Trenvano

Legal

Privacy policy

Last updated: 29 August 2026. This policy applies to the Trenvano app for Shopify and to this website.

Trenvano adds a cash on delivery order form to a Shopify store and copies the resulting orders into the merchant's own Google Sheets. This policy explains exactly what data reaches Trenvano, what is passed straight through to Shopify, and the one case in which Trenvano keeps a shopper's details in its own database: an order held because the merchant's plan has run out of its monthly allowance. That case is described in full in section 5.

1. Who this policy covers

Trenvano is operated by Yaovi Henoc Odji, trading as Trenvano, referred to below as "we" or "Trenvano".

This policy covers two groups of people:

  • Merchants. Shopify store owners and their staff who install and use the app.
  • Shoppers. People who place a cash on delivery order through a form that a merchant has added to their store using Trenvano.

2. Who controls the data

For shopper data, the merchant is the data controller and Trenvano is a data processor acting on the merchant's instructions. The merchant decides which fields the order form asks for, which Google Sheets orders are written to, and how long they keep those spreadsheets. Trenvano does not decide any of that, and does not use shopper data for its own purposes.

For merchant account data, such as the shop domain, the app settings and the connected Google account, Trenvano is the controller.

Shopify is a separate controller of the store and its orders under Shopify's own privacy policy. Google is a separate controller of the merchant's Google account under Google's own privacy policy.

3. What Trenvano does

  • It renders a cash on delivery order form on the merchant's product pages, using the fields the merchant configured.
  • It receives the submitted form through Shopify's app proxy, validates it, and asks Shopify to create an order.
  • Where the merchant's plan has used up its monthly order allowance, it holds the order instead of creating it, and places it once the merchant moves to a larger plan. This is the only case in which Trenvano keeps a shopper's details, and section 5 sets out exactly what is kept and for how long.
  • It listens for new orders in the store and appends each one as a row in the Google Sheets the merchant has mapped that product to.
  • It records whether each delivery to each sheet succeeded, and retries the ones that did not.

4. Shopper details submitted through the order form

What is collected

The merchant chooses the fields. A new installation starts with full name, phone number, delivery address, city and an optional delivery note. The merchant can add an email address, a second address line, a province, a postcode, a country, and their own questions such as a preferred delivery time.

The submission also carries the product and variant identifiers, the quantity, any optional offers the shopper accepted, and a one-time key generated by the browser so that tapping the confirm button twice cannot create two orders.

What happens to it

The details are validated and then sent to Shopify to create the order. Name, phone number, email address and the address fields go into the Shopify order. Answers to the merchant's own questions are attached to the Shopify order as custom attributes, and the delivery note becomes the order note. From that point the data lives in the merchant's Shopify admin and is governed by Shopify's terms and the merchant's own privacy policy.

What Trenvano stores

Where the order is created straight away, which is what happens on every submission until a merchant runs out of their monthly allowance, Trenvano does not write the shopper's name, address or email address into its own database. For each submission it stores only:

  • the shop the submission belongs to;
  • the one-time key described above;
  • whether the attempt is in progress, succeeded or failed, and the time it was created and last changed;
  • the identifier and number of the Shopify order it created, if one was created;
  • if it failed, a short failure code and the error message Shopify returned, cut to 500 characters. This is kept so the merchant can see why orders are failing rather than losing sales silently. Shopify's validation messages describe the problem rather than repeating what the shopper typed, but a message of that kind could in principle include a submitted value;
  • the anti-spam hashes described in section 7, where the merchant has those checks switched on.

The one exception is an order that has to be held because the merchant's allowance has run out. That order's details are kept, encrypted, until it is placed or deleted. Section 5 describes it.

Shopper contact details are deliberately not written to Trenvano's application logs. Logs record the shop domain, the order number and counts.

5. Orders held when a plan runs out of its allowance

Every Trenvano plan includes a number of orders a month. When a merchant reaches that number, the order form does not shut down. It keeps accepting orders, and each further order is held rather than created: no Shopify order exists for it, it does not appear in the merchant's admin, and nothing is written to any Google Sheet. Held orders are placed automatically, oldest first, as soon as the merchant moves to a plan with a larger allowance.

The shopper is not told the order is confirmed, because it is not. They are told that their order has been received and will be confirmed shortly.

Holding an order means Trenvano has to keep the order until it can be placed. This is the only place in the app where a shopper's personal data is stored in Trenvano's own database, and it is the reason this section exists.

