Postbag privacy policy
Effective date: 4 September 2026
Postbag is a Shopify app made by Kettle Apps (“we”, “us”). It connects a merchant’s Shopify store to the merchant’s Royal Mail Click & Drop account. This policy explains what data the app handles and why.
Who this applies to
Merchants who install Postbag, and the customers whose orders those merchants ship. Merchants are the data controllers for their customers’ data; Kettle Apps acts as a processor on the merchant’s behalf.
What we collect and why
When a merchant installs Postbag, Shopify shares the store’s domain and an access token so the app can read orders and create fulfilments. The merchant also gives us their Click & Drop API key.
For each paid order, Shopify sends the app the order details needed to create a shipment: the recipient’s name, delivery address, email address and phone number, the items ordered with quantities, prices and weights, and any note the customer left. The app forwards this to Royal Mail’s Click & Drop service so the merchant can ship the order. The app does not use customer data for any other purpose.
What we store
- The store domain and Shopify access token.
- The merchant’s Click & Drop API key, encrypted at rest.
- Per order: the Shopify order number, the Click & Drop order number, sync status, the time sent, any error message, and the tracking number once dispatched.
- Recipient details are stored only while an order has failed to send, so it can be resent, and are deleted as soon as it succeeds.
- Merchant settings (which orders to send, default weight, package format).
We do not store payment details.
Where data is processed
The app runs on Fly.io servers in London, United Kingdom. Order data is sent to Royal Mail Group Ltd’s Click & Drop service under the merchant’s own Click & Drop account and Royal Mail’s terms.
How long we keep it
Order records stay while the app is installed so the sync log works. When a merchant uninstalls Postbag, the Click & Drop API key is deleted immediately and all remaining store data is deleted within 48 hours, when Shopify sends its data-erasure request. Customer data-erasure requests received through Shopify are actioned by removing any stored recipient details and error text for the affected orders.
Security
Data is transmitted over HTTPS. API keys are encrypted in the database. Access to the servers is limited to Kettle Apps.
Your rights
Customers should contact the merchant they bought from, who can request access to or deletion of their data through Shopify. Merchants can contact us at support@kettleapps.com for questions about the data the app holds.
Changes
We will update this page if the app’s data handling changes.
Contact
Kettle Apps, support@kettleapps.com