Skip to content

Merchant privacy notice

Effective September 18, 2026

RoutiVox is operated by atoz advert online seller, located at Sharooq Land 2, 1012, Dubai Land Residence, Dubai, United Arab Emirates. For privacy questions or requests, email info@atozadvert.com.

What we process

When a merchant installs RoutiVox, the app receives Shopify order and fulfillment events. It processes order identifiers and numbers, line items and order notes, customer name, email and phone, and shipping address fields. It also processes the shop domain and display name, the shop contact email when handling a privacy request, branch contact details, and merchant-configured automation settings. RoutiVox does not require payment-card details.

Why we use the data

RoutiVox compares shipping-area fields with merchant-configured area mappings, assigns an order to a branch, applies a Shopify order tag, and sends an order notification to the selected branch address. If the merchant enables scheduled reports or other order automations, the app reads relevant order data to produce those reports or actions. We do not use this information for advertising or sell it.

Who receives the data

  • Authorized merchant staff can view dispatch activity inside the Shopify Admin app.
  • The branch email address configured by the merchant receives enabled order notifications. RoutiVox sends them from a verified RoutiVox address. The merchant may set a Reply-To address and should limit branch recipients to staff who need the order details.
  • Railway Corporation hosts the app and PostgreSQL database and stores encrypted backups in a private bucket.
  • Plus Five Five, Inc. (Resend) delivers branch notifications and privacy-request emails.

RoutiVox also exchanges order and privacy-request data with Shopify to provide these features.

Storage, security, and retention

RoutiVox stores a limited dispatch log containing a pseudonymized order identifier, encrypted order number, encrypted customer name and matched area, branch assignment, delivery and tagging status, and timestamp. The standard retention period for these logs is 90 days; a cleanup worker deletes expired entries. Branch contact details and merchant settings remain while the app is in use, subject to deletion on shop redaction.

The app uses HTTPS for public traffic, encrypts customer-linked log fields and merchant settings at the application level, and sends email through Resend over an authenticated TLS connection. Daily database exports are encrypted before upload to a private Railway bucket. After each successful backup, the job is configured to delete copies older than 90 days while preserving the newest copy. If new backups fail, that preserved copy may remain longer than 90 days.

Privacy requests

RoutiVox handles Shopify customer data request, customer redaction, and shop redaction webhooks. Merchants can also email info@atozadvert.com about an access, correction, or deletion request. Encrypted backup copies may continue to contain deleted records while those backups are retained.

International transfers and changes

The app, PostgreSQL database, and backup service currently run in Railway's United States region. Encrypted backup objects are stored in Railway's California, United States bucket region. Resend states that it stores message content and delivery logs in the United States. Order and notification data may therefore be transferred from a merchant's location to the United States. For information about applicable transfer safeguards, contact us at info@atozadvert.com.

We will update this notice when data categories, purposes, service providers, or retention materially change and notify merchants as required.