What is stored

For each held order, Trenvano stores the shopper's answers to the form exactly as they were submitted. On a default installation that is their full name, phone number, delivery address and city, and any delivery note; where the merchant has added them, it also includes an email address, a second address line, a province, a postcode, a country, and the answers to the merchant's own questions. Alongside those it stores which products and variants were ordered, the quantities, and any optional offers the shopper accepted.

Prices are deliberately not stored. A held order may be days old, so the price is read from Shopify again at the moment the order is placed rather than taken from what was saved.

The record also holds the time the order was placed, how many attempts have been made to create it, and, where an attempt failed, a short reason written by Trenvano for the merchant to read. That reason never quotes anything the shopper typed.

How it is protected

All of it is encrypted before it is written to the database, using AES-256-GCM with a fresh random initialisation vector for every record and an authentication tag that is verified on decryption. It is the same encryption used for the Google tokens described in section 9, and the key is held in the application environment rather than in the database. The details are decrypted only in the moment the order is placed.

A held order's details are never written to application logs, never included in an error message, and never sent to the merchant's browser. The merchant's admin shows how many orders are held, when each was placed, how many items it contains and whether it needs their attention. It does not show the shopper's name, number or address.

So that an erasure request can find a held order without Trenvano keeping a searchable copy of a shopper's contact details, a keyed hash of the phone number and of the email address is stored beside the record, in the same way and for the same reason as the anti-spam hashes in section 7.

How long it is kept

A held order is deleted 90 days after the shopper placed it, whatever has happened to it in the meantime. If the merchant has not moved to a larger plan by then, the order and the shopper's details in it are deleted and cannot be recovered. This applies to every held order, including ones that were flagged for the merchant to look at and never dealt with. Keeping a stranger's address indefinitely because a merchant never upgraded would not be acceptable, so there is a fixed limit and it is enforced by a job that runs several times a day.

A merchant's billing period ending does not release held orders and does not delete them. Only an upgrade releases them, and only the 90 day limit, an erasure request or the merchant leaving deletes them.

When the order is placed, the shopper's details are erased from Trenvano at that moment. What remains is a receipt: the Shopify order number and identifier and the time it was created, with no name, number or address. The order itself then lives in the merchant's Shopify admin like any other. That receipt is itself deleted at the 90 day mark.

On an erasure request, held orders belonging to that shopper are deleted. Section 15 explains how that request reaches Trenvano and its one limitation.

When a merchant uninstalls, held orders are never placed: there is no longer a merchant to fulfil them. They are deleted along with everything else about that shop when Shopify sends the shop redaction request 48 hours later, and by the 90 day limit in any event.

A shopper who wants to know whether an order of theirs is being held, or who wants it deleted before any of the above, can ask the store they ordered from, or contact us directly using the details in section 20.

6. Order details routed to your Google Sheets

When an order is created in the store, Shopify notifies Trenvano. Trenvano reads the order in order to build the spreadsheet row: the order number, date, total, currency and status page link, the customer name, phone number and email address, the shipping address, the items ordered, the order note and any custom attributes. It then appends a row to each Google Sheet the merchant has mapped that product to, using the columns the merchant chose.

This information passes through Trenvano in order to write the row. It is not saved in Trenvano's database. What Trenvano keeps about each order is a record with no contact details in it: the Shopify order identifier and number, the order total and currency, the number of items, whether routing succeeded, and one row per destination recording the delivery attempt, its status, the number of attempts and the last error message. A delivery that is retried reads the order from Shopify again rather than working from a stored copy.

Once a row is in the merchant's spreadsheet it is the merchant's record, held in the merchant's own Google account. Trenvano does not control it, and deleting the app does not delete it.

7. Anti-spam checks

The order form has no password and no checkout, so it needs protection against automated submissions. Trenvano offers the merchant a hidden field that only a bot would fill in, a minimum time between the form appearing and being submitted, a limit on submissions from one internet address per hour, and an optional check that refuses a repeat order from the same phone number inside a chosen window.

The last two need to recognise a repeat without knowing who it is. Trenvano therefore stores a keyed hash of the shopper's internet address and of their phone number, and never the values themselves. A keyed hash is a one way fingerprint computed with a secret held by the application: Trenvano can tell that two submissions came from the same address or the same number, and cannot recover the address or the number from what it stored.

These hashes are stored against the submission record described in section 4 and are removed with it.

