Privacy Policy – Enigami: Price on Request app for Shopify

Last updated: 5 October 2026

This policy explains what personal data the Enigami: Price on Request app (the "App") processes, why, and how it is protected. The App is operated by Enigami.tech, Sonnenhof 1, 8808 Pfäffikon SZ, Switzerland (the "Operator", "we"). It applies to merchants who install the App in their Shopify store and to their customers whose data the App processes on the merchant's behalf.

1. Roles

For customer data, the merchant operating the store is the controller and we are the processor, acting on the merchant's instructions under the Shopify terms and our Data Processing Agreement. For the merchant's own account data (staff user ids, store contact e-mail) we are the controller.

2. What the App does

The App lets customers of a store ask for a quotation on products sold without a public price, lets the merchant price the request and send a quote, and lets the customer accept the quote and pay through the store's checkout.

3. Data we process and why

DataSourcePurpose
Customer name, e-mail addressEntered by the customer in the request form, or taken from the Shopify customer accountIdentify the request, send the request copy and the quote, link the quote to the customer's checkout
Phone number and addressShopify customer record (read only when the quote becomes a draft order)Pre-fill the checkout and delivery of the quoted order; not stored by the App
Requested products, configuration, quantities, notes and messagesEntered by the customerPrepare and send the quote, answer questions
Quote prices, validity, remarks, status historyEntered by the merchantProvide the quote and the checkout
Order number of a paid quoteShopify order webhookMark the quote as paid
IP address of storefront requestsRequest headersRate limiting and abuse prevention; optional Cloudflare Turnstile check; kept only in the access log
Store staff user id, action, time, IP addressShopify admin sessionAccess log of who viewed or changed customer data (security and accountability)
Store name, contact e-mail, settingsShopify Admin API, merchant inputOperate the App for the store, send office notifications

The App never stores payment data. Payments are handled entirely by Shopify checkout.

4. Legal basis

Processing is necessary to perform the service the customer asked for (a quotation and the possibility to order), and, for abuse prevention and access logging, our and the merchant's legitimate interest in a secure service. Where consent is required by law, the merchant obtains it in the store. The App never uses customer data for marketing and never sells it.

5. Where data is processed and who receives it

RecipientPurposeLocation
Supabase, Inc.Database of the App: requests, quotes, messages, settings and the access log (encrypted at rest, encrypted backups)Switzerland (Zurich region)
Vercel, Inc.Running the App: handles the requests from the store and the merchant's admin; keeps short-lived technical logsGermany (Frankfurt region)
Shopify International Ltd.Store platform: customer records, draft orders, orders, checkoutPer Shopify's data processing terms
Resend, Inc.Sending transactional e-mails (request copy, quote ready, office notifications)EU region (eu-west-1)
Cloudflare, Inc.Optional bot protection (Turnstile) when the merchant enables itGlobal edge network

All connections use HTTPS. Data is stored in Switzerland and processed in the EU; it is not transferred elsewhere except to the providers listed above under appropriate safeguards (standard contractual clauses or an adequacy decision).

6. Retention

Requests, quotes, messages and the related access log entries are deleted automatically after a period set by the merchant (default: 12 months after the last activity on the request). The merchant can delete expired data at any time from the App's settings. When a merchant uninstalls the App, all data held for the store is deleted 48 hours later on Shopify's shop/redact notice. When Shopify forwards a customer's erasure request (customers/redact), the customer's requests and quotes are deleted immediately.

7. Security

8. Your rights

Customers can exercise their rights of access, rectification, erasure, restriction, portability and objection with the merchant operating the store; we support the merchant in answering. Customers can also see, edit and cancel their own requests from the quote page the App links in its e-mails. Merchants and customers can contact us at privacy@enigami.tech. Residents of Switzerland may contact the Federal Data Protection and Information Commissioner; residents of the EU/EEA their national supervisory authority.

9. Changes

We may update this policy as the App evolves. The current version is always available at this address; material changes are announced to merchants through the App.

10. Contact

Enigami.tech
Sonnenhof 1
8808 Pfäffikon SZ
Switzerland
privacy@enigami.tech