Floormode / Trust & privacy

Floormode
Privacy Notice

How we handle the data behind your operations.

Version: 7 September 2026

Who operates Floormode

Floormode is operated by P&H Cloud Solutions UG (haftungsbeschränkt), Lotte-Pulewka-Strasse 47, Apartment 7113, 14473 Potsdam, Germany (commercial register HRB38151P, Amtsgericht Potsdam). For privacy questions or requests, email support@p-h.solutions.

This notice covers the Floormode Shopify and standalone applications, APIs, and customer tracking and returns pages. It does not cover other P&H products or replace the privacy notice of the merchant whose store you use.

Merchants decide which orders to manage and which operational features and connections to enable. For customer, order and warehouse data processed on their instructions, the merchant is the controller and P&H acts as processor (or subprocessor where the merchant acts for another controller). P&H is controller for its own account administration, business correspondence, service security and legal obligations. Contact the merchant first about its use of your order data; you may also contact us for help directing your request.

Information we process

Merchant and staff information includes shop identifiers and domains; installation, plan and settings information; account identifiers, names and email addresses; organisation memberships, roles, invitations, warehouse assignments and records of staff actions.

Order and customer information includes customer and order identifiers, names, email addresses, delivery addresses and telephone numbers; purchased products, quantities, prices, tax and refund amounts; fulfillment details, shipping documents and tracking references. The available fields depend on the merchant, Shopify and the access Shopify permits.

Warehouse records include products, stock levels and movements, warehouse locations, scans, picking and packing activity, parcel and customs information, shipment status and associated staff actions.

Returns and communications can include order lookup details, return reasons, customer notes, contact email, evidence images, return-label references, refund or exchange information, and notification recipients, message content and delivery status.

Technical information includes authentication and session data, encrypted connection credentials, request and error information, service logs, operation identifiers and IP addresses used to protect public pages. Map features process delivery address components and resulting coordinates.

We receive information from merchants and their staff, Shopify, users of tracking and returns pages, and connected services such as carriers. Please avoid unnecessary personal or sensitive information in notes and images. Order IDs, tracking references and other operational records can still be personal data when linked to an individual.

Purposes and legal bases

On merchant instructions, Floormode authenticates users, imports and manages orders, organises warehouse work, maintains inventory, creates shipping documents, tracks deliveries, handles returns and related refunds or exchanges, sends configured service messages, and provides operational reports and privacy-request tools. The merchant is responsible for the legal basis for this processing and for informing its customers and staff.

For P&H’s own processing under the GDPR, we use account and contact information to enter into and perform a contract with an individual merchant (Article 6(1)(b)). Where a person acts for a business, we rely on our legitimate interest in administering that business relationship and supporting its authorised users (Article 6(1)(f)).

We handle support and business correspondence to respond to enquiries and operate customer relationships. Depending on the relationship, the basis is contractual necessity or our legitimate interest in providing effective support (Articles 6(1)(b) and 6(1)(f)). We use technical and access records to investigate faults, prevent abuse and protect the service, relying on our legitimate interest in service reliability and security (Article 6(1)(f)). Processing necessary to meet applicable legal duties relies on Article 6(1)(c).

Account and operational information needed for a requested feature must be supplied for that feature to work. Optional connections can remain disabled. Installing the app does not constitute blanket consent for unrelated processing.

Merchants can configure rules that automate operational actions, including order routing and shipping-service selection. These rules follow the merchant’s configuration. Questions about a merchant’s decisions, including any consequences for a customer or employee, should be directed to that merchant.

Services and recipients

Cloudflare provides hosting, application databases, object storage, message processing, caching and technical logging. Shopify supplies store and order data and receives authorised updates. WorkOS supports standalone sign-in, organisation and team management, and API authorisation.

When a merchant connects and uses shipping services, those services receive the sender and recipient, address, parcel or freight, customs and reference information needed for the requested operation. Supported integrations include Sendcloud, EasyPost, ShipEngine/ShipStation API, Uber Freight, DHL Parcel DE, UPS and Hermes. An aggregator may pass information to the selected carrier. The actual services used depend on the merchant’s connections and the requested operation.

PrintNode, when connected and used, receives selected document contents and printer/job information to print labels and other documents. Resend receives sender and recipient addresses, subjects and message contents when email sending is configured.

Email providers also process delivery events. Where click tracking is enabled for the sending domain, Resend rewrites email links through its redirect service, including resend-links.com. Following such a link sends a request to Resend before forwarding you to the intended page. Resend can record the click against the message, including the link, time, IP address and browser information. These provider records can show delivery and link activity; they do not establish that a person read or understood a message.

Geoapify, when configured and used for order maps, receives address components for geocoding and coordinates for a static map. Floormode stores the resulting coordinates with the order. Without a configured geocoding provider, this feature does not send addresses to another geocoder.

Optional Zonos landed-cost calculations use origin and destination countries, currency, customs item details and shipping amounts. The calculation request does not include the customer’s name, email or street address.

Enabled P&H integrations and merchant-authorised API clients receive the operational information needed for the integration or requested operation. Clients can retain information they retrieve under their own arrangements. Support enquiries include information you choose to send to our support service.

