Apollo by eBrands — Shopify Privacy Policy
Last updated: August 2026
1. Who we are
Apollo is the commerce operations platform eBrands Holdings Oy ("eBrands", "we", "us") runs for the brands it owns and for the brand partners it operates. This policy explains what Apollo by eBrands accesses from a connected Shopify store, why, who it reaches, how long we keep it, and how to contact us about it.
2. What we access
Under your authorization, Apollo reads the Shopify Admin API data needed to deliver the features your store is set up for:
- Orders — order IDs, line items, quantities, status, market, and fulfilment timestamps.
- Customers — the customer record attached to an order: name, email, phone where present, and shipping and billing address. Shopify includes these fields in the order data the app receives.
- Products and catalog — products, variants, SKUs, prices, product files, and inventory items.
- Inventory and locations — stock levels per location and per variant.
- Fulfilments, returns and shipping — fulfilment and fulfilment-order state, returns, and shipping methods.
- Financials and payouts — payout reports, fees, refunds, and settlement records.
Apollo also holds write permissions for products and product files, inventory, orders and order edits, and fulfilment orders. Authorised eBrands operators use them, for the brands eBrands owns or operates, to correct catalogue entries and product media, adjust stock, amend orders and line items, and progress fulfilment. We do not request write access to your customer records and we never modify them. We do not request access to orders older than 60 days.
Directly from you, we collect your store domain and the store profile Shopify returns when you install (name, currency, country, plan), the address you write to us from, and standard service logs. We collect nothing directly from your customers — every customer record we hold reaches us from Shopify, under the authorization granted by the merchant operating the store.
3. Why we process it
- To operate the Apollo platform: order, inventory, catalogue and settlement reporting for the store, and order lookups for your own team.
- For a store eBrands has activated as one of the brands it owns or operates: to create and update the corresponding order in the enterprise resource planning and fulfilment systems eBrands runs centrally for those brands, so the order can be picked, shipped, invoiced and booked. The push carries only the fields needed to fulfil and account for the order — line items, quantities, shipping address, customer identifier and order totals. The flow is one-directional: Apollo writes to that system and never reads back from it.
- To meet our own legal obligations, in particular VAT and statutory accounting.
- To operate and secure the service.
- For the brands eBrands itself operates, to allocate advertising spend across products using order-level attribution data. That processing uses no name, email, address or phone number, and produces aggregate allocations rather than profiles of individual buyers.
Event types Apollo does not use are discarded on receipt.
4. Activation
Installing the connector links your store to Apollo. Event data is processed only once eBrands has activated the store as one of the brands it owns or operates, which is a deliberate commercial step agreed with eBrands. Until then, order, catalogue and inventory events are not read, nothing is written to Apollo's reporting store, and the events expire unread in our intake queue. Nothing from your store reaches eBrands' fulfilment and accounting systems.
5. Our role
For a store operated by a brand partner, that partner is the controller of its customers' personal data and eBrands acts as its processor, on that partner's instructions, under the data processing agreement referenced in section 13. For a store that eBrands itself owns and operates, eBrands is the controller. Where we use order data to meet our own legal obligations — VAT and statutory accounting — we act as controller for that use. We are also the controller of the account and contact data of the merchant staff who administer the connection.
6. What we do not do
We do not, and will not:
- Use the Shopify data we receive through this app to market to your customers.
- Share or sell one merchant's data, or insights derived from it, to another merchant.
- Share Shopify data with advertising networks or unrelated third parties.
- Use it for automated decision-making or profiling that produces legal effects for an individual.
7. Security
We apply technical and organisational measures appropriate to the risk.
- In transit: Shopify data is transmitted using TLS 1.2 or higher.
- At rest: personal data is encrypted using AES-256; other Shopify data is held on encrypted volumes, and backups are encrypted.
- Credentials: access credentials are held in a dedicated secret store, separate from business data, and are not written into application logs.
- Access control: access to systems handling Shopify data is granted on a least-privilege basis to individually named accounts and scoped service identities, requires multi-factor authentication on internal dashboards, is reviewed periodically, and is withdrawn when a person leaves or changes role.
