Legal & privacy

Privacy, explained clearly.

How AWB Cadabra collects, uses, shares and protects personal data when merchants manage deliveries through Shopify.

Last updated: July 29, 2026

1. Who we are

5M SOFTCON S.R.L. (CUI 49530204 / 05.02.2024), Mun. Curtea de Argeș, Str. Cuza Vodă, Nr. 22, Județ Argeș, Romania (“we”, “us”) operates AWB Cadabra, an application that connects Shopify stores to a courier service so merchants can quote shipping, create consignments and track deliveries.

Contact for privacy matters: contact@softcon.ro.

2. Our role: controller and processor

We act in two distinct capacities, and your rights differ accordingly:

  • As a controller for the merchant account data needed to provide and bill the app: store domain, contact email, plan and accounts granted access to our support back-office.
  • As a processor for shopper data in a merchant’s orders and shipments. The merchant is the controller and determines why it is processed; we process it only on their instructions to produce shipping quotes and consignments.

If you bought from a store using this app, please direct requests to that store first. We will assist the merchant in answering them.

3. What we process

CategoryDataPurpose
Merchant accountShopify store domain, contact email, country, currency, plan and access tokens issued to the app.Install and run the app, authenticate API calls and apply the correct subscription tier.
Order dataOrder number, date, totals, currency, payment and fulfilment status, line items, shopper name, email, phone and shipping address.Display orders and build the shipping consignment.
Shipment dataRecipient details, parcel weight and dimensions, cash-on-delivery amount, shipping service and selected pickup point.Create the consignment (AWB), print labels, request collection and follow tracking.
Diagnostic logsCourier system requests and responses, which may contain recipient details. Credentials and tokens are replaced with [masked].Investigate delivery and integration failures. Full logging is off by default and records only when enabled by a merchant.
Courier credentialsThe merchant’s courier API username and password, stored encrypted.Call courier systems on the merchant’s behalf.
Support accountsUsername and hashed password for back-office users.Control access to support tools.

We do not process special categories of personal data and do not use this data for advertising, profiling or automated decision-making.

4. Legal bases

  • Performance of a contract (GDPR Art. 6(1)(b)) — providing the app to the merchant.
  • Legitimate interests (Art. 6(1)(f)) — securing the service, diagnosing faults and preventing abuse.
  • Legal obligation (Art. 6(1)(c)) — retaining records where law requires it.

For shopper data, the merchant determines the legal basis; we rely on our data processing agreement with them.

5. Who we share data with

RecipientPurposeLocation
Courier configured by the merchantConsignments, labels, pickups and tracking.European Union
ShopifyPlatform hosting the app, source of order data and destination of fulfilment updates.Canada / EU, under Shopify’s terms
Hetzner Online GmbHServer hosting.Germany (EU)
CloudflareDNS, TLS and protection against abusive traffic.EU / global edge network
Google MapsWhen the merchant supplies a Maps API key, displays the pickup-point map in the shopper’s browser.Global

We do not sell personal data or share it with anyone for their own purposes.

6. International transfers

Our servers are in the European Union. Where a provider processes data outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses or an adequacy decision.

7. How long we keep data

  • Order and shipment records are retained while the app is installed so merchants can access shipping history.
  • Orders deleted in Shopify are removed from our cache at the next reconciliation. Existing consignment records are retained and marked because they remain real records the merchant may need.
  • Diagnostic logs are written only while a merchant has debug logging enabled.
  • On uninstall, we mark the store as uninstalled and stop processing. Following Shopify’s shop redaction request, the store’s data is erased.

8. Requests from Shopify and from you

Shopify sends us mandatory privacy webhooks: customer data requests, customer redaction requests and shop redaction requests. We record and act on each request.

Shopper requests are fulfilled with the merchant. We provide or erase the data we hold and confirm completion. Requests are handled by our team; please allow up to 30 days as permitted by GDPR Art. 12(3).

9. Your rights

Under the GDPR you may request access, correction, erasure, restriction, portability and object to processing based on legitimate interests. Write to contact@softcon.ro; we will respond within one month.

You may also complain to your national supervisory authority. In Romania this is the ANSPDCP (dataprotection.ro).

10. Security

Traffic is encrypted with TLS. Courier credentials are encrypted and passwords are hashed. Each merchant’s data is isolated. Back-office access is restricted to named accounts and protected against brute-force attempts. Credentials and tokens are masked in diagnostic entries.

11. Cookies

The merchant-facing app runs inside Shopify admin and uses short-lived session tokens rather than tracking cookies. Our back-office uses one strictly necessary session cookie. We set no advertising or analytics cookies.

12. Changes to this policy

If our processing changes, we will update this page and its date. Material changes affecting merchants will also be announced inside the app.

13. Contact

5M SOFTCON S.R.L.
Mun. Curtea de Argeș, Str. Cuza Vodă, Nr. 22, Județ Argeș, Romania
contact@softcon.ro