Layne privacy policy
Last updated: September 22, 2026
This policy explains how Trafik Plus LTD handles personal data through Layne: France & EU Withdrawal ("Layne" or "the App"), a Shopify app that lets merchants receive, verify and manage right-of-withdrawal requests from their customers.
1. Who we are
Layne is developed and operated by Trafik Plus LTD, a company registered in England and Wales under company number 15198434, with registered office at 24-26 Arcadia Avenue, Fin009, London, N3 2JU, England. Privacy contact: hello@trafik.plus.
2. Our role
- Customer data (processor): when a merchant's customer submits a withdrawal request, the merchant is the data controller and Trafik Plus processes that data only on the merchant's behalf and instructions, under the Data Processing Agreement merchants accept in the App.
- Merchant data (controller): for the details of merchants who install the App, used to run, support and improve it, Trafik Plus is the data controller.
3. Data we process
a) Merchants' customers
- Name and email address entered in the withdrawal form
- Order data: order number, Shopify order ID, confirmation number and order date, used to verify the request when order lookup is enabled
- Items selected for withdrawal: product title, variant and quantity
- Request metadata: reference, status, submission and processing timestamps, and the Shopify customer ID when the customer is logged in
The App does not ask for payment details or special categories of personal data.
b) Merchants
- Shop domain, shop name, shop owner name, contact email and admin language, obtained from Shopify when the App is installed and opened
- Company details and the date the Data Processing Agreement was accepted, entered during onboarding
- App settings: notification recipients, branding, translations and retention choices
- Product usage analytics inside the App admin
4. How we use it
- Receive withdrawal requests and show them to the merchant in the App admin
- Verify the order number and email against Shopify order data, when enabled by the merchant
- Send confirmation emails to customers and notification emails to merchants
- Add order tags or create Shopify return requests, when the merchant turns these on
- Provide support, keep the App secure and understand how the App is used so we can improve it
We process merchant data to perform our contract with the merchant and for our legitimate interest in operating and improving the App. We never sell personal data or use customers' data for our own marketing.
5. Shopify access
The App requests only the Shopify permissions it needs: reading orders (to verify withdrawal requests), reading locales and themes (to display the form in the storefront's language and theme), and writing app proxy, content, products and metaobjects (to serve the withdrawal form and store its settings).
6. Subprocessors
- Shopify Inc. — platform, authentication, order lookup and write-back actions
- Fly.io — application hosting and database (Amsterdam, EU)
- Amazon Web Services (SES) — transactional email delivery
- PostHog — product analytics for the App admin, hosted in the EU; merchant data only
Where a provider processes data outside the UK or EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses.
7. Retention and deletion
- Merchants choose how long withdrawal records are kept: automatic deletion after 3, 6, 12 or 24 months, or until deleted manually.
- When Shopify sends a customer redaction request, we delete that customer's withdrawal records for the shop.
- When the App is uninstalled, its access to the store ends immediately, and all data we hold for that shop is deleted when Shopify sends its shop redaction request, 48 hours after uninstall.
8. Your rights
Under the GDPR and UK GDPR, you may access, correct, erase, restrict, port or object to the processing of your personal data. If you submitted a withdrawal request to a store, please contact that store first: it controls your data, and we will help it respond. Merchants, or customers whose request a store cannot answer, can write to hello@trafik.plus; we reply within one month. You may also complain to your local supervisory authority, such as the CNIL in France or the ICO in the UK.
9. Security
Data travels over HTTPS/TLS, records are scoped to each shop, merchant access goes through Shopify admin authentication, and only authorised personnel bound by confidentiality can access production data.
10. Changes and contact
We may update this policy; the date above shows the latest revision. Questions: hello@trafik.plus, Trafik Plus LTD, 24-26 Arcadia Avenue, Fin009, London, N3 2JU, England.