ApproveLane Privacy Policy
Last updated: 13 September 2026
This Privacy Policy explains how REXCODE DIGITAL LTD (“RexCode”, “we”, “us”, or “our”) processes information in connection with the ApproveLane Shopify application (“ApproveLane” or the “App”). ApproveLane helps Shopify merchants manage artwork, design, customisation, and production-proof approval workflows with their customers. ApproveLane is a product provided by REXCODE DIGITAL LTD, not a separate legal entity.
1. Who we are
REXCODE DIGITAL LTD
Trading as: RexCode
Company Number: 17088152
Registered in: England and Wales
Registered Office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
ICO Registration Reference: ZC205511
Email: support@rexcode.co.uk
Website: www.rexcode.co.uk
2. Our role
For personal data relating to a merchant’s customers that we process through ApproveLane on the merchant’s instructions, the merchant will generally act as controller and RexCode will generally act as processor or service provider. RexCode may act as an independent controller for information relating to merchants, authorised users, support enquiries, account security, legal compliance, and RexCode’s own business operations. The precise roles may depend on the circumstances and applicable law.
3. Information processed by ApproveLane
Merchant and store information
- Shopify store identifier and domain;
- merchant or authorised-user installation and session information;
- application configuration information; and
- support communications.
Order and customer information
Only where required for the proof workflow, the App accesses and stores the Shopify order identifier and order number, order date, customer identifier, customer name, customer email address, ordered-product title, variant title, and quantity. The App uses this data to identify the order, display it to the merchant, associate it with proof versions, and deliver the customer’s approval link. It does not request addresses, telephone numbers, payment-card details, or access to orders older than Shopify’s standard read_orders scope permits.
Proof workflow information
- proof, artwork, image, or document files uploaded by a merchant;
- proof version number, original filename, file type, size, integrity hash, and optional merchant message;
- customer comments, optional reviewer name, approval status, and workflow timestamps; and
- audit records for creation, upload, sending, viewing, revision, approval, cancellation, and privacy actions.
Technical and security information
The App processes limited authentication, installation, request, error, rate-limit, webhook-delivery, and security information needed to operate and protect the service. Application logging is designed to redact fields commonly containing passwords, tokens, cookies, keys, and secrets.
4. Why we process information
Information is processed to provide and secure the proof workflow; associate proofs with Shopify orders; generate controlled approval links; let customers approve proofs or request changes; maintain version and audit history; notify merchants and customers; troubleshoot the App; provide support; comply with applicable law and Shopify requirements; and respond to privacy requests.
RexCode does not use a merchant’s customer information for unrelated marketing and does not sell personal data. ApproveLane does not make solely automated decisions about individuals that produce legal or similarly significant effects.
5. Data minimisation and Shopify access
The App requests the read_orders and read_customers Shopify scopes and the protected customer fields “name” and “email”. Customer access is limited in application code to the customer associated with a selected recent order and is used only for the order-linked approval workflow described above. Shopify independently processes data under its own terms and privacy practices. Merchants remain responsible for their Shopify store, their customer relationship, and any privacy information or lawful basis required for their own processing.
6. Subprocessors
RexCode currently uses Shopify for the commerce platform and authorised API data; Supabase for managed PostgreSQL and private object storage; Vercel for application hosting, scheduled retention execution, deployment, and platform logs; GitHub for private source-code hosting, deployment integration, and encrypted backup artefacts; and Resend for transactional proof-notification email delivery. Resend receives the recipient email address, shop name, order number, proof version number, and secure approval link needed to deliver the notification.
These providers receive only the access reasonably necessary for their role. RexCode may replace or add providers as the service changes and will consider appropriate contractual, privacy, security, and transfer safeguards.
7. Proof files and secure links
Proof files are stored in a private Supabase Storage bucket, not a publicly browsable directory. Uploads are restricted by file size and detected content type. Customer links contain a cryptographically random token; the application database stores a peppered hash rather than the raw token. Links are version-bound, expire, and are revoked when replaced, cancelled, approved, or made obsolete. File access uses short-lived signed URLs.
8. Security
Current technical measures include HTTPS/TLS, managed encryption at rest, private file storage, restricted server-side credentials, authenticated Shopify sessions, tenant-scoped database queries, row-level security and restricted Data API roles, integrity constraints, immutable application audit events, append-only protected-data access logs, upload validation, short-lived signed file URLs, rate limiting, encrypted backups with restoration checks, secret-aware logging, and authenticated, deduplicated Shopify webhooks. No online service can guarantee absolute security.
9. Retention and deletion
Proof-workflow personal data and proof files are automatically deleted or anonymised after 12 months without workflow activity. The scheduled process removes each related object from private Storage, revokes and deletes approval links, removes comments and notification records, and clears customer names, email addresses, Shopify customer identifiers, order details, filenames, merchant messages, reviewer names, and line-item snapshots. It retains only a non-personal workflow shell, file integrity metadata, status/timestamps, and immutable audit information needed for security, accountability, and dispute evidence. Each run records its cutoff, counts, completion state, and non-sensitive failure codes for audit.
Protected-customer-data access logs contain tenant, time, hashed actor identifier where available, action, non-sensitive resource identifier, route, request identifier, and outcome, but not names, email addresses, proof contents, raw links, tokens, or credentials. They are retained for 24 months and then automatically deleted. Shopify uninstall immediately disables the shop, removes application sessions, and revokes active approval links. Shopify customer-redaction and shop-redaction requests continue to remove affected proof files and anonymise or remove customer and order data without waiting for the general schedule.
On the current Supabase Free plan, RexCode does not rely on automatic Supabase production backups. A daily restricted workflow exports application database records and both proof-file buckets, encrypts the export with AES-256 before it is stored as a private GitHub Actions artefact, verifies checksums, and performs a restoration test in an isolated temporary PostgreSQL environment. Encrypted artefacts expire after 30 days. A deleted record may therefore remain in an encrypted backup for up to 30 days before automatic expiry. Point-in-time or zero-data-loss recovery is not promised.
10. Merchant and customer rights
Customers should normally contact the Shopify merchant from whom they ordered because that merchant generally determines the purpose of the processing. RexCode will assist merchants with valid requests where reasonably required. Where RexCode acts as controller, individuals may contact support@rexcode.co.uk. Depending on applicable law, rights may include access, correction, deletion, restriction, objection, portability, and the right to complain to a supervisory authority.
11. International transfers
RexCode and its providers may process data outside the United Kingdom or the individual’s country of residence. Where required, RexCode relies on an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, Standard Contractual Clauses, or another recognised transfer safeguard made available for the relevant processing.
12. Changes and contact
We may update this policy to reflect changes to ApproveLane, its infrastructure, applicable law, Shopify requirements, or our privacy practices. The current version is published at this URL.
Privacy questions may be sent to support@rexcode.co.uk or to REXCODE DIGITAL LTD at the registered office shown above.