Early Bird Integrations Privacy Policy
Last updated: 8 September 2026
This privacy policy applies to the Early Bird Connect Shopify app and the ItsEd Connect service for WooCommerce, including its WordPress plugin. Both are provided by Exacta Digital AB (org. nr 559136-4681), Kungsgatan 62, Uppsala, Sweden.
These integrations connect a merchant's store with Early Bird shipping services. They process the data needed to check delivery options, book shipments, update the store with shipment information, and support the merchant's use of the service. Platform-specific details are identified below.
Contact
Exacta Digital AB Org. nr 559136-4681 Kungsgatan 62 Uppsala, Sweden info@itsed.se
Roles and Responsibilities
For order, customer, delivery, and shipment data, the Shopify or WooCommerce merchant is normally the controller under the GDPR. Exacta Digital AB processes that data as the merchant's processor in order to provide the integration.
Exacta Digital AB is controller for data processed for its own administration and operation of the service, for example support correspondence, billing administration, access control, security logs, and legal compliance.
Data Used by the Integrations
Shopify
The app may process the following data from Shopify:
- shop domain, shop identifiers, installation status, app subscription status, and Shopify access tokens;
- order identifiers, order name, order status, fulfilment status, selected shipping method, fulfilment order data, parcel weight, and shipping-related order metadata;
- receiver details needed for shipment booking, including name, address, postcode, city, country, email address, and phone number;
- parcel locker selections and delivery preferences, if enabled by the merchant;
- booking, tracking, fulfilment, and shipment-status information written back to Shopify.
WooCommerce
The WordPress plugin connects the store to the hosted ItsEd Connect service at eb-gateway.itsed.se. The service performs carrier operations and returns shipment updates to the store. It receives:
- the store name, a stable installation identifier, the ItsEd Connect service key, selected carrier environment, and store webhook and integration-health URLs during verification or connection;
- Early Bird carrier credentials and sender details when the merchant connects its carrier account;
- destination postal code and relevant address and parcel information when checking delivery coverage, dates and available parcel lockers;
- sender and recipient names, addresses, applicable email and phone details, order references, parcel details and delivery selections for shipment booking, returns and related operations;
- booking, delivery and tracking identifiers for labels, status updates, cancellations and returns;
- environment and software-version information used to check integration health.
Booking payloads, including recipient information, are stored in the hosted service for retries, shipment operations and support. They are not discarded immediately after forwarding to the carrier. The store receives a service API key and webhook secret, which WordPress stores locally; the hosted service holds the carrier credentials.
The service uses SureCart to validate service keys and manage subscription entitlements and store activations. Subscription purchase and payment processing are separate from the recipient information sent for shipping.
Configuration and operational information
The merchant may also provide:
- Early Bird carrier credentials and webhook secrets;
- sender and return-address details;
- shipping configuration, service mappings, prices, notification preferences, and setup state;
- support and troubleshooting information.
Technical logs may include timestamps, request identifiers, shop domain, order or booking identifiers, status codes, error context, IP address, and user-agent information. Logs should not contain passwords, API keys, signing secrets, or access tokens.
The shipping integrations do not process payment-card details. Subscription payments are handled through the applicable checkout and payment providers. Merchant and customer data is not used for advertising or profiling.
Optional WooCommerce setup assistance and diagnostics
Contextual setup tips run locally in WordPress and use a preference stored in the current browser session. Turning tips on does not enroll anyone in email or contact ItsEd support.
Setup emails are a separate optional choice. They remain off until an administrator selects the email checkbox for the displayed recipient. WordPress then checks setup progress and may send up to two reminders through the store's email system. Readiness checks may query an existing ItsEd Connect connection. The administrator can turn setup emails off in the setup controls. Earlier automatically enabled reminders do not authorize new email reminders.
Remote diagnostic reporting is also optional and off until an administrator explicitly enables it in advanced settings. Reports contain minimized error codes, request identifiers, plugin-relative error locations and WordPress, WooCommerce, PHP and plugin versions. They are associated with the connected store account and are not anonymous. These reports exclude raw customer and shipment payloads and credentials.
The administrator can turn diagnostic reporting off in advanced settings. Turning it off stops future optional reports and clears the plugin's buffered reports. Earlier saved opt-ins without current consent evidence are disabled and their buffered reports discarded; a fresh opt-in applies to future events. Necessary shipment processing and service security records are separate from optional diagnostic reporting.
Purposes
Data is processed to:
- connect the Shopify or WooCommerce store to Early Bird;
- show shipping options, coverage decisions, and parcel locker choices;
- create, cancel, track, and update shipments;
- update the store with shipment, tracking, fulfilment, and status information;
- prevent duplicate bookings, replay attacks, abuse, and unauthorised access;
- provide support and troubleshooting;
- maintain billing, entitlement, audit, webhook, and security records;
- assist merchants with privacy requests and legal obligations.
- provide the optional setup assistance and diagnostics selected by the merchant.
Legal Basis
When Exacta Digital AB acts as processor, the merchant is responsible for the legal basis for processing customer and order data.
