1. Who We Are and Our Roles
This Privacy Policy explains how PunchRelay ("we", "us") handles personal data on our website (punchrelay.com) and in the PunchRelay app that Shopify merchants install. PunchRelay is operated from Hanoi, Vietnam. You can reach us about privacy at the email address at the end of this page.
We act in two roles under the EU and UK General Data Protection Regulation (GDPR):
- Controller for website visitors: when you visit punchrelay.com or send us an early access request, we decide how that data is used and are responsible for it.
- Processor for merchants: when a merchant uses the PunchRelay app, the merchant is the controller of the store, buyer and order data. We process it only to run the service for that merchant and on the merchant's instructions.
2. Website: Early Access Requests
When you submit the early access form, we store your work email address, your Shopify store URL and procurement system if you enter them, the page and language you used, the country derived from your connection, your browser's user agent string, and the time of the request.
We use this to reply to you and to prepare onboarding. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request before a contract). Your email address is needed to reply; every other field is optional. There is no legal obligation to provide any of it.
The request is stored in Cloudflare Workers KV and deleted automatically after 180 days. A notification with the same details is sent through Cloudflare Email Sending to our mailbox hello@punchrelay.com, which is hosted by Google (Gmail). Emails about your request stay in that mailbox while we are in contact with you; you can ask us to delete them at any time.
3. Website: Security, Basic Analytics and Your Cookie Choice
These run for every visitor and do not depend on your cookie choice:
- Security and bot protection: Cloudflare filters traffic to our site and uses Turnstile on the early access form. This involves your IP address and technical browser signals. Cloudflare may set strictly necessary security cookies such as __cf_bm or cf_clearance. Legal basis: our legitimate interest in keeping the site and form safe from abuse (Art. 6(1)(f) GDPR).
- Basic analytics: Cloudflare Web Analytics counts page views and measures load performance without cookies or other identifiers stored on your device. Legal basis: our legitimate interest in running a fast, working site (Art. 6(1)(f) GDPR).
- Your cookie choice: when you accept or reject optional analytics, your browser's local storage keeps an entry named pr-consent with your choice and the time you made it. It stays for six months, after which we ask again. It is strictly necessary to respect your choice and needs no consent.
4. Website: Optional Analytics (Only With Your Consent)
With your consent we use Google Analytics 4 to measure visits and completed early access requests, and Microsoft Clarity to record how pages are used (clicks, scrolling, page layout) and to build heatmaps. Neither loads until you select Accept in the cookie banner. If you select Reject or make no choice, no request is sent to Google or Microsoft for these tools and none of their cookies are set.
Once loaded, these tools receive your IP address and information about your browser and device. Google Analytics sets the cookies _ga and _ga_8RPMWNX6KK (up to 2 years). Clarity sets _clck (up to 1 year) and _clsk (1 day), and Microsoft may set its own cookies on clarity.ms and bing.com. Google advertising storage, ad user data and ad personalization stay switched off. When an early access request succeeds, Google Analytics receives only the selected procurement system and the page language, never your email address or store URL. Clarity masks text typed into form fields.
Google keeps Google Analytics event data for 2 months. Microsoft keeps Clarity recordings for 30 days and aggregated heatmap data for up to 13 months.
Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 5(3) of the ePrivacy Directive; in Germany § 25(1) TDDDG). You can withdraw consent at any time under Cookie settings at the bottom of every page. We then stop loading these tools and delete their cookies on our domain. Withdrawal does not affect processing that took place before it.
5. App: Data We Process for Merchants
To connect Shopify stores with buyer procurement systems, the PunchRelay app processes the following on the merchant's behalf:
- Merchant account: the Shopify store domain, Shopify access and refresh tokens (encrypted), and Shopify staff user IDs recorded in the admin activity log.
- Buyer connections: buyer identities (for example Ariba network IDs), shared secrets (encrypted), protocol settings and the Shopify B2B company, location and contact each connection is bound to.
- Punchout sessions: incoming cXML PunchOutSetupRequest and OCI login data, including buyer user details the procurement system sends, session cookies and return URLs.