Providers acting on our behalf process information to deliver their services. A carrier or service contracted directly by a merchant may have a separate role and its own terms; it is not automatically our subprocessor. Information may also be disclosed when required by law or to handle legal claims. Contact us for the provider and processing details applicable to your Floormode use.

Processing locations and transfers

Our providers operate internationally, and Floormode processing is not limited to Europe. Cloudflare and WorkOS offer international processing services. Resend states that account data, email metadata, logs and API records are stored in the United States even when emails are sent from its Ireland region.

Cloudflare’s standard self-service terms incorporate its data processing addendum; WorkOS and Resend also incorporate their processing addenda into their subscription or service agreements. These addenda provide standard contractual clauses for covered transfers outside the EEA where applicable. The linked provider documents explain these safeguards. Contact support@p-h.solutions for a copy of the relevant transfer documentation and information about the arrangements applying to your use. Merchant-contracted services provide details of their own transfers under their terms.

Retention and deletion

Operational records are kept to provide the merchant’s ongoing order, inventory, fulfillment and returns workflows and their history. Orders, shipments, shipping documents, returns, evidence and many staff/warehouse records do not have a general automatic age-based expiry. Their deletion depends on the merchant’s instructions, privacy requests, account/channel closure and the status of related workflows. The merchant should set a retention policy appropriate to its business and contact us where separate deletion handling is needed.

Scheduled cleanup makes eligible successful delivery and ingest records, and eligible webhook receipts, removable after generally 30 days; specified failed records after 90 days. Applied integration receipts are eligible after 90 days. Event history is eligible after 365 days. Eligibility is measured from the relevant receipt, event or settlement time; unresolved work can defer removal.

For terminal notifications, the recipient, subject and body are eligible for removal after 90 days from creation, while delivery status records may remain. Stored email-effect request content is eligible for removal after one day; settled effect-claim records after 180 days. Completed or redacted privacy-request records are eligible after 90 days from completion or redaction. Cleanup runs in batches, so these are eligibility thresholds rather than exact deletion deadlines.

Customer erasure clears specified customer and contact fields and related message contents and removes linked return evidence. Some financial, operational, tracking and audit records remain. We do not describe all remaining identifiers as anonymous. Notes, shared documents, historical records and copies held by other services may need separate review and deletion handling.

To help prevent delayed imports or repeated order updates from restoring erased contact information, erasure handling may retain a separate, minimal set of replay-protection records. These contain hashes of customer identifiers, normalised email addresses and order keys; the original order identifier where needed to process pending work; the erasure cutoff; and technical record identifiers and timestamps. The markers do not store the original customer name, email address, phone number or delivery address. They are pseudonymous, not anonymous, and are retained for this protection until the tenant database is destroyed rather than expiring with the privacy-request record. Order markers protect the specific erased orders. Customer and email markers use the erasure cutoff to distinguish historical orders from independent new purchases created afterward, which can be processed normally.

Uninstalling the last active channel initiates application-database cleanup after required connected-workflow cleanup. Shop redaction additionally removes linked return evidence and relevant registry/account links. A tenant with another active channel is handled separately. A shared WorkOS user account is not automatically deleted when one shop is removed.

Business correspondence and account-administration records are retained according to the ongoing relationship, outstanding enquiries, legal duties and the need to establish or defend legal claims. Provider logs, backups and provider-held copies follow their applicable retention and deletion arrangements. App cleanup does not itself delete merchant downloads or every provider copy. Contact us for record-specific retention information or a deletion request.

Cookies, public pages and security

Standalone sign-in uses the secure, HttpOnly app_session cookie with a 24-hour expiry and a seven-day refresh ceiling from login. The app_oauth_tx cookie lasts ten minutes and protects the sign-in transaction. Blocking necessary authentication storage can prevent sign-in. Shopify and configured sign-in providers also operate their own authentication mechanisms.

Customer tracking pages may show a merchant-supplied logo from an external host. Loading that image can disclose browser request metadata, including the IP address, to that host. Public-page protection uses IP-based and order-based request limits.

Floormode separates tenant databases, checks access permissions, verifies Shopify webhook signatures and encrypts stored integration credentials. Return evidence is retrieved through authenticated app access. These measures reduce risk; they do not guarantee absolute security.

Your rights and contact

Depending on the applicable law and circumstances, you can request access, correction, erasure, restriction or portability of your personal data. You can object to processing based on legitimate interests, and withdraw consent where processing relies on consent; withdrawal does not affect prior lawful processing.

For a store’s order data, contact the merchant or ask us to help direct the request. Authorised merchants can use Floormode’s privacy-request queue and export tools, review additional records and evidence, and deliver the response securely. Downloading an export does not automatically send it to the customer. We may need information to verify your identity and identify the relevant account or merchant.

For P&H’s own processing, contact support@p-h.solutions or write to the address above. You can also complain to a competent data protection authority, including the authority where you live or work. P&H’s local authority is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany.

We update this notice when the described processing changes. The version date identifies the text you are reading.

Provider documentation and complaints