Contact AutoResponder Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how WebPanda Solutions ("we", "us", "our") collects, uses, shares, and protects personal data when merchants use Contact AutoResponder (the "App"). The App helps merchants send automated transactional reply emails after storefront form submissions.
Who This Policy Covers
This policy covers personal data relating to:
- Merchants and merchant staff using the App.
- Storefront visitors/customers whose form data is processed by the App.
Roles Under Data Protection Laws
For storefront customer form data, the merchant is typically the controller and we act as a processor/service provider under the merchant's instructions. For some account, billing, and security operations, we may act as an independent controller where permitted by law.
Where we use third-party providers to help deliver the service (for example email delivery providers), those providers act as our subprocessors for the relevant processing activities.
Personal Data We Process
Depending on use, we may process:
- Merchant account and store data: Shopify store domain, OAuth/session technical data, billing/subscription status, and app configuration data.
- Autoresponder configuration: enable/disable settings, subject lines, sender name, reply-to email, CC addresses, and configured HTML message templates.
- Storefront form submission data: form fields submitted by visitors (for example: name, email, phone number, message content), processed for transactional autoresponse delivery. We do not store this submission content in our own app database for this flow.
- Operational and security data: anti-abuse counters and related technical records needed to operate and protect the service.
What We Store in Our Database
In our app database, we store merchant account and configuration data required to run the App (for example enabled settings, subject lines, sender details, message templates, and operational counters).
We do not store storefront customer-submitted contact/newsletter form content in our own app database for this flow.
How We Use Personal Data
We use personal data to:
- Provide app functionality, including sending transactional autoresponder emails.
- Store and apply merchant-selected configuration.
- Enforce anti-abuse and security controls.
- Provide customer support and service communications.
- Meet legal obligations and protect our rights.
We do not sell personal data and we do not use storefront customer form data for our own independent marketing.
Legal Bases (EEA/UK/Switzerland)
Where required, we rely on one or more of the following legal bases:
- Performance of a contract with merchants to provide the App.
- Legitimate interests in securing and improving the App.
- Compliance with legal obligations.
- For merchant-controlled customer communications, the merchant is responsible for the appropriate lawful basis and notices at collection.
GDPR-Specific Information
If GDPR or UK GDPR applies, this section summarizes key compliance points for this App:
- Controller/processor roles: for storefront customer form data, the merchant is typically the controller and we act as processor on the merchant's documented instructions.
- Article 28 terms: processing terms between us and merchants are set out in our Data Processing Agreement (DPA).
- International transfers: where data is processed outside the EEA/UK/Switzerland, we apply lawful safeguards such as adequacy mechanisms, Standard Contractual Clauses, or equivalent safeguards.
- Data subject rights: data subjects may have rights of access, rectification, erasure, restriction, objection, and portability, subject to applicable law.
- Complaints: data subjects may also lodge a complaint with their local supervisory authority.
- Automated decision-making: we do not use personal data processed through the App for automated decision-making or profiling that produces legal or similarly significant effects on data subjects.
- Withdrawal of consent: where any processing relies on consent, the relevant consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Sharing and Subprocessors
We share personal data only as necessary to provide the App and operate our business. Key recipients include:
- Shopify: authentication, app embedding, billing, and platform integration.
- Email delivery provider: Mailchimp Transactional (formerly Mandrill), used to deliver transactional autoresponder emails. This provider processes recipient address, message subject/body, and related metadata needed for delivery operations.
- Infrastructure providers: hosting, storage, and security service providers that help operate the App.
We may also disclose personal data where required by law, legal process, or to protect rights, safety, and security.
International Data Transfers
Personal data may be processed outside the EEA/UK/Switzerland, including in the United States, where service providers operate infrastructure. Where required, we use appropriate safeguards for international transfers, such as adequacy mechanisms, Standard Contractual Clauses, or equivalent lawful safeguards. You may request further information about these safeguards, or a copy of the relevant safeguards where applicable, by contacting us at support@webpanda-solutions.com.
Data Retention
- Merchant account/configuration data: retained while the App is active and for a reasonable period afterward for legal, security, and operational purposes.
- Storefront submission data: processed primarily for autoresponse delivery. We do not maintain long-term customer profile storage for this data in our app database for this flow.
- Email provider activity logs: retained by the delivery provider according to provider settings and policies, with a maximum retention period of 90 days in our current Mailchimp Transactional (formerly Mandrill) setup.
- Security/anti-abuse records: retained as necessary to enforce limits, detect abuse, and comply with legal obligations.
Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, loss, or misuse. These include access controls, service authentication, and anti-abuse controls.
Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to certain processing, and request portability of personal data.
If you are a storefront customer, you should usually contact the merchant first, because the merchant is typically the controller of that data. We will support merchants with reasonable processor assistance where required.
Children's Data
The App is intended for business use by merchants and is not directed to children. We do not knowingly collect children's personal data directly for our own purposes.
Changes
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version here with a revised "Last updated" date.
Contact Us
For questions, rights requests, or complaints regarding this policy: