Privacy

Privacy Policy

How we collect, use, and protect your data. Transparent and straightforward.

Last updated: June 2026 hello@caprelease.com

1. Introduction

We are CapRelease Limited (known as "CapRelease", "we", "us", or "our"). Here's how we protect your data and respect your privacy.

This Privacy Policy applies to you if you are a CapRelease customer, a Shopify merchant using our app, a subscriber, or a visitor to our website. It describes how we collect, use, store, and share your personal data, and sets out your rights.

If you are a registered CapRelease customer or a visitor to our website, we act as the "data controller" of personal data. This means we determine how and why your data is processed.

2. Our Role in Your Privacy

Our Responsibilities

As data controller, we are responsible for ensuring your personal data is processed lawfully, fairly, and transparently. We implement appropriate technical and organisational measures to protect your data.

For most of your data we are the sole controller. The main exception is data collected through the Meta Pixel on our website: for the collection of that data and its transmission to Meta, we and Meta Platforms Ireland Limited act as joint controllers. See Section 12 for details.

Your Responsibilities

  • Read this Privacy Policy
  • If you are our customer, also review the contracts between us, including the Data Processing Agreement (available upon request at hello@caprelease.com)
  • If you provide us with personal information about other people, you confirm that you have the right to authorise us to process it on your behalf

3. When and How We Collect Data

If you are only a visitor to our website, the only data we collect before you contact us comes from cookies and similar technologies. Essential cookies are always active. Non-essential analytics and advertising technologies — Google Analytics, Microsoft Clarity, and the Meta Pixel — are not used unless and until you consent through our cookie banner. See Section 13 for the full list and how to change or withdraw your choice.

Data You Give Us

  • When you register for or use CapRelease services
  • When you install our Shopify app and grant permissions
  • When you complete identity verification (KYC) via Onfido
  • When you sign agreements via DocuSign
  • When you contact us for customer support
  • When you opt in to marketing communications

Data We Collect Automatically

  • When you browse our website (via consent-based analytics and advertising technologies — see Section 13)
  • When you use our platform or Shopify app
  • When you receive and interact with our emails

Data Collected via Shopify

When you install the CapRelease Shopify app, we access certain data from your Shopify store via Shopify's APIs and through our integration partner Codat, including store information, order data, product and inventory data, customer data, and financial data.

Data Collected via TrackStar

We use TrackStar to integrate with your warehouse management and inventory systems, accessing inventory levels, product data, stock movements, warehouse and fulfilment data for real-time visibility into your operations.

4. Types of Data We Collect

Contact Details: Your name, email address, phone number, role in your company, and business address.

Financial Information: Bank account number, sort code, Direct Debit mandate details, revenue data, and other financial metrics.

Identity Verification Data: Information collected during KYC checks via Onfido, including government-issued identity documents and facial biometric data (for document matching purposes only).

Business and Inventory Data: Product listings, stock levels, order history, sales performance, supplier information, warehouse data, and other operational metrics.

Buyer Data from Your Store: Names, email addresses, delivery addresses, and phone numbers of your customers. We use this solely to analyse purchasing patterns. We do not contact your customers or share their data for unrelated purposes.

Data That Identifies You: IP address, login information, browser type, time zone, geolocation, and operating system.

Usage Data: URL clickstreams, pages viewed, page response times, session duration, and actions taken.

Sensitive Data: We do not intentionally collect any sensitive data. Biometric data collected by Onfido is not retained by CapRelease.

5. How and Why We Use Your Data

PurposeDescriptionLegal Basis
Providing Our ServicesDelivering the platform, syncing store data, generating analyticsContract / Legitimate Interests
Shopify Data SyncAccessing store, order, inventory, and buyer data for insightsContract / Legitimate Interests
Identity VerificationKYC checks via Onfido for directors and beneficial ownersLegal Obligation
Contract ManagementSending, signing, and storing agreements via DocuSignContract
Improving CapReleaseProduct analytics, testing features, improving modelsLegitimate Interests
Website Analytics & AdvertisingGoogle Analytics, Microsoft Clarity, and the Meta Pixel on our websiteConsent
Customer SupportService notifications, issue resolutionLegitimate Interests
MarketingEmails about features and content via Mailchimp (with consent)Consent
Transactional CommsSystem notifications via Mailgun and SendGridContract / Legitimate Interests
Payment CollectionGoCardless Direct DebitContract
Legal & RegulatoryAML regulations, FCA requirementsLegal Obligation

Legal Bases Explained

Consent: Clear consent for a specific purpose. You can withdraw marketing-email consent at any time via hello@caprelease.com or the unsubscribe link, and cookie consent at any time via the Cookie settings link (see Section 13).

Legitimate Interests: Necessary for our interests, not outweighed by your rights.

Contract: Necessary for performing a contract with you.

Legal Obligation: Necessary to comply with AML, KYC, and FCA rules.

6. How We Use Your Customers' (Buyer) Data

  • What we access: Buyer names, email addresses, delivery addresses, phone numbers, and order details
  • Why: To analyse purchasing patterns including customer concentration, repeat vs new ratios, and average order values
  • What we do NOT do: We never contact your buyers, never use their data for marketing, never sell or share it
  • Retention: Only as long as necessary for our services. Deleted per Shopify redaction requirements on app uninstall
  • Buyer rights: Buyers can request access, correction, or deletion via hello@caprelease.com within 30 days

7. Your Privacy Choices and Rights

Your Choices

  • You can choose not to provide personal data (but we cannot provide services without it)
  • You can change or withdraw your cookie consent at any time using the Cookie settings link in our banner or site footer — withdrawing is as easy as giving consent
  • You can opt out of marketing via hello@caprelease.com or the unsubscribe link

Your Rights

Exercise these by emailing hello@caprelease.com:

  • Access: Request what data we hold and how we process it
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion where no longer necessary
  • Data Portability: Receive your data in CSV or JSON format
  • Object: Object to profiling or automated decision-making
  • Restrict Processing: Limit how we use your data
  • Complain: Lodge a complaint with the ICO

We respond within one month.

