Privacy Policy
Last updated: July 28, 2026
1. Who we are
BoxProof ("we", "us") provides a technical aid for drop-off proof (QR codes, photos, GPS, APIs). We are not a carrier and are not responsible for performing deliveries or for the accuracy of addresses provided by users, merchants, or partners.
This policy explains how we collect and use personal data when you use boxproof.fr, our APIs, and related apps (including the Shopify app).
2. Data we collect
- Account: email, name, profile details, plan.
- QR / drop-off spot: labels, address, reference photos, optional coordinates.
- Shipments & proof: tracking numbers, carriers, recipient email, delivery photos, GPS, notes, timestamps.
- Merchants / partners: shop domain, platform identifiers, webhook URLs, usage metrics.
- Technical: IP (sometimes hashed), logs, essential cookies.
- Payments: handled by Stripe; we do not store full card numbers.
3. Purposes
- Provide the Service (accounts, QR, drop-off proof, notifications).
- Connect merchants (Shopify, partner APIs, webhooks).
- Security, fraud prevention, service improvement.
- Billing when enabled; legal obligations.
4. Legal bases (GDPR)
Contract performance; legitimate interests (security, improvement); legal obligation; consent where required (e.g. certain cookies or marketing).
5. Sharing
We do not sell personal data. We may share data with:
- Processors: hosting, email, Stripe.
- Connected partners: only data needed for the APIs/webhooks they configured (e.g. proof payload).
- Authorities: when required by law.
6. Shopify
If you install the BoxProof Shopify app, we process shop and order-related data needed to offer checkout QR linking and merchant features. Merchants remain responsible for their storefront and for how they instruct carriers. See also our Terms of Service and the in-app notice: BoxProof is a proof aid, not a carrier.
7. Retention
Data is kept as long as needed to provide the Service and meet legal obligations. Drop-off proofs may be retained while the related account or dispute justification remains, then deleted or anonymised.
8. Security
HTTPS, password hashing, access controls, and other organisational measures appropriate to the Service.
9. Your rights
Access, rectification, erasure, portability, objection, restriction:
10. Cookies
Essential cookies for session and authentication. No third-party advertising cookies without consent.