8. Merchant and shop data

To run the app, Trenvano stores:

  • The Shopify session. The shop domain, the access token Shopify issued to Trenvano, the permissions granted, and, where Shopify issues a token for an individual staff member, that person's Shopify user identifier, name and email address. This record is created and managed by Shopify's own app library.
  • Shop record. The store domain, when the app was installed and uninstalled, the current plan, the subscription status and dates taken from Shopify billing.
  • Settings. The order form fields and appearance, the connected Google accounts, the destination spreadsheets and their column layouts, the rules mapping products to destinations, and any offers the merchant configured.
  • Operational records. The order and delivery records described in section 6, the submission records described in section 4, and any held orders described in section 5.

Trenvano does not receive payment card details. Subscriptions are charged by Shopify through the merchant's Shopify account.

9. Google account data and the access Trenvano requests

Connecting a Google account is optional and is done by the merchant. It is what allows Trenvano to write orders into spreadsheets. Trenvano requests these scopes and no others:

ScopeWhy Trenvano asks for it
https://www.googleapis.com/auth/spreadsheetsTo read the tabs and header row of a spreadsheet the merchant selects, to write a header row when a sheet is first connected, and to append one row per order. Trenvano writes only to the spreadsheets the merchant has chosen in the app.
https://www.googleapis.com/auth/drive.fileTo list spreadsheets in the picker so the merchant can choose one. This scope covers only files used with this app. It does not give Trenvano access to the rest of the merchant's Google Drive.
openid and emailTo identify which Google account was connected, so a merchant using several accounts can tell them apart and knows which one to reconnect if access lapses.

What is stored

For each connected account Trenvano stores the Google account identifier, the email address, the access token, the refresh token, the token expiry time, the scopes granted, the connection status and the last error reported by Google. The access token and the refresh token are encrypted before they are written to the database, using AES-256-GCM with a fresh random initialisation vector for every value and an authentication tag that is verified on decryption. The encryption key is held in the application environment and is not stored in the database. Tokens and authorisation codes are never written to application logs.

Trenvano does not read, index or copy the contents of the merchant's spreadsheets beyond what it needs to place a row correctly, and does not access any file the merchant has not chosen.

How to withdraw access

A merchant can disconnect a Google account at any time from the Google accounts section of the app. Disconnecting asks Google to revoke the grant, deletes the stored account record and both encrypted tokens, and removes the sheet destinations that depended on it along with the routing rules pointing at them. Rows already written to the spreadsheets are left alone.

A merchant can also revoke access directly at myaccount.google.com/permissions. Doing so stops Trenvano writing to their sheets, and the app will show the connection as needing to be reconnected.

Uninstalling the app does not by itself revoke the Google grant. The stored tokens are deleted when Shopify sends the shop redaction request described in section 15, but that deletion removes them from Trenvano rather than revoking them at Google. A merchant who wants the grant revoked immediately should either disconnect the account in the app before uninstalling, or revoke it at the Google page above.

10. Google API Services User Data Policy and Limited Use

Trenvano's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google states those requirements as follows. This quotation is taken from the Google API Services User Data Policy; the policy itself is the authoritative version.

Limited Use: Your use of data obtained via the product's specified scopes must comply with the below requirements. These requirements apply to the raw data obtained from the scopes and data aggregated, anonymized, or derived from them.

  1. Limit your use of data to providing or improving user-facing features that are prominent in the requesting application's user interface;
  2. Transfers of data are not allowed, except:
    1. To provide or improve your appropriate access or user-facing features that are visible and prominent in the requesting application's user interface and only with the user's consent;
    2. For security purposes (for example, investigating abuse);
    3. To comply with applicable laws; or,
    4. As part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user.
  3. Don't allow humans to read the data, unless: you first obtained the user's affirmative agreement to view specific messages, files, or other data; it is necessary for security purposes (for example, investigating a bug or abuse); it is necessary to comply with applicable laws; or in the further limited circumstances set out in the policy.

In practice, this is how Trenvano meets each requirement:

  • Google account data is used for one visible feature: choosing a spreadsheet and writing orders into it. That feature is the reason the app exists and is the first thing a merchant sets up.
  • Trenvano does not transfer Google user data to anyone. It is not sold, rented, shared with advertisers or data brokers, or used to build any profile or model.
  • No member of staff reads a merchant's Google data as a matter of course. A person would look at it only where the merchant has asked for help with a specific problem and agreed to it, where it is necessary to investigate a security issue or abuse, or where the law requires it.
  • Google account data is never used for advertising of any kind, including retargeting, personalised advertising or interest-based advertising.

