Last updated: 16 June 2026
Introduction
EU Withdrawal Cancel Button ("the App") is operated by Undercover Otter, a sole proprietorship registered in the Netherlands and trading under the name Frontend Familiar.
This Privacy Policy explains how we collect, use, store, and protect information when merchants install and use the App and when customers submit withdrawal requests through stores that use the App.
The App is designed to help Shopify merchants receive, validate, manage, and process withdrawal and cancellation requests submitted by customers.
By installing or using the App, merchants agree to the practices described in this Privacy Policy.
Data Controller
The data controller for the App is:
Undercover Otter
Trading as Frontend Familiar
The Netherlands
Email: support@frontendfamiliar.com
Information We Collect
Merchant Information
When a merchant installs or uses the App, we may collect:
- Shopify store domain
- Shopify shop ID
- Store name
- Merchant contact information made available by Shopify
- App configuration settings
- Technical and diagnostic information required to operate the App
Customer Information
When a customer submits a withdrawal request through a merchant's storefront, the App may collect:
- Customer name
- Customer email address
- Order number
- Information entered into the withdrawal request form
- Additional information voluntarily provided by the customer
Order Validation Information
To validate withdrawal requests, the App may access limited Shopify order information, including:
- Shopify order identifiers
- Order number
- Customer information associated with the order
- Order status information
- Information required to determine whether the submitted request matches an existing Shopify order
How We Use Information
We process information solely to provide the App's functionality.
This includes:
- Receiving withdrawal requests
- Validating requests against Shopify orders
- Storing withdrawal request records
- Sending confirmation emails to customers
- Sending notification emails to merchants
- Displaying requests in the merchant dashboard
- Providing support and troubleshooting
- Maintaining service security
- Preventing abuse and fraud
- Complying with legal obligations
We do not sell personal information.
We do not use customer information for advertising purposes.
Shopify Data
The App uses Shopify APIs to access only the information required to provide its functionality.
The App accesses Shopify data exclusively for the purposes described in this Privacy Policy and in accordance with Shopify's API Terms and Partner Program requirements.
Third-Party Service Providers
We use trusted service providers to operate the App.
Shopify
Shopify provides the e-commerce platform, authentication services, and APIs used by the App.
Railway
Application infrastructure is hosted using Railway.
PostgreSQL
Application and withdrawal request records are stored in PostgreSQL databases.
Resend
Customer confirmation emails and merchant notification emails may be delivered through Resend.
These providers process information only as necessary to provide their services.
Data Sharing
We do not sell, rent, or trade personal information.
Information is shared only:
- With service providers necessary to operate the App
- When required by law
- To respond to lawful requests from public authorities
- To protect the security, integrity, or legal rights of the App, merchants, customers, or third parties
International Transfers
Information may be processed in countries outside the country in which it was originally collected.
Where required, appropriate safeguards are implemented to protect personal information during international transfers.
Data Retention
Withdrawal request records and related information may be retained for as long as reasonably necessary to:
- Provide App functionality
- Maintain merchant records
- Respond to support requests
- Resolve disputes
- Enforce agreements
- Meet legal and regulatory obligations
Data may be deleted following app uninstallation, subject to operational, security, accounting, or legal requirements.
Security
We implement reasonable technical and organisational measures designed to protect information against:
- Unauthorised access
- Unauthorised disclosure
- Accidental loss
- Misuse
- Alteration
- Destruction
However, no method of electronic transmission or storage can be guaranteed to be completely secure.
GDPR Rights
Where applicable, individuals may have rights under the General Data Protection Regulation (GDPR), including the right to:
- Access personal information
- Correct inaccurate information
- Request deletion of personal information
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent where processing relies on consent
Requests may be submitted to:
support@frontendfamiliar.com
Merchants remain responsible for responding to customer privacy requests relating to information under their control.
Children's Privacy
The App is not intended for children.
We do not knowingly collect personal information from children.
Merchant Responsibilities
Merchants are responsible for:
- Providing legally required privacy notices to their customers
- Determining their legal obligations regarding withdrawal rights
- Ensuring their use of the App complies with applicable laws
- Responding to customer privacy requests where required
The App is a software tool and does not provide legal advice.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Changes become effective when the updated Privacy Policy is published.
The "Last updated" date at the top of this document indicates the most recent revision.
Contact
Questions regarding this Privacy Policy may be directed to:
Undercover Otter
Trading as Frontend Familiar
support@frontendfamiliar.com