Privacy Policy — Carrier Pickup Points

Last updated: 20 August 2026

Carrier Pickup Points (the "App") is provided by Zenfulfillment GmbH, Tempelhofer Damm 227, 12099 Berlin, Germany ("we", "us"). We also operate under the brand name Alaiko; the two names refer to the same legal entity. The App lets a shopper choose a carrier pickup point (Hermes parcelshop, DHL Packstation or DHL Postfiliale) during checkout in a Shopify store.

This policy explains what personal information the App receives, why, and who it is shared with. It applies to merchants who install the App and to shoppers who use it during checkout.

Personal information the App collects

The App consists only of Shopify checkout and admin UI extensions. It has no separate merchant-facing website or user accounts, and it runs entirely in the shopper's or merchant's browser.

Information we receive from Shopify

When you install the App, we are authorised to access the following types of personal information from your Shopify account via Shopify's APIs:

  • Orders (scope read_orders) — used by the order-details admin block to read the pickup point stored on an order.

The admin block reads order data directly in the merchant's browser through Shopify's Admin GraphQL API. Order data is not transmitted to or stored on our servers.

Information the App processes during checkout

When a shopper selects a pickup-point shipping method at checkout, the App processes:

  • the delivery address entered in checkout — street (address line 1 and 2), postal code, city and country code;
  • any address or place name the shopper types into the map search box;
  • the pickup point the shopper selects — its ID, name, address, postal code, city, country and carrier;
  • for DHL Packstation, the shopper's DHL post number (Postnummer), where the merchant has enabled this requirement;
  • the shop domain (*.myshopify.com) of the store, to attribute requests and diagnostics to the correct merchant.

The selected pickup point and post number are written back into the Shopify checkout as the order attribute zen_pickup_point. They are therefore stored by Shopify as part of the merchant's order, under the merchant's own privacy policy — not in a database of ours.

The App does not collect names, email addresses, phone numbers, payment details, IP-based location, or browsing history. It sets no cookies and contains no analytics or advertising trackers.

Diagnostic logs

The App sends application logs to our logging endpoint (https://pickup-points.main-prd.alaiko.com/logs) so we can detect and fix failures. A log entry contains a severity level, a message, a timestamp, the shop domain, and technical context such as HTTP status codes, request URLs and JavaScript error messages and stack traces.

Where a pickup-point lookup fails, the log entry also contains the delivery address, postal code, city and country used for that lookup, so the failure can be reproduced. DHL post numbers are never written to logs — only the number of characters entered.

How we use your personal information

We use this information solely to:

  • find and display pickup points near the shopper's delivery address;
  • resolve an address typed into the map search box into map coordinates;
  • record the shopper's chosen pickup point on the order so the merchant and carrier can deliver to it;
  • validate the DHL post number before checkout completes;
  • operate, secure, debug and improve the App.

We do not use this information for profiling, advertising, or automated decision-making, and we do not sell it.

The legal basis for this processing under the GDPR is the performance of a contract (Art. 6(1)(b)) for delivering the ordered goods to the chosen pickup point, and our legitimate interest (Art. 6(1)(f)) in keeping the App secure and operational for diagnostic logging. Towards merchants we act as a processor; the merchant is the controller of the shopper data described above.

Sharing your personal information

We share personal information with the following third parties, only to the extent needed to run the App:

  • Zenfulfillment GmbH (Alaiko) — operates the pickup-points API and logging endpoint at pickup-points.main-prd.alaiko.com. Hosted on Amazon Web Services in Frankfurt, Germany (eu-central-1).
  • Carrier data sources (Hermes, DHL) — the delivery address or coordinates are used to query the carriers' pickup-point directories so nearby locations can be shown.
  • Google (Google Ireland Ltd. / Google LLC) — when a shopper uses the map, the App calls the Google Maps JavaScript API and the Google Places API (New). The text typed into the search box, and a location bias derived from the delivery address, are sent to Google. Requests are restricted to Germany. See Google's Privacy Policy. The API key used is the merchant's own Google Cloud key, configured in the App's settings, so Google's terms apply between the merchant and Google.
  • Shopify — the App runs inside Shopify checkout and admin, and the selected pickup point is stored in Shopify. See Shopify's Privacy Policy.

We may also disclose personal information to comply with applicable laws and regulations, to respond to a lawful subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

Behavioural advertising

The App does not use personal information for behavioural advertising and does not share it with advertising networks.

Your rights

If you are a resident of the European Economic Area, the United Kingdom or Switzerland, you have the right to access the personal information we hold about you, to ask that it be corrected, updated or erased, to restrict or object to its processing, and to data portability. To exercise these rights, contact us using the details below.

Shoppers should direct requests to the merchant whose store they ordered from, as that merchant is the controller of the order data. We will support merchants in responding to such requests. Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact) are implemented and handled by our service.

Your personal information is processed in the European Union (Frankfurt, Germany). It may be transferred outside the EU where a shopper uses the map search, because Google may process Places API requests in the United States. Such transfers are covered by the EU standard contractual clauses and/or the EU-US Data Privacy Framework where applicable.

You also have the right to lodge a complaint with your local data protection authority. For us this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

Data retention

We do not maintain our own database of shopper orders or selected pickup points. The pickup point stored in the order attribute is retained by Shopify for as long as the merchant retains the order.

Diagnostic logs are retained for 14 days and are then deleted automatically. Request logs for the pickup-points API are retained for the same 14 days.

Google's retention of Places API request data is governed by Google's own policies.

Changes

We may update this privacy policy from time to time to reflect changes to the App, or for operational, legal or regulatory reasons. The date at the top of this policy shows when it was last revised.

Contact us

For more information about our privacy practices, if you have questions, or to make a complaint, contact us by email at support@zenfulfillment.com or by mail using the details below:

Zenfulfillment GmbH
Tempelhofer Damm 227
12099 Berlin
Germany