Panaché Privacy Policy
Last updated: September 27, 2026
Panaché – Mixed Wine Cases ("Panaché", "the app") is a Shopify app published by Alexandre KHEFIF-DERAIN, individual (registration in progress), 15 boulevard de Verdun, 59000 Lille, France ("we"). Contact for any question about your data: support@getpanache.app.
This policy explains what data the app processes, why, how long it is kept and what your rights are. It is intended for merchants who install Panaché and, for information, for their customers.
1. What Panaché does
Panaché lets a merchant sell wine by the case (for example 2, 4 or 6 bottles). The app shows a gauge in the cart and on product pages, blocks at checkout the orders whose number of bottles doesn't make an allowed case, suggests products to complete the case and gives the merchant statistics.
2. Merchant data we keep
When you install Panaché, we keep, for the store:
- the store address (myshopify domain), its name, its email address and the admin language;
- the access token issued by Shopify, required for the app to work;
- your Panaché plan, installation and trial dates;
- your settings (case sizes, products in scope, messages…);
- sales statistics: for each order, its ID, date, currency, whether it contains cases and the amount of products added from the app's suggestions; the daily number of checkouts where the case message was displayed;
- a technical log (app events, without any data about your customers) and the list of emails we sent you.
This data is used to run the app, show you your statistics, send you service emails (welcome, setup, trial end, monthly summary) and help you if there is a problem. Legal basis: performance of our contract (terms of service) and, for the technical log and alerts, our legitimate interest in providing a reliable service.
3. Your customers' data
Panaché does not store any personal data about your customers.
- The checkout rule runs on Shopify (Shopify Functions): it reads the cart content and, where relevant, the tags of the logged-in customer to apply exemptions. None of this data is sent to us.
- The storefront script runs in the customer's browser; it queries Shopify (not our servers) to describe the products in the cart.
- When an order is placed, Shopify sends us the order (
orders/createwebhook). We only keep the order ID, date, currency and lines (product, quantity, price). The customer's name, email address, postal address and phone number are neither stored nor logged. - The app's web pixel counts, at checkout, how often the case message is displayed. It only sends the store address and the type of message, without any customer identifier. It only runs if the customer has accepted analytics (the store's consent banner).
For this reason, you (the merchant) are the controller of your customers' data; we act as a processor for these technical operations (see the data processing agreement).
4. Uninstall survey
If you uninstall Panaché, we may send you an email with a short survey. Your answers (reason, optional comment) are stored anonymously: they are not linked to your store; only your plan and how long you used the app are kept with them. Please don't include personal data in the comment.
5. Retention
- Store data, settings and statistics: as long as the app is installed. After uninstalling, Shopify asks us to delete the store's data (within 48 hours): it is then erased.
- Technical log: the last 200 events per store.
- Uninstall survey answers: kept anonymously.
- Erasure requests forwarded by Shopify for a customer: the statistics lines of the orders concerned are deleted.
6. Processors and hosting
| Provider | Role | Data location |
|---|---|---|
| Shopify | Platform, app billing, running the checkout rule | As per Shopify |
| Railway | Hosting of the app and its database | West Europe region (Netherlands); company established in the United States |
| Mailjet (Sinch) | Sending service emails | European Union |
Where data may be accessible from a country outside the European Union, the transfer is covered by the European Commission's standard contractual clauses, provided for in Railway's data processing agreement.
7. Security
Communications are encrypted (HTTPS); the database only accepts encrypted connections; secrets are kept outside the code; access to data is limited to the people who need it for the service. Our hosting provider states that data is encrypted at rest.
8. Cookies
The app doesn't set cookies on the storefront. In the Shopify admin, the app uses Shopify's authentication. The web pixel respects the consent choices of the store's customers.
9. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object and port your data. Write to us at support@getpanache.app. You can also lodge a complaint with your data protection authority (in France, the CNIL, www.cnil.fr). Your customers can exercise their rights with you; Shopify forwards us the requests that concern us and we handle them.
10. Changes
We may update this policy; the date of the last update is shown at the top of the page. For any significant change, we will let you know by email or in the app.