11. Cookies, advertising and analytics

Trenvano sets no cookies of its own on this website or on the storefront order form, and stores nothing in the shopper's browser storage. This website loads no analytics, no advertising tags and no tag manager. It requests one webfont stylesheet from Shopify's content delivery network.

By default the order form on a merchant's storefront communicates only with the merchant's own domain, through Shopify's app proxy, and makes no requests to any third party. The one exception is the marketing pixels described below, which a merchant switches on themselves.

Marketing pixels

A merchant can connect a Meta (Facebook) pixel, a TikTok pixel, or both, by entering the pixel ID in the Trenvano admin. This is off by default. When a merchant has not switched a pixel on, the order form loads no code from Meta or TikTok and sends them nothing at all.

When a merchant does switch a pixel on, the order form loads that network's own script from the network's servers and sends it events when a shopper views the product, begins filling in the form, and completes an order. Those events carry the product, the order value and the currency. They do not carry the shopper's name, phone number or delivery address. The network sets its own cookies at that point and becomes an independent controller of the data it collects, governed by its own privacy policy rather than this one.

These events are sent only when the shopper's tracking consent allows it. Trenvano checks Shopify's Customer Privacy API before loading any pixel script and before sending any event, and where a shopper has declined marketing tracking, no script is loaded and no event is sent. Because the merchant chooses to enable a pixel and decides what to tell their shoppers about it, the merchant is responsible for their own cookie notice and for any consent their local law requires.

Shopify sets its own cookies on the storefront and in the Shopify admin. Those are governed by Shopify's privacy policy and by the merchant's own cookie notice, not by this one.

Trenvano does not sell personal data. Trenvano does not use personal data for its own advertising, and the pixels described above send data to the merchant's own advertising accounts, not to Trenvano's.

12. Who else processes this data

Trenvano uses a small number of service providers. It uses no analytics service and no error tracking service.

ProviderWhat it does
ShopifyHosts the store, holds the orders, authenticates the app, delivers order notifications and charges the subscription.
GoogleProvides the Sheets and Drive APIs and the sign in used to connect an account, at the merchant's instruction.
RenderHosts the Trenvano application and the PostgreSQL database it stores data in.
MetaReceives conversion events from the storefront order form, but only where the merchant has switched on a Meta pixel and the shopper's tracking consent allows it. Not used unless a merchant enables it.
TikTokReceives conversion events from the storefront order form, but only where the merchant has switched on a TikTok pixel and the shopper's tracking consent allows it. Not used unless a merchant enables it.

Meta and TikTok are listed because a merchant can choose to enable them. Where a merchant has not, no data reaches either of them.

Data is disclosed to no one else, except where the law requires it.

13. How data is protected

  • All traffic to and from the app is over HTTPS. Calls to Shopify and Google are server to server over TLS.
  • Google access and refresh tokens are encrypted at rest with AES-256-GCM, as described in section 9.
  • The shopper details in a held order are encrypted at rest with the same AES-256-GCM scheme, as described in section 5, and are decrypted only in the moment the order is placed.
  • Every order form submission arrives through Shopify's app proxy, which signs the request. Requests that are not correctly signed are rejected.
  • Every webhook from Shopify is verified against its signature before it is processed. Anything unsigned or altered is rejected.
  • The link used to connect a Google account carries a signed, time-limited value that ties the consent to one shop and expires within ten minutes, so a link that leaks cannot be used to point one merchant's Google account at another merchant's shop.
  • Tokens, authorisation codes, held order details and shopper contact details are kept out of application logs and out of error messages.

No system is perfectly secure. If a breach affects personal data, we will notify the affected merchants and the relevant supervisory authority as the law requires.

14. How long data is kept

Trenvano keeps data for as long as the app is installed on the store, with one exception, which is the only category that carries a shopper's personal details.

Held orders are deleted after 90 days, counted from the moment the shopper placed the order and applied whatever state the order is in, including after it has been placed in Shopify and its details erased. Section 5 sets this out in full. It is the one fixed retention period in the app, and it exists because this is the one place a shopper's name, phone number and address are stored.

Everything else has no automatic deletion after a fixed period: the order records, delivery records and submission records described above are kept while the shop exists so that the merchant can see their own order history and so that failed deliveries can be retried. None of those records contains a shopper's name, phone number, address or email address.

When a merchant uninstalls the app, the Shopify session and its access token are deleted straight away and the shop is marked as uninstalled. Settings are deliberately kept at that point, because merchants often uninstall and reinstall while trialling an app, and losing their configuration would mean setting everything up again.