8. How Secure Is the Data We Collect?

  • Encryption in transit (TLS/SSL) and at rest
  • Access controls and role-based permissions
  • Regular security reviews and vulnerability assessments
  • Microsoft Azure hosting in the UK (UK South region)
  • Multi-factor authentication for sensitive systems
  • Microsoft 365 security and compliance features

If you believe your privacy has been breached, contact us immediately at hello@caprelease.com.

9. Where Do We Store the Data?

We store data primarily on Microsoft Azure servers in the UK (UK South region). We also process data through providers in the UK, EU, and US. For transfers to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge") where the recipient is certified, and on UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses, supported by a transfer risk assessment, where it is not. Data is encrypted in transit and at rest.

10. How Long Do We Store Your Data?

We archive data within 3 months of your last use. We delete it no later than 6 years after, or as agreed in a separate contract.

Identity Verification Data

Biometric data is processed by Onfido and not stored by CapRelease. Verification results retained per AML requirements (typically 5 years after the business relationship ends).

Shopify App Data

  • We cease accessing store data immediately on uninstallation
  • We respond to Shopify's deletion webhooks within 30 days
  • Data for active agreements retained as needed for legal obligations
  • Aggregated anonymous data may be retained for analytics

11. Shopify Data Compliance

We implement Shopify's mandatory compliance webhooks:

  • customers/data_request: Buyer data provided within 30 days
  • customers/redact: Buyer data deleted or anonymised within 30 days
  • shop/redact: All store and buyer data deleted within 30 days of uninstall

12. Third Parties Who Process Your Data

Data is shared only when necessary and with appropriate safeguards. For transfers to the United States, we rely on the UK-US Data Bridge where the recipient is certified, and on UK IDTAs or Standard Contractual Clauses, supported by a transfer risk assessment, where it is not. Data is encrypted in transit and at rest.

Infrastructure & Hosting

ProviderPurposeLocation
Microsoft AzureCloud hosting and data storageUK (UK South)
Microsoft 365Email, productivity, collaborationUK / EU

Platform Integrations

ProviderPurposeLocation
Shopify Inc.eCommerce platform integrationUS / Canada
Codat LimitedData aggregation from merchant platformsUK
TrackStarInventory and warehouse integrationUS

CRM & Sales

ProviderPurposeLocation
Salesforce, Inc.CRM and partner portalUS
Apollo.ioSales prospectingUS
ChilliPiperMeeting schedulingUS

Identity & Legal

ProviderPurposeLocation
Onfido LtdKYC and identity verificationUK / EU
DocuSign, Inc.Electronic signaturesUS / EU

Communications & Marketing

ProviderPurposeLocation
Mailgun (Sinch)Transactional emailUS / EU
SendGrid (Twilio)Transactional emailUS
Mailchimp (Intuit)Marketing emailsUS

Payments

ProviderPurposeLocation
GoCardless LtdDirect Debit collectionUK / EU

Website & Analytics

ProviderPurposeLocation
Webflow, Inc.Website hostingUS
Google LLC (Google Analytics)Website analytics (set only with consent)US
Microsoft Corporation (Microsoft Clarity)Website analytics and session replay (set only with consent)US

Advertising

ProviderPurposeLocation
Meta Platforms Ireland LimitedAdvertising delivery and conversion measurement via the Meta Pixel (set only with consent)Ireland (EEA)

Joint Controllership with Meta

For data collected through the Meta Pixel, we and Meta Platforms Ireland Limited are joint controllers (Article 26 UK GDPR) for the collection of that data and its transmission to Meta. We are responsible for deploying the pixel, obtaining your consent before it activates, and providing this information. Meta is responsible for its processing of the data after transmission and for handling requests relating to the data it holds. The arrangement is set out in Meta's Controller Addendum, and Meta's processing is described in Meta's Privacy Policy. Meta Ireland is in the EEA, which the UK treats as adequate; any onward transfer by Meta to the US is made under Meta's own transfer arrangements. You may exercise your data protection rights against either party.

13. Cookies

We use cookies and similar technologies, grouped into three categories: Essential (always active, no consent required), Analytics, and Marketing. Analytics and Marketing technologies are non-essential — we do not set them until you consent through our cookie banner. You can accept all, reject all non-essential cookies, or choose by category, and you can change or withdraw your choice at any time via the Cookie settings link. Withdrawing is as easy as giving consent.

NameProviderCategoryPurposeExpiry
_gaGoogleAnalyticsDistinguishes users for Google Analytics2 years
_ga_*GoogleAnalyticsPersists Google Analytics session state2 years
_gidGoogleAnalyticsDistinguishes users24 hours
_clckMicrosoft (Clarity)AnalyticsStores a Clarity user ID; recognises returning visitors1 year
_clskMicrosoft (Clarity)AnalyticsGroups a visitor's page views into one session1 day
_fbpMetaMarketingIdentifies the browser to measure and deliver advertising3 months
_fbcMetaMarketingStores the ad-click identifier; set only when you arrive from a Meta advert3 months

14. Data Protection & Contact

Email: hello@caprelease.com

Post: CapRelease Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

Company Number: 15180252 (England and Wales)

Supervisory Authority: Information Commissioner's Office (ICO)