Last updated: 20 August 2026
Carrier Pickup Points (the "App") is provided by Zenfulfillment GmbH, Tempelhofer Damm 227, 12099 Berlin, Germany ("we", "us"). We also operate under the brand name Alaiko; the two names refer to the same legal entity. The App lets a shopper choose a carrier pickup point (Hermes parcelshop, DHL Packstation or DHL Postfiliale) during checkout in a Shopify store.
This policy explains what personal information the App receives, why, and who it is shared with. It applies to merchants who install the App and to shoppers who use it during checkout.
The App consists only of Shopify checkout and admin UI extensions. It has no separate merchant-facing website or user accounts, and it runs entirely in the shopper's or merchant's browser.
When you install the App, we are authorised to access the following types of personal information from your Shopify account via Shopify's APIs:
read_orders) — used by the order-details admin block to read the pickup point stored on an order.The admin block reads order data directly in the merchant's browser through Shopify's Admin GraphQL API. Order data is not transmitted to or stored on our servers.
When a shopper selects a pickup-point shipping method at checkout, the App processes:
*.myshopify.com) of the store, to attribute requests and diagnostics to the correct merchant.The selected pickup point and post number are written back into the Shopify checkout as the order attribute zen_pickup_point. They are therefore stored by Shopify as part of the merchant's order, under the merchant's own privacy policy — not in a database of ours.
The App does not collect names, email addresses, phone numbers, payment details, IP-based location, or browsing history. It sets no cookies and contains no analytics or advertising trackers.
The App sends application logs to our logging endpoint (https://pickup-points.main-prd.alaiko.com/logs) so we can detect and fix failures. A log entry contains a severity level, a message, a timestamp, the shop domain, and technical context such as HTTP status codes, request URLs and JavaScript error messages and stack traces.
Where a pickup-point lookup fails, the log entry also contains the delivery address, postal code, city and country used for that lookup, so the failure can be reproduced. DHL post numbers are never written to logs — only the number of characters entered.
We use this information solely to:
We do not use this information for profiling, advertising, or automated decision-making, and we do not sell it.
The legal basis for this processing under the GDPR is the performance of a contract (Art. 6(1)(b)) for delivering the ordered goods to the chosen pickup point, and our legitimate interest (Art. 6(1)(f)) in keeping the App secure and operational for diagnostic logging. Towards merchants we act as a processor; the merchant is the controller of the shopper data described above.
We share personal information with the following third parties, only to the extent needed to run the App:
pickup-points.main-prd.alaiko.com. Hosted on Amazon Web Services in Frankfurt, Germany (eu-central-1).We may also disclose personal information to comply with applicable laws and regulations, to respond to a lawful subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
The App does not use personal information for behavioural advertising and does not share it with advertising networks.
If you are a resident of the European Economic Area, the United Kingdom or Switzerland, you have the right to access the personal information we hold about you, to ask that it be corrected, updated or erased, to restrict or object to its processing, and to data portability. To exercise these rights, contact us using the details below.
Shoppers should direct requests to the merchant whose store they ordered from, as that merchant is the controller of the order data. We will support merchants in responding to such requests. Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact) are implemented and handled by our service.
Your personal information is processed in the European Union (Frankfurt, Germany). It may be transferred outside the EU where a shopper uses the map search, because Google may process Places API requests in the United States. Such transfers are covered by the EU standard contractual clauses and/or the EU-US Data Privacy Framework where applicable.
You also have the right to lodge a complaint with your local data protection authority. For us this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
We do not maintain our own database of shopper orders or selected pickup points. The pickup point stored in the order attribute is retained by Shopify for as long as the merchant retains the order.
Diagnostic logs are retained for 14 days and are then deleted automatically. Request logs for the pickup-points API are retained for the same 14 days.
Google's retention of Places API request data is governed by Google's own policies.
We may update this privacy policy from time to time to reflect changes to the App, or for operational, legal or regulatory reasons. The date at the top of this policy shows when it was last revised.
For more information about our privacy practices, if you have questions, or to make a complaint, contact us by email at support@zenfulfillment.com or by mail using the details below:
Zenfulfillment GmbH
Tempelhofer Damm 227
12099 Berlin
Germany