order data: order number, customer name, delivery address, phone number, and order total (COD amount)
  • Shopify customer IDs (numeric identifiers only — not email addresses or payment details)

Information you provide directly

  • Your pickup address, phone number, and GPS coordinates (entered on the Profile page)
  • Your Koombiyo API key (entered on the API Configuration page)

Automatically collected

  • Delivery status updates pushed by Koombiyo's delivery system via webhooks
  • Shipment waybill numbers assigned by Koombiyo
We do not collect payment card details, Shopify Payments data, or any information unrelated to delivery management.

2. How we use your information

We use the information collected solely to provide the Koombiyo Delivery service:

  • Creating and managing shipments through Koombiyo's delivery network
  • Syncing order status updates between Koombiyo and your Shopify store
  • Scheduling pickup requests and tracking their status
  • Generating Proof of Delivery (POD) documents
  • Displaying your delivery dashboard and order history
  • Maintaining an audit log of status changes for your records

We do not use your data for advertising, marketing profiling, or any purpose other than operating this app.

3. Data sharing & disclosure

We share data only as necessary to provide the service:

Koombiyo Delivery (koombiyodelivery.lk)

Order details (customer name, address, phone, COD amount, description) are transmitted to Koombiyo's API to create shipments and request pickups. This is the core function of the app. Koombiyo's own privacy practices govern how they handle this data.

We do not share your data with:

  • Advertising or analytics networks
  • Data brokers or resellers
  • Any third party other than Koombiyo as described above

Legal requirements

We may disclose information if required by law, court order, or to protect the rights and safety of our users.

4. Data retention

We retain your data for as long as your store has the app installed. Specifically:

  • Session tokens are deleted when you uninstall the app
  • Order records are retained for 12 months after the last status update, then purged
  • Audit logs are retained for 6 months
  • Profile and API key are deleted when you uninstall the app or request deletion

When you uninstall the app, we receive a Shopify app/uninstalled webhook and immediately delete all session data and mark your installation as inactive.

5. GDPR & merchant rights

We comply with Shopify's GDPR webhook requirements. We respond to the following mandatory webhooks:

  • customers/data_request — we can provide a summary of any customer data we hold upon request
  • customers/redact — we anonymise customer PII (name, address, phone) for the specified customer ID
  • shop/redact — we delete all data associated with your shop within 30 days of uninstall

Your rights as a merchant

You may request access to, correction of, or deletion of any data we hold about your store at any time by contacting us at support@koombiyodelivery.lk. We will respond within 30 days.

6. Security

We take reasonable technical measures to protect your data:

  • All data is transmitted over HTTPS/TLS
  • Shopify API credentials are stored encrypted at rest
  • Koombiyo webhook endpoints are authenticated using your API key embedded in the URL — no unauthenticated access is permitted
  • Shopify webhook payloads are verified using HMAC signatures before processing

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data using industry-standard practices.

7. Children's privacy

This app is a business-to-business service intended for Shopify merchants. It is not directed at, nor does it knowingly collect data from, individuals under the age of 18.

8. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify merchants via the Shopify admin or email where required by law.

Continued use of the app after changes are posted constitutes your acceptance of the updated policy.

9. Contact us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

AppKoombiyo Delivery for Shopify
Emailsupport@koombiyodelivery.lk
Phone0117 886 786
Websitehttps://shopify.lkit.dev
Koombiyo Websitehttps://koombiyodelivery.lk/
← Back to app·Terms of Service·© 2026 Koombiyo Delivery