Privacy Policy
for the Dingio - Telegram Order Alerts Shopify app
Last updated: 29 September 2026
This privacy policy explains how the Shopify app Dingio - Telegram Order Alerts ("the App"), operated by EpicPilot Labs ("we", "us"), handles information when you install and use it on your Shopify store.
In short: the App sends you a Telegram message when an order is placed or cancelled, or when stock runs low. It does not collect or store your customers' personal data - no names, email addresses, phone numbers, or shipping addresses are ever stored by us or included in your alerts.
1. Who we are
The App is developed and operated by EpicPilot Labs, based in Lithuania (European Union). EpicPilot Labs is the data controller for the information described in this policy.
For any question or request relating to this policy or your data, contact dingio@epicpilotlabs.com. We aim to respond within two business days. Additional registration or contact details can be provided on request.
2. Information we receive and what we send
When you install the App, Shopify grants it permission to read certain information about your store. The App subscribes to notifications ("webhooks") for events you choose to be alerted about.
What we receive
When one of your chosen events occurs, Shopify sends the App a notification containing information about that event. From it, the App uses only:
- the order ID, to prevent duplicate alerts;
- the order number;
- the order total and currency;
- the number of items in the order;
- for stock alerts: the product and variant name and the remaining stock;
- your store's name and
myshopify.comdomain.
What we do not use or store
Shopify's order notifications may technically contain personal data about your customers. The App deliberately ignores this. We do not use, store, or transmit:
- customer names;
- customer email addresses or phone numbers;
- shipping or billing addresses;
- the buyer's IP address and other technical fields;
- order notes;
- payment details;
- any other customer-identifying information.
None of this information appears in your Telegram alerts, and none of it is written to our database. Apart from the order ID and the low-stock alert state described in section 3, event data is processed in memory only, for the moment it takes to compose your alert, and is then discarded.
What Dingio sends to your Telegram chat
When an order is placed or cancelled, Dingio sends a message to the Telegram chat or group you connected. It contains the order number, the order total and currency, the number of items and your store name. Low-stock alerts contain the product and variant name, the remaining stock and your store name. Messages never contain your customer's name, email address, phone number, shipping or billing address, IP address or order notes.
Telegram is a third-party service. Messages in your chat are stored by Telegram under its own terms and are not deleted by Dingio when you uninstall the App.
3. What Dingio stores
Dingio stores: your settings (bot token, chat, which alerts are on and your low-stock threshold), the access token Shopify gives the App, the store owner's email address and your store's public contact email (both from Shopify, used only for service emails about the App), low-stock alert state per product variant, the delivery status of your recent alerts, and daily alert counts. Order IDs are kept for 7 days only, to prevent duplicate alerts. Shopify's order data includes technical fields such as the buyer's IP address; Dingio ignores them and never stores them. Dingio does not store order contents or your customers' information. The access token is deleted as soon as you uninstall the App; everything else about 48 hours later, when Shopify sends us the request to erase your store's data.
In more detail, this is what we keep in our database and why. Some of it you enter yourself; the access token and both email addresses are provided by Shopify when you install the App.
| What | Why |
|---|---|
| Your Telegram bot token | So the App can send messages through the Telegram bot you created. Stored so alerts continue to work without you re-entering it. |
| Your Telegram chat ID | To know which chat or group should receive your alerts. |
| Your store name and domain | To identify your store in your alerts and to associate your settings with your store. |
| Your alert preferences | Which alerts you enabled and your low-stock threshold. |
| Shopify session data | The access token Shopify issues so the App can operate on your store. Managed by Shopify's standard app libraries. Deleted as soon as you uninstall the App. |
| The store owner's email address and your store's public contact email | Both provided by Shopify at install. Used only to contact you about the App itself: help finishing setup, notice of a problem affecting your alerts, or an important change to the App. We do not send marketing email, and you can ask us to stop contacting you at any time. |
| Low-stock alert state per product variant | So the App knows which low-stock alerts it has already sent and does not repeat them. |
| Delivery status of your recent alerts | Whether each recent alert reached Telegram, so delivery problems can be spotted and fixed. |
| Daily alert counts | Counts of alerts sent per day, used to monitor the service. No message content is stored. |
| Order IDs | Kept for 7 days only, to prevent duplicate alerts when Shopify sends the same notification more than once. |
| Support messages | If you contact us by email or Telegram, we receive your address or username and the message you send, so we can reply. |
All of this relates to you and your store - not to your customers.
