GDPR Compliance Statement
General Data Protection Regulation (GDPR) Compliance
1. Overview
Whaleal is committed to complying with the General Data Protection Regulation (GDPR) (EU) 2016/679. This statement outlines our compliance measures and your rights under GDPR.
Effective Date: June 15, 2026
2. Data Controller
For the purposes of GDPR, the data controller is Whaleal. We determine the purposes and means of processing personal data collected through the Whaleal Cart application.
Contact: hi.whaleal@gmail.com
3. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract Performance: Processing necessary to provide abandoned cart recovery services
- Legitimate Interests: Analytics, service improvement, and fraud prevention
- Consent: Where explicitly obtained for specific purposes
- Legal Obligation: Compliance with applicable laws and regulations
4. Data Subject Rights
Under GDPR, you have the following rights:
4.1 Right to Access
You have the right to request access to your personal data and information about how we process it.
4.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
4.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances.
4.4 Right to Restriction of Processing
You have the right to request restriction of processing in certain circumstances.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
4.6 Right to Object
You have the right to object to processing based on legitimate interests.
To exercise these rights, contact us at hi.whaleal@gmail.com
5. Data Processing Activities
| Purpose | Data Types | Legal Basis |
|---|---|---|
| AI Cart Recovery | Email, Name, Cart Items | Contract Performance |
| Email Delivery | Email Address | Contract Performance |
| Analytics | Usage Data, Statistics | Legitimate Interests |
| Customer Support | Contact Information | Contract Performance |
6. International Data Transfers
Data may be transferred outside the European Economic Area (EEA). We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved contractual protections with subprocessors where applicable
- Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate protection
7. Data Minimization
We collect only data necessary for abandoned cart recovery: checkout and customer fields received from Shopify webhooks and Admin API (e.g. email, name, cart contents). We do not track general storefront visitors or use personal data for unrelated purposes.
8. Data Security Measures
We implement technical and organizational measures:
- Encryption in Transit: HTTPS/TLS for all App and API communication
- Encryption at Rest: Production data and backups stored on encrypted cloud infrastructure
- Access Controls: Shopify Session Token authentication; shop-level data isolation; no internal staff customer search UI
- Employee Access: Production systems accessible only to authorized personnel on a need-to-know basis
- Environment Separation: Separate development and production databases
- Automated Deletion: Customer records are deleted after the retention period (maximum 180 days) or upon uninstall / GDPR redact requests
9. Security Incident Response
We maintain procedures to detect, investigate, and respond to security incidents involving personal data, including merchant notification when required by GDPR Articles 33–34, remediation, and cooperation with Shopify and supervisory authorities.
10. Data Retention Periods
Personal data is kept no longer than necessary. The maximum retention period for customer checkout and email records is 180 days.
- Active Stores: Duration of App installation, subject to the 180-day maximum
- Customer Checkout & Email Data: Up to 180 days, then deleted
- Uninstalled App: Deleted via
shop/redact(within 30 days maximum, per Shopify) - Support Communications: Up to 2 years for record-keeping
11. Third-Party Processors
We engage the following third-party processors:
- Email Delivery: Resend (email service provider)
- Hosting: Shopify (platform infrastructure)
- Analytics: Internal analytics tools
All processors are bound by data processing agreements complying with GDPR Article 28.
12. Automated Decision-Making
Whaleal does not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
13. Children's Data
The App is not intended for children under 16 (or 13 in certain jurisdictions). We do not knowingly collect personal data from children.
14. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing violates GDPR. Contact your local data protection authority.
15. Contact Information
For GDPR-related inquiries:
- Email: hi.whaleal@gmail.com
- Response Time: Within 30 days
16. Shopify Data Protection Commitments
For Shopify Partner and merchant review, Whaleal Cart confirms compliance with standard data protection requirements:
- Minimum necessary processing: Yes — Section 7
- Merchant transparency: Yes — Sections 2, 3, 5, and 10
- Purpose limitation: Yes — cart recovery and related analytics only
- Merchant agreement: Yes — Privacy Policy + Terms of Service on install
- Customer consent & opt-out: Yes — unsubscribe links and GDPR webhooks
- Data sale / automated legal decisions: Not applicable
- Retention (max 180 days): Yes — Section 10
- Encryption, backups, test/prod separation, DLP: Yes — Section 8
- Employee access limits & strong passwords: Yes — Section 8
- Access logging & incident response: Yes — Sections 8 and 9
Full mapping table: Privacy Policy Section 15
17. Updates to This Statement
We may update this GDPR Compliance Statement periodically. Check this page for the latest version.