- Separation: each merchant's Shopify data is used only to provide the service to that merchant. We do not expose one merchant's data to another, and access to stored credentials is scoped per store.
- Incidents: we maintain a documented security incident response policy. If we confirm a personal-data breach affecting Shopify data, we notify the affected merchant without undue delay after confirming it, with the information available at the time, and supplement it as more becomes known. Where we are the controller, we notify the competent supervisory authority as required by law. We also notify Shopify as required by our agreement with Shopify.
8. Where data is processed
eBrands Holdings Oy is established in Finland, in the European Union. Shopify-derived data is processed primarily inside the EEA. Some of the providers we rely on are established outside the EEA, or may access data from outside it for support and administration. Where that involves a transfer out of the EEA, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Details of the mechanism relied on, and a copy of the relevant clauses, are available on request from apollo@ebrandsglobal.com.
9. Sub-processors
Apollo runs on third-party cloud infrastructure located in the European Union. Shopify-derived data may also be handled by the business systems and service providers we operate on — such as our enterprise resource planning, hosting, logistics, and operational support services. You authorise us to engage these sub-processors. We review the sub-processors handling Shopify data at least annually and require equivalent protections where we contract with them directly. A current and complete list of sub-processors is available on request from apollo@ebrandsglobal.com, and we inform you before adding or replacing a sub-processor that handles your Shopify data, so that you can object.
10. Retention
- Where eBrands has not activated your store: nothing is retained. Events are not read, nothing is written to our reporting store, and unread events expire in our intake queue.
- Customer personal data: kept only for as long as it is needed for the purpose it was received for — fulfilling, supporting and accounting for the order — and then deleted or irreversibly de-identified, except where a longer period is required by tax, accounting or other law. Under Finnish accounting law, records that support our own bookkeeping are retained for the statutory period.
- Other Shopify data (orders, catalogue, inventory, settlement records): retained as long as necessary to operate the platform and to meet our legal obligations.
- Compliance-request records: we keep a record of each request and its outcome for as long as needed to evidence that we handled it. The record holds request metadata only — topic, store, timestamp — never the customer data itself.
11. Uninstall and deletion
You can end Apollo's access at any time from your Shopify admin → Apps → Apollo.
On uninstall, or on written request to apollo@ebrandsglobal.com, we stop accessing your store's Shopify data and destroy the stored access credential for it, including every earlier version of it, so nothing further can be read.
Apollo honours Shopify's mandatory compliance webhooks — customers/data_request, customers/redact and shop/redact. Each request is authenticated and recorded, with its outcome, in an append-only audit trail. Where eBrands has not activated your store, there is no retained data in scope and we confirm that. Where eBrands has activated your store, we complete the action each request requires within 30 days, and we delete or de-identify the Shopify data we hold for the store within 30 days of uninstall — except where tax, accounting or other law requires us to retain it. Backup copies are purged on their normal rotation schedule.
Where an order has already been passed into eBrands' fulfilment and accounting systems, the resulting order and accounting records are retained for the period required by tax and bookkeeping law and are not erased by an uninstall or a redaction request. We restrict access to those records and delete or de-identify them at the end of that period.
12. Your rights
Where we act as a controller, you can ask us for access to your personal data and for its rectification, erasure or portability, ask us to restrict our processing of it, and object to processing we carry out on the basis of our legitimate interests. Write to apollo@ebrandsglobal.com. We answer within one month, and we tell you if we need longer, as the GDPR allows.
If you are a customer of a merchant that uses Apollo, that merchant is the controller of your data — contact the store first, and we assist them in answering you. Where eBrands operates the store itself, write to us and we answer you directly.
You can also lodge a complaint with a data protection supervisory authority: in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi), or the authority in the country where you live.
13. Data processing terms
Where we process your customers' personal data on your behalf, we do so as your processor under our data processing agreement, which applies from the point you install Apollo. If your organisation requires its own form of agreement, or a countersigned copy, contact apollo@ebrandsglobal.com.
14. Changes
We update this policy when our processing changes. The current version is always at this address, and the date at the top tells you when it last changed.
15. Contact
eBrands Holdings Oy, Helsinki, Finland. Privacy contact: apollo@ebrandsglobal.com. Website: ebrands.com.