4. Do we ask for information about your customers?
No. The App does not request, use, or retain personal data about your customers or your store's visitors. We have not requested access to Shopify's protected customer data fields (name, email, phone, address).
5. How your information is used
We use the information described above solely to:
- deliver the alerts you have enabled to the Telegram chat you connected;
- remember your settings between visits;
- respond to your support requests;
- contact you about the App when it matters: finishing setup, a fault affecting your alerts, or an important change;
- diagnose technical errors and keep the App running reliably.
We do not sell, rent, or share your information for advertising or marketing, and we do not add you to a marketing mailing list. We do not use your information for automated decision-making or profiling.
6. Where your information is stored
The App runs on servers located in Frankfurt, Germany (European Union), and its database is hosted in the European Union. Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting providers.
6a. Our websites
This policy covers the App. Our websites (epicpilotlabs.com) use Cloudflare Web Analytics to count page views. It sets no cookies, does not fingerprint visitors, and does not track anyone across sites. Nothing on our websites asks you for personal data.
7. Service providers
We rely on the following providers to operate the App. Each processes only what is necessary for its function:
- Fly.io - application hosting (Frankfurt, EU).
- Neon - database hosting (EU region).
- Telegram - delivery of your alert messages to the chat you chose. Message content is limited to the fields listed in section 2.
- Shopify - the platform the App is installed on, which provides the event notifications.
- Cloudflare - website hosting and cookieless page view analytics for our public websites. Not used by the App itself.
8. How long we keep information
- Order and stock event data: order IDs are kept for 7 days, only to prevent duplicate alerts, and then deleted. For stock events, only the low-stock alert state per product variant is kept. Everything else in an event is processed in memory and discarded as soon as your alert is sent.
- Your settings and store contact details (bot token, chat ID, preferences, store name, the store owner's email and the store contact email): kept while the App is installed.
- After uninstall: when you uninstall the App, your Shopify session and access token are deleted immediately, so the App can no longer access your store. Your settings (bot token, chat ID, alert preferences, store name and both email addresses) are kept for a short grace period of about 48 hours, so that reinstalling within that time restores your setup instead of requiring you to configure Telegram again. Shopify then sends the request to erase your store's data, at which point everything associated with your store is deleted: settings, tokens, chat ID, email addresses, low-stock alert state, alert delivery status, daily alert counts, order IDs and session records. Nothing is retained. Messages already delivered to your Telegram chat are held by Telegram and are not deleted by Dingio.
- Support messages: kept in our support inbox for as long as needed to handle your request and any follow-up.
9. Data protection requests
The App supports Shopify's mandatory privacy webhooks:
customers/data_request- as we hold no customer personal data, there is nothing to provide.customers/redact- as we hold no customer personal data, there is nothing to delete.shop/redact- all data for your store is deleted.
If you would like a copy of the data we hold about your store, or want it deleted before uninstalling, email dingio@epicpilotlabs.com and we will action it.
10. Your rights
Depending on where you are located (for example, under the GDPR in the EU/EEA or the UK, or the CCPA in California), you may have rights to access, correct, delete, or export the personal data we hold about you, and to object to or restrict its processing. Since the data we hold relates to your store account, you can exercise most of these rights directly in the App: you can change the connected bot or chat, or turn alerts off. Uninstalling the App deletes your data, as described in section 8. For anything else, contact dingio@epicpilotlabs.com.
You can also ask us to stop emailing you about the App at any time, by replying to any message we send or writing to the address below.
If you are in the EU/EEA and believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority.
11. Security
Your Telegram bot token is stored in our database and is never displayed back to you or exposed to your browser after saving. All connections between Shopify, the App, and Telegram use encrypted HTTPS/TLS. Incoming notifications from Shopify are cryptographically verified before being processed. Access to our production systems is restricted to the App's operator.
Please note that the alerts themselves are delivered through Telegram and are subject to Telegram's own privacy practices and to the security of the chat or group you connect. You control which chat receives them: you can change it or turn alerts off at any time in the App, or stop them completely by uninstalling the App.
12. Children
The App is a business tool intended for Shopify merchants and is not directed at children.
13. Changes to this policy
We may update this policy as the App evolves or as legal requirements change. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated to merchants where appropriate.
14. Contact
Questions, requests, or concerns about privacy:
EpicPilot Labs
Lithuania, European Union
Telegram: @EpicPilotLabs
Email: dingio@epicpilotlabs.com
Further registration details are available on request.