Privacy Policy

Fixel Pixel LLP ("DeploTeka", "we", "us")
Effective: 18 July 2026 · Version: 1.0
Controller: Fixel Pixel LLP, United Kingdom — registered office available on request
Privacy contact: privacy@deploteka.com


1. Who this policy covers

This policy applies to:

  • Operators — people at Shopify app vendors who create a DeploTeka account, connect a Shopify Partner organization, and use the cabinet; and
  • Prospects — visitors to deploteka.com who submit the "request early access" form; and
  • Site visitors — anyone whose visit generates standard server logs.

It does not apply to shoppers on merchant storefronts. If you are a shopper and a store you visited uses an app managed through DeploTeka, the store (merchant) is the controller of your data; please contact the store. We process that data only on the merchant side's instructions, under the Data Processing Agreement (/legal/dpa), and we will refer any request you send us to the responsible controller.

2. What we collect

We collect only what the service needs. There is no third-party analytics, advertising, or tracking on our site or cabinet today.

CategoryDataSourceApplies to
Account dataAccount email addressYou, at sign-upOperators
Shopify connectionYour Shopify Partner + Dev dashboard session, captured by the paired DeploTeka browser connector and sealed in an encrypted vault (see §5)You, when you connectOperators
Operational metadataRecords about the apps, stores, and setup runs in your organization (app names/IDs, store domains, run status, timestamps, health/lifecycle state)Generated by your use of the service and by our automation acting on your instructionsOperators
Lead formWork email address, plus three multiple-choice answers: fleet size, current setup, plan interest. That is the entire form.You, when you submit itProspects
Server logsIP address, user agent, request path, timestampsAutomaticEveryone
CookiesTwo first-party cookies: a session cookie (cabinet sign-in) and dt_theme (your light/dark preference). No third-party cookies.Automatic (cabinet)Operators

What we never collect: your Shopify password. When you connect, your password is typed only into Shopify's own login page in a browser on your own machine; it never passes through, and is never stored by, DeploTeka.

Operational metadata is mostly business data (app IDs, store domains), but we treat it as in-scope here because it can be linked to your account.

3. Why we use it, and the legal basis

PurposeData usedLegal basis
Providing the service: operating your account, executing setup runs and configuration pushes you initiate, showing fleet healthAccount data, Shopify connection, operational metadataContract — Art. 6(1)(b)
Responding to your early-access request and communicating with you about itLead formSteps at your request prior to a contract — Art. 6(1)(b); where you act for a company, our legitimate interest in responding to your enquiry — Art. 6(1)(f)
Service communications to account holders (changes to the service, these terms, security notices)Account emailContract — Art. 6(1)(b); legal obligation for some notices — Art. 6(1)(c)
Securing the service: abuse prevention, rate limiting, incident investigationServer logs (incl. IP)Legitimate interest in keeping the service and its tenants secure — Art. 6(1)(f)
Remembering your theme preference and keeping you signed inCookiesLegitimate interest / strictly necessary — Art. 6(1)(f)
Establishing, exercising, or defending legal claims; complying with lawAny of the above, as neededLegal obligation — Art. 6(1)(c); legitimate interest — Art. 6(1)(f)

We do not sell personal data, do not share it for advertising, and do not send marketing you didn't ask for. If you submitted the lead form, we will contact you about your request and about DeploTeka's availability; you can tell us to stop at any time and we will.

We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you.

4. The Shopify dashboard session, specifically

Because it is the most sensitive thing we hold, it gets its own section:

  • What it is. A session token for your Shopify Partner and Dev dashboards — the same kind of session your own browser holds after you log in. It is not your password and we cannot derive your password from it.
  • What we use it for. Exclusively to perform, server-side, the actions you direct through the cabinet: creating and configuring dedicated apps in your Partner organization and monitoring their state. We do not use it for anything you didn't ask the product to do.
  • How it's kept. Sealed in an encrypted vault and used server-side; it is never written to logs or rendered into pages. See the Security one-pager (/legal/security).
  • Your control. You can disconnect at any time from the cabinet or by contacting us; disconnection stops all further automated use, and the sealed session is deleted within 7 days. You can also invalidate the session yourself at any time by logging out of / resetting sessions in your Shopify account — that immediately makes our stored copy useless.

5. Who we share data with

We share personal data only with:

  • Sub-processors / service providers that host and help us run the service, under contracts that restrict them to processing on our instructions: an EU-based cloud infrastructure provider (data hosted in the European Union).
  • Shopify — inherently: the service acts inside your own Shopify accounts at your direction, so the actions you instruct are visible to Shopify like any dashboard activity. Shopify processes that data under its own terms with you; DeploTeka is not affiliated with Shopify.
  • Authorities or parties in legal proceedings, where required by law or necessary to establish, exercise, or defend legal claims — and only then.
  • A successor entity in a merger, acquisition, or asset sale, in which case this policy continues to apply and we will notify account holders.

No data is shared with advertisers or data brokers.

6. Retention

DataKept for
Lead-form submissions24 months from submission, or until you ask us to delete, whichever is first
Account data & operational metadataLife of the account, then deleted within 30 days of closure
Sealed dashboard sessionUntil you disconnect or your account closes, then deleted within 7 days
Server logs30–90 days, then deleted or fully anonymized
Records needed for legal claims/complianceAs long as the law requires or the claim period runs

7. Security

Full detail is in the Security one-pager (/legal/security). In short: all traffic is over TLS; the dashboard session is sealed in an encrypted vault and never appears in logs or pages; every cabinet read is tenant-scoped at the query layer; public endpoints are rate-limited and validated. No system is perfectly secure; if a breach affects your personal data we will notify you and any competent authority as the law requires.

8. International transfers

Our infrastructure is hosted in the European Union. Where personal data is transferred to a country without an adequacy finding, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914), plus the UK Addendum/IDTA where UK data is in scope, with a documented transfer risk assessment. Details of the mechanism applicable to a given sub-processor are available on request at privacy@deploteka.com.

9. Your rights

Depending on your location, you have the right to:

  • access the personal data we hold about you, and get a copy;
  • rectify inaccurate data;
  • erase data ("right to be forgotten");
  • restrict or object to processing, including any processing based on legitimate interest;
  • data portability — receive data you provided in a structured, commonly used, machine-readable format;
  • withdraw consent at any time, where processing is based on consent (today, essentially nothing is);
  • complain to a supervisory authority — in the EU, the supervisory authority of your habitual residence or place of work; in the UK, the ICO. We'd appreciate the chance to resolve your concern first, but you are not required to give us one.

To exercise any right, email privacy@deploteka.com from the address your account or submission is under (or provide equivalent verification — we will ask only for what we need to confirm it's you). We respond within one month, extendable by two further months for complex requests, in which case we'll tell you within the first month. Exercising these rights is free unless requests are manifestly unfounded or excessive.

If your request concerns shopper data collected on a merchant storefront, we are the processor, not the controller: we will forward your request along the chain to the responsible controller and assist as the DPA requires.

10. Children

The service is for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We will post changes here and update the effective date. For material changes we will notify account holders by email at least 14 days before they take effect. Previous versions are available on request.

12. Contact

Fixel Pixel LLP, United Kingdom — registered office available on request
privacy@deploteka.com


DeploTeka is not affiliated with or endorsed by Shopify. "Shopify" is a trademark of Shopify Inc.