Privacy Policy - Wolt
Privacy Policy — Wolt Sync
Last updated: June 30, 2026
This Privacy Policy describes how Wolt Sync ("the App", "we", "us") collects, uses, and stores information when you install and use the App on your Shopify store.
1. Information We Collect
The App collects and stores the following data:
-
Shopify store domain — to identify your store and associate settings.
-
Shopify access token — to communicate with your store's Shopify Admin API on your behalf.
-
Wolt API credentials — venue ID, API base URL, authentication credentials you provide — stored to enable inventory sync and order routing.
-
Inventory sync records — SKU, inventory level, and timestamp — used to track synchronisation history.
-
Order data from Wolt — when an order is received from Wolt, the following customer information may be stored temporarily as part of the raw order payload:
- Customer name
- Customer phone number
- Delivery address
This data is stored only to process and create the corresponding Shopify order, and is not used for any other purpose.
2. How We Use Your Information
- To create Shopify orders from incoming Wolt order notifications.
- To synchronise product inventory between Shopify and your Wolt venue(s).
- To display activity logs within the App dashboard.
- We do not sell, rent, or share your data with third parties other than Shopify and Wolt as required to provide the service.
3. Data Retention
- Order records — retained for up to 90 days, then deleted automatically.
- Inventory sync records — last 500 records per store are retained; older records are purged.
- API credentials and store settings — retained for as long as the App is installed. Deleted upon uninstall.
4. Data Storage & Security
All data is stored in a MongoDB database hosted on MongoDB Atlas (cloud), protected by access controls and encryption at rest. Access tokens are stored encrypted and are never logged. The App is served over HTTPS (TLS) at all times.
5. Third-Party Services
- Shopify — the App uses the Shopify Admin API under the merchant's authorisation. See Shopify's Privacy Policy.
- Wolt — order and inventory data is sent to Wolt's POS integration API. See Wolt's Privacy Policy.
- MongoDB Atlas — cloud database provider. See MongoDB's Privacy Policy.
6. Merchant Rights
As a merchant, you may request deletion of all data associated with your store at any time by contacting us at [email protected]. Uninstalling the App will also initiate data removal in accordance with Shopify's GDPR webhook requirements.
7. GDPR & Data Subject Rights
The App processes customer data (name, phone, address) solely on behalf of the merchant (as a data processor). Merchants are the data controllers and are responsible for their customers' data under applicable privacy laws. We respond to Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) to fulfil data erasure and access requests.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted at this URL with a revised "Last updated" date. Continued use of the App after changes constitutes acceptance of the new policy.
9. Contact
For privacy-related questions or data deletion requests, contact us at: [email protected]
