Early Bird Integrations Privacy Policy

Last updated: 8 September 2026

This privacy policy applies to the Early Bird Connect Shopify app and the ItsEd Connect service for WooCommerce, including its WordPress plugin. Both are provided by Exacta Digital AB (org. nr 559136-4681), Kungsgatan 62, Uppsala, Sweden.

These integrations connect a merchant's store with Early Bird shipping services. They process the data needed to check delivery options, book shipments, update the store with shipment information, and support the merchant's use of the service. Platform-specific details are identified below.

Contact

Exacta Digital AB Org. nr 559136-4681 Kungsgatan 62 Uppsala, Sweden info@itsed.se

Roles and Responsibilities

For order, customer, delivery, and shipment data, the Shopify or WooCommerce merchant is normally the controller under the GDPR. Exacta Digital AB processes that data as the merchant's processor in order to provide the integration.

Exacta Digital AB is controller for data processed for its own administration and operation of the service, for example support correspondence, billing administration, access control, security logs, and legal compliance.

Data Used by the Integrations

Shopify

The app may process the following data from Shopify:

WooCommerce

The WordPress plugin connects the store to the hosted ItsEd Connect service at eb-gateway.itsed.se. The service performs carrier operations and returns shipment updates to the store. It receives:

Booking payloads, including recipient information, are stored in the hosted service for retries, shipment operations and support. They are not discarded immediately after forwarding to the carrier. The store receives a service API key and webhook secret, which WordPress stores locally; the hosted service holds the carrier credentials.

The service uses SureCart to validate service keys and manage subscription entitlements and store activations. Subscription purchase and payment processing are separate from the recipient information sent for shipping.

Configuration and operational information

The merchant may also provide:

Technical logs may include timestamps, request identifiers, shop domain, order or booking identifiers, status codes, error context, IP address, and user-agent information. Logs should not contain passwords, API keys, signing secrets, or access tokens.

The shipping integrations do not process payment-card details. Subscription payments are handled through the applicable checkout and payment providers. Merchant and customer data is not used for advertising or profiling.

Optional WooCommerce setup assistance and diagnostics

Contextual setup tips run locally in WordPress and use a preference stored in the current browser session. Turning tips on does not enroll anyone in email or contact ItsEd support.

Setup emails are a separate optional choice. They remain off until an administrator selects the email checkbox for the displayed recipient. WordPress then checks setup progress and may send up to two reminders through the store's email system. Readiness checks may query an existing ItsEd Connect connection. The administrator can turn setup emails off in the setup controls. Earlier automatically enabled reminders do not authorize new email reminders.

Remote diagnostic reporting is also optional and off until an administrator explicitly enables it in advanced settings. Reports contain minimized error codes, request identifiers, plugin-relative error locations and WordPress, WooCommerce, PHP and plugin versions. They are associated with the connected store account and are not anonymous. These reports exclude raw customer and shipment payloads and credentials.

The administrator can turn diagnostic reporting off in advanced settings. Turning it off stops future optional reports and clears the plugin's buffered reports. Earlier saved opt-ins without current consent evidence are disabled and their buffered reports discarded; a fresh opt-in applies to future events. Necessary shipment processing and service security records are separate from optional diagnostic reporting.

Purposes

Data is processed to:

Legal Basis

When Exacta Digital AB acts as processor, the merchant is responsible for the legal basis for processing customer and order data.

When Exacta Digital AB acts as controller, the legal basis is normally one or more of the following:

We rely on consent for optional WooCommerce setup emails and remote diagnostic reporting. They are enabled only after the administrator's explicit choice, which can be withdrawn using the controls described above. Withdrawal does not affect processing already carried out or the separate data needed to provide shipping operations.

Recipients and Service Providers

Data is shared only as needed to provide and operate the app.

The app exchanges data with:

WooCommerce setup reminders are sent through the merchant's WordPress email system and its configured email provider. The merchant's hosting and email arrangements apply to the store's local data and messages.

Exacta Digital AB also uses technical providers for hosting, databases, connectivity, logging, tracing, monitoring, and operational security. Current technical providers include Railway and Grafana Cloud.

The WooCommerce gateway, background worker, database and queue are hosted in Railway's European region. Operational monitoring uses Grafana Cloud's European endpoint. Billing providers and other recipients may also process data outside the EU/EEA, as described below.

Early Bird may process shipment data as a carrier under its own responsibilities and terms. Shopify processes data according to its relationship with the merchant.

Retention

Personal data is kept for as long as needed to provide the app, support merchants, maintain security, and meet legal or operational requirements.

Shopify uninstall and deletion

When Shopify sends a shop deletion request after uninstall, Early Bird Connect deletes local shop records where required. Shipment records held by Early Bird or in carrier-related operational systems may be subject to separate retention requirements.

WooCommerce disconnect, uninstall and deletion

Disconnecting removes the plugin's local service connection. Uninstalling removes local connection credentials and runtime settings; shipment-related order metadata and the stable non-secret installation identifier are retained. The merchant controls order retention and backups in its WordPress installation.

Disconnecting or uninstalling does not cancel the service subscription or automatically erase hosted account, booking or shipment records. Merchants can contact info@itsed.se about subscription cancellation and separately request access to or deletion of hosted service data.

Hosted booking payloads and shipment records are retained for ongoing shipment operations, retries, support and any applicable legal requirements. Operational logs, delivery audit records, webhook records and diagnostic events support troubleshooting, security and reliable delivery of updates. The applicable retention depends on the record's purpose, whether a shipment or support matter remains open, and any accounting, legal-claim or statutory retention obligation. Backups and billing records may have separate retention requirements. Contact us for the retention and deletion arrangements applicable to your service account.

When handling a deletion request, we establish the merchant's authority, identify the relevant account and records, and explain any information that must be retained and why. Requests concerning data controlled by the merchant or carrier are directed to that party. The Shopify shop-redaction process does not apply to WooCommerce stores.

Security

Shopify access tokens and Early Bird credentials are encrypted at rest. WooCommerce service authentication keys are hashed in the gateway; the plugin stores its connection key and webhook secret in the merchant's WordPress installation. Production service communication uses HTTPS or private service networking where available. Webhooks and callbacks are signature-verified where supported.

Production data is accessible only to authorised personnel who need access for support, security, or operation of the service.

Transfers Outside the EU/EEA

Personal data may be processed outside the EU/EEA by Shopify, billing providers or technical providers used to operate the integrations. Where required, transfers are protected by GDPR-approved safeguards, such as the European Commission's standard contractual clauses. Contact info@itsed.se for information about the providers and transfer arrangements applicable to your service.

Cookies and Similar Technologies

The Shopify app uses Shopify's embedded app environment and strictly necessary storage for authentication, session handling, and app settings. The WooCommerce plugin uses WordPress settings for its configuration and browser-session storage for local setup tips. The shipping integrations do not use advertising cookies or cross-store tracking. The merchant's own storefront and the separate subscription checkout have their own cookie and privacy information.

Rights

Where Exacta Digital AB is controller, you may request access, rectification, erasure, restriction, objection, and data portability under the GDPR.

For customer, order, delivery, and shipment data, customers should normally contact their Shopify or WooCommerce merchant, since the merchant is the controller. Merchants can contact Exacta Digital AB at info@itsed.se. Include your store address and the type of request, but do not send passwords, service keys or carrier credentials. We may ask for information needed to verify authority and locate the relevant records.

Complaints may be submitted to Integritetsskyddsmyndigheten (IMY): https://www.imy.se.

Changes

The latest version of this policy is available at this URL.