When Exacta Digital AB acts as controller, the legal basis is normally one or more of the following:
- contract, where processing is needed to provide the app to the merchant;
- legitimate interest, for security, troubleshooting, service reliability, fraud prevention, and business administration;
- legal obligation, where information must be retained or disclosed under applicable law.
We rely on consent for optional WooCommerce setup emails and remote diagnostic reporting. They are enabled only after the administrator's explicit choice, which can be withdrawn using the controls described above. Withdrawal does not affect processing already carried out or the separate data needed to provide shipping operations.
Recipients and Service Providers
Data is shared only as needed to provide and operate the app.
The app exchanges data with:
- Shopify, for the Shopify app's installation, Admin API access, webhooks, billing, fulfilment updates, and embedded app functionality;
- Early Bird, for shipment booking, delivery, tracking, carrier operations, and related support.
- SureCart, for WooCommerce service subscriptions, key validation and store activations. Its privacy policy describes its processing. The checkout identifies the payment providers used for subscription payments.
WooCommerce setup reminders are sent through the merchant's WordPress email system and its configured email provider. The merchant's hosting and email arrangements apply to the store's local data and messages.
Exacta Digital AB also uses technical providers for hosting, databases, connectivity, logging, tracing, monitoring, and operational security. Current technical providers include Railway and Grafana Cloud.
The WooCommerce gateway, background worker, database and queue are hosted in Railway's European region. Operational monitoring uses Grafana Cloud's European endpoint. Billing providers and other recipients may also process data outside the EU/EEA, as described below.
Early Bird may process shipment data as a carrier under its own responsibilities and terms. Shopify processes data according to its relationship with the merchant.
Retention
Personal data is kept for as long as needed to provide the app, support merchants, maintain security, and meet legal or operational requirements.
Shopify uninstall and deletion
- Shopify access tokens are deleted when the app is uninstalled;
- shop configuration, sender profile, billing state, shipping settings, order-to-shipment links, locker selections, and related shop records are kept while the app is installed and until deletion is required or requested through Shopify's shop-redaction process;
- operational logs, webhook records, audit records, and security records are kept for troubleshooting, replay protection, security, and compliance;
- shipment and booking records may be retained for longer where needed for carrier operations, support, accounting, legal claims, or legal obligations.
When Shopify sends a shop deletion request after uninstall, Early Bird Connect deletes local shop records where required. Shipment records held by Early Bird or in carrier-related operational systems may be subject to separate retention requirements.
WooCommerce disconnect, uninstall and deletion
Disconnecting removes the plugin's local service connection. Uninstalling removes local connection credentials and runtime settings; shipment-related order metadata and the stable non-secret installation identifier are retained. The merchant controls order retention and backups in its WordPress installation.
Disconnecting or uninstalling does not cancel the service subscription or automatically erase hosted account, booking or shipment records. Merchants can contact info@itsed.se about subscription cancellation and separately request access to or deletion of hosted service data.
Hosted booking payloads and shipment records are retained for ongoing shipment operations, retries, support and any applicable legal requirements. Operational logs, delivery audit records, webhook records and diagnostic events support troubleshooting, security and reliable delivery of updates. The applicable retention depends on the record's purpose, whether a shipment or support matter remains open, and any accounting, legal-claim or statutory retention obligation. Backups and billing records may have separate retention requirements. Contact us for the retention and deletion arrangements applicable to your service account.
When handling a deletion request, we establish the merchant's authority, identify the relevant account and records, and explain any information that must be retained and why. Requests concerning data controlled by the merchant or carrier are directed to that party. The Shopify shop-redaction process does not apply to WooCommerce stores.
Security
Shopify access tokens and Early Bird credentials are encrypted at rest. WooCommerce service authentication keys are hashed in the gateway; the plugin stores its connection key and webhook secret in the merchant's WordPress installation. Production service communication uses HTTPS or private service networking where available. Webhooks and callbacks are signature-verified where supported.
Production data is accessible only to authorised personnel who need access for support, security, or operation of the service.
Transfers Outside the EU/EEA
Personal data may be processed outside the EU/EEA by Shopify, billing providers or technical providers used to operate the integrations. Where required, transfers are protected by GDPR-approved safeguards, such as the European Commission's standard contractual clauses. Contact info@itsed.se for information about the providers and transfer arrangements applicable to your service.
Cookies and Similar Technologies
The Shopify app uses Shopify's embedded app environment and strictly necessary storage for authentication, session handling, and app settings. The WooCommerce plugin uses WordPress settings for its configuration and browser-session storage for local setup tips. The shipping integrations do not use advertising cookies or cross-store tracking. The merchant's own storefront and the separate subscription checkout have their own cookie and privacy information.
Rights
Where Exacta Digital AB is controller, you may request access, rectification, erasure, restriction, objection, and data portability under the GDPR.
For customer, order, delivery, and shipment data, customers should normally contact their Shopify or WooCommerce merchant, since the merchant is the controller. Merchants can contact Exacta Digital AB at info@itsed.se. Include your store address and the type of request, but do not send passwords, service keys or carrier credentials. We may ask for information needed to verify authority and locate the relevant records.
Complaints may be submitted to Integritetsskyddsmyndigheten (IMY): https://www.imy.se.
Changes
The latest version of this policy is available at this URL.