Last updated: 5 October 2026
This policy explains what personal data the Enigami: Price on Request app (the "App") processes, why, and how it is protected. The App is operated by Enigami.tech, Sonnenhof 1, 8808 Pfäffikon SZ, Switzerland (the "Operator", "we"). It applies to merchants who install the App in their Shopify store and to their customers whose data the App processes on the merchant's behalf.
For customer data, the merchant operating the store is the controller and we are the processor, acting on the merchant's instructions under the Shopify terms and our Data Processing Agreement. For the merchant's own account data (staff user ids, store contact e-mail) we are the controller.
The App lets customers of a store ask for a quotation on products sold without a public price, lets the merchant price the request and send a quote, and lets the customer accept the quote and pay through the store's checkout.
| Data | Source | Purpose |
|---|---|---|
| Customer name, e-mail address | Entered by the customer in the request form, or taken from the Shopify customer account | Identify the request, send the request copy and the quote, link the quote to the customer's checkout |
| Phone number and address | Shopify customer record (read only when the quote becomes a draft order) | Pre-fill the checkout and delivery of the quoted order; not stored by the App |
| Requested products, configuration, quantities, notes and messages | Entered by the customer | Prepare and send the quote, answer questions |
| Quote prices, validity, remarks, status history | Entered by the merchant | Provide the quote and the checkout |
| Order number of a paid quote | Shopify order webhook | Mark the quote as paid |
| IP address of storefront requests | Request headers | Rate limiting and abuse prevention; optional Cloudflare Turnstile check; kept only in the access log |
| Store staff user id, action, time, IP address | Shopify admin session | Access log of who viewed or changed customer data (security and accountability) |
| Store name, contact e-mail, settings | Shopify Admin API, merchant input | Operate the App for the store, send office notifications |
The App never stores payment data. Payments are handled entirely by Shopify checkout.
Processing is necessary to perform the service the customer asked for (a quotation and the possibility to order), and, for abuse prevention and access logging, our and the merchant's legitimate interest in a secure service. Where consent is required by law, the merchant obtains it in the store. The App never uses customer data for marketing and never sells it.
| Recipient | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database of the App: requests, quotes, messages, settings and the access log (encrypted at rest, encrypted backups) | Switzerland (Zurich region) |
| Vercel, Inc. | Running the App: handles the requests from the store and the merchant's admin; keeps short-lived technical logs | Germany (Frankfurt region) |
| Shopify International Ltd. | Store platform: customer records, draft orders, orders, checkout | Per Shopify's data processing terms |
| Resend, Inc. | Sending transactional e-mails (request copy, quote ready, office notifications) | EU region (eu-west-1) |
| Cloudflare, Inc. | Optional bot protection (Turnstile) when the merchant enables it | Global edge network |
All connections use HTTPS. Data is stored in Switzerland and processed in the EU; it is not transferred elsewhere except to the providers listed above under appropriate safeguards (standard contractual clauses or an adequacy decision).
Requests, quotes, messages and the related access log entries are deleted automatically after a period set by the merchant (default: 12 months after the last activity on the request). The merchant can delete expired data at any time from the App's settings. When a merchant uninstalls the App, all data held for the store is deleted 48 hours later on Shopify's shop/redact notice. When Shopify forwards a customer's erasure request (customers/redact), the customer's requests and quotes are deleted immediately.
Customers can exercise their rights of access, rectification, erasure, restriction, portability and objection with the merchant operating the store; we support the merchant in answering. Customers can also see, edit and cancel their own requests from the quote page the App links in its e-mails. Merchants and customers can contact us at privacy@enigami.tech. Residents of Switzerland may contact the Federal Data Protection and Information Commissioner; residents of the EU/EEA their national supervisory authority.
We may update this policy as the App evolves. The current version is always available at this address; material changes are announced to merchants through the App.
Enigami.tech
Sonnenhof 1
8808 Pfäffikon SZ
Switzerland
privacy@enigami.tech