Zvanta Blocklist — Privacy Policy
Operator: 7KGEAR, Poland (EU). Contact: support@zvanta.com. Last updated: 2026-08.
What we store
- Blocklist entries created by the merchant: an email address, phone number or delivery address of a customer, plus an optional merchant note. These are personal data of the blocked customer and are stored encrypted at rest (AES-256-GCM).
- Match fingerprints: short non-reversible hashes used to compare orders against the list. A fingerprint cannot be turned back into an email, phone or address.
- Block events: order number, matched entry type and action taken (tag / cancellation), kept for statistics for up to 13 months.
- Store credentials: the Shopify access token of the installing store, encrypted at rest.
What we do NOT store
- No order contents, payment data or customer lists are copied from the store.
- No data is sold or shared with third parties. No external analytics or advertising SDKs.
Why (legal basis)
The app processes the data solely to provide the service the merchant configured: preventing checkout and order completion for customers the merchant chose to block (legitimate interest of the merchant — fraud and abuse prevention, Art. 6(1)(f) GDPR). Buyers are shown a neutral message; the app never reveals to a buyer that they are on a list.
GDPR requests
- customers/redact: entries matching the customer's email or phone are deleted automatically and the checkout list is updated immediately.
- customers/data_request: we provide the merchant with the entries held about the customer.
- shop/redact: after uninstalling, all data of the store (entries, events, tokens) is deleted.
Retention
Blocklist entries live until the merchant deletes them (they are the merchant's register). Block events are deleted after 400 days. Uninstalling the app removes the store's access token immediately and all remaining data upon Shopify's shop/redact webhook (within 48 hours).
Hosting
Data is hosted in the EU (Hetzner, Germany/Finland). Transport is TLS-encrypted end to end.