Gooval Privacy Policy

Effective Date: July 21, 2026

Last Updated: July 21, 2026

1. Overview

This Privacy Policy explains how Gwofy HK Limited ("we", "us", or "our") collects, uses, stores, and safeguards merchant data through the Gooval plugin application service when merchants install and use this application.

Gooval is a plugin application service. Our role with respect to merchants is that of a technical service provider that monitors and tracks order and logistics data. We access and process the relevant data solely for the purpose of providing data monitoring and tracking services.

This Policy applies to all data accessed by us after a merchant installs Gooval from the Shopify App Store and completes the authorization.

2. Roles and Data Relationship

In the data processing relationship:

  • The merchant (i.e., the Shopify store operator) is the data controller and determines the types of data collected in its store.
  • Gwofy HK Limited is the data processor, accessing only the data strictly necessary to provide order and logistics data monitoring and tracking services to the merchant.
  • Our relationship with the merchant is a technical service relationship for data monitoring and tracking, and does not involve any transfer of data ownership.

3. Data We Collect

After a merchant authorizes Gooval in Shopify, we access the following data within the merchant's store as necessary:

  • Order data: order number, order time, product information, order amount.
  • Logistics data: carrier name, tracking number, shipment status.
  • Recipient information: recipient name and shipping address (used only as required for logistics tracking).
  • Store basic information: store domain, store owner email address.

We only access the data scopes expressly authorized by the merchant in Shopify. Gooval does not access any data that the merchant has not authorized.

4. Purpose of Data Use

We use the data collected only within the following scope:

  • Monitoring order fulfillment status and tracking logistics updates.
  • Providing the merchant with technical service results related to orders and logistics.
  • Performing data verification required for the service benefit processing flow.
  • Other data processing necessary to perform our cooperation agreement with the merchant.

We do not use the data for:

  • Marketing or advertising to third parties.
  • Any purpose unrelated to monitoring and tracking orders and logistics.
  • Selling or exchanging the data with any third party.

5. Data Sharing

We only exchange data with necessary third parties in the following limited circumstances:

  • Carrier APIs: To query shipment status, we submit the tracking number to the corresponding carrier system.
  • Cloud service providers: To store and operate our service, we use cloud services with appropriate data security capabilities.
  • Legal requirements: Where mandated by law, we may disclose necessary information to competent authorities.
  • Financial institution partners: We partner with financial institution partners to support risk assessment and review of service benefit fulfillment. To comply with cross-border data transfer requirements, we do not directly transmit identifiable personal data to financial institution partners across borders. Service benefit request records are deidentified and recorded as hash values on a public blockchain. Financial institution partners independently verify the authenticity and integrity of request records through on-chain data.

Except for the circumstances described above, we do not share merchant data with any third party.

6. Data Storage and Protection

We take the following measures to protect data security:

  • Encryption in transit using HTTPS / TLS.
  • Encryption or masking of sensitive fields at rest.
  • Role-based access control so that only authorized personnel can access necessary data.
  • Regular backup and log auditing.

Data retention period:

  • While the merchant uses Gooval, relevant data is retained to provide the service.

Blockchain storage:

  • On-chain content: Only de-identified hash values and classification codes (including benefit fulfillment category, processing status, amount range, and date) are recorded. No personally identifiable information is stored on-chain.
  • Off-chain content: Recipient names, shipping addresses, contact information, order details, tracking numbers, and all other personally identifiable information are stored in a locally protected database and are not transmitted on-chain.
  • Verification mechanism: Financial institution partners verify the integrity of request records by comparing on-chain hash values, without needing access to the original personal data.
  • Since on-chain data has been de-identified and cannot be used, alone or in combination with other information, to identify an individual, this data is not subject to the right of erasure described in Section 7 of this Policy.

7. Merchant Rights

The merchant has the following rights with respect to its data:

  • Right of access: to learn what data we have collected.
  • Right of rectification: to request correction of inaccurate or incomplete data.
  • Right of erasure: to request deletion of identifiable personal data stored in our local database (uninstalling the application will trigger deletion). De-identified on-chain hash data and classification codes are not subject to this right as they are immutable and do not constitute identifiable personal information.
  • Right to withdraw authorization: to revoke the data access authorization granted to Gooval in Shopify at any time.

To exercise the above rights, please contact us using the information provided in Section 8.

8. Contact Us

If you have any questions about this Privacy Policy or about our data processing

practices, please contact us through the following means:

  • Company Name: Gwofy HK Limited
  • Registered Address: ROOM C05, FLAT A, 2/F, TONTEX INDUSTRIAL BUILDING, 2-4 SHEUNG HEI STREET, SAN PO KONG, HONG KONG
  • Email: contact@gooval.io

9. Policy Updates

We may revise this Policy in light of business adjustments or changes in laws and regulations. The revised Policy will be published on the Gooval application page or the merchant backend, and the merchant will be notified before it takes effect. Merchants are encouraged to review this Policy periodically.