Last updated May 29, 2026

CODProof Terms of Service And Data Processing Terms

These terms describe how merchants may use CODProof and how the app processes customer personal data on behalf of merchants.

Service

CODProof provides Shopify merchants with COD order screening, email and phone risk checks, OTP verification, merchant blocklists, delivery quote controls, COD order creation tools, and transactional setup/service notices.

Merchant Responsibilities

Data Processing

The merchant is the controller of customer personal data. CODProof processes customer personal data as a service provider or processor for the merchant, only to provide app functionality selected by the merchant.

Processed data is limited to the minimum needed for the app features: customer name, email, phone, shipping and billing address details, submitted COD order details, OTP verification state, merchant blocklist entries, risk-check metadata, Shopify order identifiers, and merchant shop metadata needed for app operation, transactional service notices, and privacy webhook handling.

Use Restrictions

Deletion And Redaction

Merchants can remove blocked contacts in the app. Shopify privacy redaction webhooks remove matching blocked email and phone entries from app storage. Shop redaction removes the installed shop record.

Security

The app verifies Shopify OAuth and webhook signatures, uses signed admin sessions and CSRF checks for app admin actions, logs personal-data access without raw customer values, minimizes webhook fields for fraudulent-cancellation auto-blocking, and encrypts app-owned Shopify storage at rest when the production DATA_ENCRYPTION_KEY secret is configured.