Privacy policy — Pickup points by Lyra for Shopify

Last updated 17 September 2026

Pickup points by Lyra (“the app”) is a Shopify app published by [Legal entity name, e.g. Lyra WMS B.V.] (“Lyra WMS”, “we”). It lets a store's customers choose a parcel pickup point at checkout, and saves that choice on the order, where the store's Lyra WMS reads it. This policy explains what data the app processes, why, for how long, and what your rights are. It covers merchants who install the app and the customers of their stores.

1. Who is responsible

For the merchant's own data (store, settings, credentials) Lyra WMS is the data controller. For customer data that flows through the app (shipping postcode, chosen pickup point, order reference) the merchant is the controller and Lyra WMS acts as a processor on the merchant's behalf, under the merchant's agreement with Lyra WMS for Lyra WMS and under Shopify's Partner Program Agreement.

2. What we process and why

DataSourcePurposeKept
Store domain, Shopify access token, granted scopesShopify, on installOperate the app on the store (read orders and shipping settings, create the pickup rate, write metafields)Until uninstall
App settings, including the Lyra URL and Lyra API keyMerchant, in the appLook up pickup points from the merchant's Lyra WMS and send orders back to itUntil uninstall
Shipping postcode, country and (when the app has been granted access) street address of a checkoutCustomer, via Shopify checkoutFind nearby pickup points. Sent to the merchant's Lyra WMS for the lookup; not stored by the appNot stored (processed in memory)
Chosen pickup point (carrier, name, address, opening hours, carrier reference)Customer's choiceSaved on the Shopify order (order attributes and an order metafield) and sent to the merchant's Lyra WMS so the shipping label goes to that locationOn the order in Shopify; a copy with the order id and sync status in the app until uninstall or a Shopify data-erasure request
Order id, order name, creation dateShopify (webhook / Admin API)Link the pickup point to the order and show sync status to the merchantUntil uninstall or erasure request
Technical logs (timestamps, request paths, error messages)App serversReliability and support. Logs do not contain the API key or customer addressesUp to 30 days

We do not process customer names, e-mail addresses, phone numbers or payment details, and we do not sell or share personal data for advertising.

3. Where the data goes (sub-processors)

4. Legal basis

For merchants: performance of the contract under which they use Lyra WMS and this app. For customers: the merchant's legitimate interest in delivering the order to the location the customer asked for; processing is limited to what that requires.

5. Retention and deletion

6. Security

All traffic uses HTTPS. Requests from the checkout are authenticated with Shopify session tokens; webhooks are verified with Shopify's HMAC signatures. Lyra API keys are stored server-side and never sent to the customer's browser. Access to production systems is limited to Lyra WMS staff who need it to operate the service.

7. Your rights

Under the GDPR you can ask for access to, correction or deletion of your personal data, or object to its processing. Customers should contact the store they ordered from, which controls the order data; we assist merchants with such requests. Merchants can contact us directly. You can also lodge a complaint with your data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

8. Changes

We may update this policy when the app changes. The date at the top shows the current version; material changes are announced to merchants inside the app.

9. Contact

[Legal entity name, e.g. Lyra WMS B.V.]
[Street, postcode, city, country]
[Chamber of Commerce / company registration number]
[privacy@lyrawms.nl]