Shopify sends a shop redaction request 48 hours after an uninstall. On receiving it, Trenvano deletes the shop record and everything attached to it: the form settings, the connected Google accounts and their encrypted tokens, the destinations, the routing rules, the offers, the order history, the submission records and any held orders. Nothing about that shop remains.

Held orders belonging to an uninstalled shop are never placed, because there is no longer a merchant to fulfil them. They are deleted by the shop redaction above, and by the 90 day limit in any event.

A merchant who wants their data deleted sooner can ask us at the address in section 20, or disconnect their Google accounts and remove their destinations in the app, which deletes those records immediately.

Rows already written into a merchant's Google Sheets are the merchant's own records and are not affected by any of this. They stay in the merchant's Google account until the merchant deletes them.

15. Shopify data requests, erasure and shop redaction

Shopify requires every app to handle three privacy requests. Trenvano implements all three.

customers/data_request

Sent when a shopper asks a merchant what data an app holds about them. Trenvano acknowledges and records the request using the request and customer identifiers only, and the merchant answers the shopper from their own Shopify records, which is where the order itself lives.

Trenvano does not return anything automatically, because the order and submission records described in sections 4 and 6 hold no contact details to return. The one thing Trenvano can hold about a shopper is a held order, described in section 5. If a shopper has one, and either they or the merchant asks us using the details in section 20, we will say so and provide or delete it.

customers/redact

Sent when a shopper asks for their data to be erased. On receiving it, Trenvano deletes every held order belonging to that shopper in that shop, which erases the name, phone number, address and items stored in it. The shopper's phone number and email address in the request are used to find those records by comparing keyed hashes, as described in section 5, and are not themselves stored or logged. If the request carries neither a phone number nor an email address, nothing is deleted, because a request we cannot match must erase one shopper's orders or none.

Trenvano's other records hold identifiers, totals and delivery status, with no name, phone number, address or email address, so there is nothing in them to erase.

One limitation, stated plainly: Shopify only sends this request for a shopper it knows as a customer of that store. A shopper whose only order was held never became a Shopify customer, so no request is sent for them and this route cannot reach their held order. Those orders are still deleted by the 90 day limit in section 5, and can be deleted sooner on request using the details in section 20.

Rows already appended to the merchant's Google Sheets are the merchant's own records in the merchant's own Google account, and the merchant handles those as the controller.

shop/redact

Sent 48 hours after a shop uninstalls the app. Trenvano deletes the shop and everything attached to it, including any held orders, as described in section 14.

16. Where data is processed

The Trenvano application and its database are hosted on Render in Frankfurt, Germany, which is inside the European Economic Area. Trenvano is operated from Benin, so the people who run it reach that data from outside the EEA. Shopify and Google process data on their own global infrastructure under their own terms. Where personal data leaves the European Economic Area or the United Kingdom, that transfer relies on the safeguards those providers put in place, including the standard contractual clauses where they apply.

17. Children

Trenvano is a business tool sold to Shopify merchants. It is not directed at children and we do not knowingly collect data from them. The order form is filled in by whoever is buying from the merchant's store, and the merchant is responsible for who they sell to.

18. Your rights

Depending on where you live, you may have the right to ask for a copy of your personal data, to have it corrected or deleted, to object to or restrict how it is used, and to complain to a data protection authority.

If you are a shopper, please contact the store you ordered from. They hold your order, and they decide what happens to it. Trenvano will help that merchant answer you. If your order is being held because the store has run out of its monthly allowance, you can also contact us directly using the details in section 20, and we will tell you what is stored or delete it.

If you are a merchant, contact us using the details in section 20 and we will respond within 30 days.

You may complain to the Autorité de Protection des Données à Caractère Personnel (APDP) in Benin. If you are in the United Kingdom you may instead complain to the Information Commissioner's Office, and if you are elsewhere in the European Economic Area, to your own national supervisory authority.

19. Changes to this policy

If the app starts handling data in a way this policy does not describe, this page will be updated before that change goes live, and the date at the top will change with it. Where the change affects how Google account data is used, merchants will be asked to agree to the updated policy before the new use begins.

20. Contact

Questions about this policy, or about data Trenvano holds, go to:

Operator
Yaovi Henoc Odji, trading as Trenvano
Email
support@trenvano.com
Postal address
Available on request by email. Trenvano is run by a sole trader with no registered office.
Support
Trenvano support