YunExpress Pickup

Legal

Privacy Policy

This policy explains what YunExpress Pickup processes when it is installed in a Shopify store, what it deliberately does not keep, and how deletion works.

Last updated: 25 August 2026

What the app stores

When the app is installed, it stores the shop domain, the Shopify access token needed to call the Admin API on the store's behalf, and the store's pickup configuration: selected countries, bound shipping options, search settings, buyer-facing text, and order field mappings.

The app also stores the subscription state Shopify reports for the store, so the correct plan can be shown in the admin interface.

What the app does not store

The pickup point a customer selects is written to the Shopify order — as an app-owned order metafield and as order attributes — and is read back from Shopify whenever it is needed. The app's own service does not keep a copy of order pickup point data.

Logs deliberately exclude full delivery addresses, postal codes, session tokens, secrets, request signatures and raw provider responses.

Buyer information

To find nearby pickup points, the app sends the destination country and postal code — and, when the customer uses the place search, the text they typed — to the pickup point and geocoding services it depends on. This is the minimum needed to return a list of nearby points and place them on a map.

On the Order status page, the app compares the signed-in customer's identity against the customer on the order before allowing a read or a change. That comparison is performed at request time and is not retained.

Shopify permissions

The app requests only the Shopify access scopes it uses: reading and writing orders to store and read the pickup point, reading customers to prove an order belongs to the signed-in buyer, reading shipping settings to list the delivery methods available for binding, reading checkout validations to report setup status, and reading locales, translations and markets so the buyer-facing text and the shipping option bindings still resolve in each published language.

Deletion and retention

Uninstalling marks the store as uninstalled and clears its session immediately. The stored configuration is kept for approximately 48 hours so that an accidental uninstall followed by a reinstall does not cost a merchant their settings.

When Shopify sends the shop redaction request that follows an uninstall, all data the app stores for that store is permanently deleted. Customer data requests and customer redaction requests from Shopify are handled through the same mandatory compliance webhooks.

Sharing

Merchant and buyer information is not sold. Information is shared only with the infrastructure, pickup point and mapping providers required to operate the app, or where a legal obligation applies.

Contact and changes

Privacy or data access questions can be sent to the support address below. This policy may be updated; continued use of the app or this website after an update means the revised policy applies.