- Cart transfers: item SKUs, descriptions, prices, currency, quantities and classification codes returned to the buyer as cXML PunchOutOrderMessage or OCI form data.
- Purchase orders: cXML OrderRequest documents with purchase order numbers, line items, buyer contact details and shipping and billing addresses, used to present the purchase order for merchant review and, when a merchant chooses, to create the Shopify order.
6. Security
We protect data with the following measures:
- Encryption in transit: connections to our website and gateway use HTTPS with TLS 1.2 or higher.
- Encryption of credentials: Shopify tokens and buyer shared secrets are encrypted with AES-256-GCM using an application key kept outside the database and its backups.
- Redacted logs: protocol logs keep raw cXML and OCI messages for troubleshooting, but shared secrets, passwords and authorization tokens are removed before storage.
- Encrypted backups: database backups are encrypted before they leave the server.
7. How Long We Keep Data
We keep data only as long as the purpose requires:
- Early access requests: 180 days (see section 2).
- Punchout sessions and protocol logs: 90 days.
- Purchase order contents, including addresses, and the order processing records built from them: 90 days. After that a deduplication record remains so the same PO is never turned into two Shopify orders. It holds the store domain, status, timestamps and two SHA-256 fingerprints (one of the store, buyer identity and purchase order number, one of the order's commercial fields). It does not contain the order contents and is kept for as long as the store may receive orders from that buyer, including after uninstallation.
- Support diagnostics: 30 days; the record of who looked them up: 1 year.
- Merchant account and buyer connection settings: until Shopify's shop/redact request (see section 9).
- Records of privacy requests (type, dates and status): kept to show that we handled them.
- Encrypted database backups: 30 days. Data deleted from the live system can remain in these backups until they expire.
- Server and proxy logs, which can contain IP addresses: rotated automatically and kept only for operations and security.
8. Service Providers and International Transfers
We use the providers listed below. Each may process personal data only on our instructions.
Cloudflare, Google and Microsoft are based in the USA. Transfers to them rely on the EU-US Data Privacy Framework, under which all three are certified, and additionally on the European Commission's Standard Contractual Clauses where the provider's data processing terms include them. PunchRelay is operated from Vietnam, and we access data from there to answer requests and run the service.
- Cloudflare, Inc. (USA, global network): DNS, CDN, firewall, Turnstile, Web Analytics, Workers and KV storage for early access requests, email sending, and R2 storage for encrypted backups in Cloudflare's EU jurisdiction.
- netcup GmbH (Vienna, Austria, EU): application servers and the primary database.
- Shopify Inc. (Canada and USA): the commerce platform, merchant sign-in and app billing.
- Google LLC (USA): the Gmail mailbox for hello@punchrelay.com and, only with your consent, Google Analytics 4.
- Microsoft Corporation (USA): Microsoft Clarity, only with your consent.
9. Shopify Privacy Requests
The app handles Shopify's mandatory privacy webhooks as follows:
- app/uninstalled: the store's Shopify access tokens are deleted and its buyer connections are disabled immediately.
- customers/data_request: we prepare an export of the data we hold about that customer and make it available to the merchant in the app within 30 days.
- customers/redact: we delete or anonymize that customer's personal data within 30 days.
- shop/redact: Shopify sends this about 48 hours after uninstallation. When it arrives we delete the store's remaining data, except the deduplication records and privacy request records described in section 7. Copies in encrypted backups expire within 30 days.
10. Your Rights
You have the right to access your personal data, to have it corrected or erased, to restrict its processing, to object to processing based on our legitimate interests, and to receive it in a portable format. Where processing is based on consent, you can withdraw it at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live or work or where you believe your rights were infringed.
If your data reached us through a merchant's store (for example as a buyer contact on a purchase order), please contact that merchant first. We support merchants in answering such requests. We do not make decisions about you based solely on automated processing.
11. Changes to This Policy
We update this policy when our processing changes. The date at the top shows the latest version. If a change affects optional analytics, we ask for your cookie choice again.
Contact
For privacy questions, requests to exercise your rights, or security reports, email: