Privacy Policy
In short. This website sets no cookies and runs no analytics or tracking. Baton processes data for two groups: stores that install the app (merchants) and the people who buy digital products from those stores (buyers). For buyers' data, the store is the controller and Baton is its processor. Emails are sent from Amazon SES in the EU, files are stored in Cloudflare R2 in the EU, and our servers are in Germany. A store's data is deleted when it uninstalls Baton, and on request.
1. Who we are
Baton ("Baton", "we", "us") is a Shopify app and the website batonsend.com. It is operated by an individual entrepreneur (sole trader, autónomo) established in Spain, who is the data controller for the processing described in this policy unless stated otherwise.
You can reach us at hello@batonsend.com.
2. Merchants and buyers
- Merchants are Shopify stores that install Baton. For the data we hold about a merchant and its account, Baton is the controller.
- Buyers are customers of those stores who receive digital products through Baton. The store decides why and how buyer data is used and is the controller. Baton processes buyer data only on the store's instructions, as its processor, under the data processing terms in our Terms of Service.
3. This website
batonsend.com is a static website. It sets no cookies, loads no third-party scripts, fonts or analytics, and does not fingerprint visitors. Our server keeps no visitor access log for the website.
Cloudflare, which provides DNS, reverse proxy and DDoS protection for batonsend.com, and our hosting provider process connection metadata (IP address, requested URL, browser user agent, timestamps) to operate and secure the service, as described in their own privacy notices. If you email us, we keep the correspondence for as long as needed to handle your request and, where relevant, to establish or defend legal claims.
4. Data we process about merchants
When a store installs Baton we process:
- the store's Shopify domain and store name;
- the store's contact email address, used as the reply-to address of delivery emails and for service notices;
- Shopify API access tokens for the permissions the store grants (products and orders), stored encrypted;
- the files the store uploads and how they are linked to products and variants;
- the store's settings (download limits, link expiry, fraud hold, email pause status);
- email delivery statistics for the store (sends, deliveries, bounces, complaints);
- a record of the privacy requests Shopify forwards to us and how each one was handled.
Purposes and legal basis. We use this data to provide the service the store signed up for (performance of a contract, art. 6(1)(b) GDPR), to keep the service secure and protect email deliverability for every store on Baton (our legitimate interests, art. 6(1)(f)), and to meet legal obligations such as accounting and tax rules (art. 6(1)(c)).
5. Data we process about buyers, on behalf of the store
When you buy a digital product from a store that uses Baton, we process the following to deliver your purchase:
- the email address you gave at checkout;
- the order details needed for delivery: order number and identifier, the products and variants bought, refund status and, if the store enabled a fraud hold, Shopify's risk assessment of the order;
- your delivery record: the private download link, download count, expiry and whether it was revoked;
- download events (time, IP address, browser user agent, bytes served), used to enforce download limits and detect abuse;
- license keys assigned to your order, when the product includes one;
- delivery events for the delivery email (sent, delivered, bounced, marked as spam). If your mailbox rejects our emails or you report one as spam, we record that the store must not email you again through Baton.
The store relies on the performance of its contract with you (art. 6(1)(b) GDPR) and, for fraud prevention and abuse detection, on its legitimate interests (art. 6(1)(f)). Baton sends buyers transactional emails only: the delivery email, and the same email again if the store resends it. We never use buyer data for marketing, never share it with other stores, and never sell it.
6. Service providers
We rely on the following providers. Each one processes data under a contract that binds it to the GDPR's requirements for processors.
| Provider | What it does for Baton | Location and safeguards |
|---|---|---|
| Shopify | E-commerce platform. Source of the store's orders, products and account. Governed by the store's own agreement with Shopify. | Global. See Shopify's privacy policy. |
| Amazon Web Services (Amazon SES, Amazon SNS) | Sends delivery emails and reports delivery, bounce and complaint events back to us. | EU, Stockholm region (eu-north-1). EU-US Data Privacy Framework and Standard Contractual Clauses. |
| Cloudflare | Object storage (R2) for the files stores upload; DNS, reverse proxy and DDoS protection for batonsend.com; routing of email sent to our contact address. | Files are stored in Cloudflare's EU jurisdiction. Network traffic may pass through Cloudflare data centres worldwide. EU-US Data Privacy Framework and Standard Contractual Clauses. |
| dataforest GmbH | Hosting of the dedicated server that runs Baton and its database. | Germany (EU). |
7. How long we keep data
- Merchant account data: for as long as Baton is installed. When a store uninstalls Baton, Shopify sends us a shop redaction request 48 hours later; we then delete the store's records and queue its files for deletion from storage, which completes within a few days.
- Deliveries, download events and email events: for as long as the store uses Baton, so buyers can download again within the store's limits and the store can support them. They are deleted together with the store's data, or anonymised earlier when the store, or Shopify on the store's behalf, sends a customer erasure request.
- Email suppression entries: for as long as the store uses Baton, because their purpose is to prevent further emails to that address.
- Privacy request records: kept as an audit trail of how each request was handled.
- Correspondence with us: for as long as needed to handle the matter and to establish or defend legal claims.
- Accounting records: for the period required by Spanish tax and commercial law, where they contain personal data.
8. Security
All traffic to batonsend.com, to the app and to download pages uses HTTPS. Shopify access tokens are encrypted at rest with keys kept outside the database. Download links are long random tokens that can be limited, given an expiry and revoked. Every webhook we receive from Shopify or Amazon is signature-checked before it is processed. Credentials follow the principle of least privilege, and data lives in EU data centres. Baton never sees or stores payment card data; payments are handled by Shopify.
9. Your rights
Under the GDPR you can ask for access to your personal data, have it corrected or erased, restrict or object to its processing, and receive a copy in a portable format. Where processing is based on consent, you can withdraw it at any time.
- Buyers: the fastest route is the store you bought from, because it is the controller and can identify your order. Stores can also submit requests through Shopify, which forwards them to Baton automatically. You are welcome to contact us directly as well; we will handle the request with the store.
- Merchants: write to hello@batonsend.com.
We answer within one month. We may ask you to confirm your identity before acting on a request. If you believe we are processing your data unlawfully, you can lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or with the authority in your own EU country.
10. Children
Baton is a business tool for stores. It is not directed at children, and we do not knowingly process children's data beyond what a store's order contains.
11. Changes and contact
We will post any change to this policy on this page with a new effective date. Merchants are told about material changes through the app or by email.
Questions or requests: hello@batonsend.com.