PackFlow - Returns
Last updated: 12 August 2026
Timmgard GmbH (“we”, “us”, “our”) operates the PackFlow - Returns Shopify application (“the App”), which provides merchants with a customer-facing returns portal and DHL return label generation. This Privacy Policy describes how we collect, use, store, and protect personal data when merchants and their customers use the App. The Terms of Service governing the use of the App are available at https://tg-ai.de/en/apps/packflow-returns/terms-of-service.
Provider and data controller within the meaning of Art. 4(7) GDPR for the operation of the PackFlow - Returns app as a software service is:
Timmgard GmbH
Kurhausstraße 78a
53773 Hennef, Germany
Commercial Register: HRB 17527 (Amtsgericht Siegburg)
VAT ID: DE359202464
Authorised Representative: S. Timm
Email: [email protected]
Contact form: https://tg-ai.de/en/kontakt - response guaranteed within 24 hours
For the processing of customer data in the course of individual return requests, Timmgard GmbH acts as processor under Art. 28 GDPR; the controller in that respect is the merchant (shop owner).
We process personal data in three categories: merchant data, customer data (accessed on behalf of the merchant via the Shopify Admin API), and technical analytics data.
We use the collected data exclusively to provide the App's functionality:
Where Timmgard GmbH processes personal data as controller (in particular merchant data and technical operations data), processing is based on the following legal grounds:
Where PackFlow processes customer data on behalf of the merchant (Art. 28 GDPR), the merchant is the controller; determining the legal basis for that processing (typically Art. 6(1)(b) GDPR - handling the return as part of the purchase contract) is the merchant's responsibility.
We share personal data only with the sub-processors listed below. Each is engaged under a data processing agreement per Art. 28 GDPR; the full DPA is available at https://tg-ai.de/en/dpa/packflow-returns. We do not sell, rent, or share personal data with any other third parties for marketing, advertising, or profiling purposes.
Shopify Inc., 151 O'Connor Street, Ottawa, Ontario K2P 2L8, Canada, is our primary sub-processor. All order, customer, product, fulfillment, returns, and draft order data originates from and resides at Shopify; PackFlow accesses it via the Shopify Admin API. As Merchant of Record, Shopify also handles merchant billing. Transfers outside the EEA are safeguarded by the adequacy decision for Canada (Decision 2002/2/EC) and EU Standard Contractual Clauses per Implementing Decision (EU) 2021/914 within the Shopify DPA.
DHL processes data via three distinct APIs, each limited to the minimum fields required:
DHL processes this data on EU infrastructure according to its own privacy policy.
Render Services Inc., 525 Brannan St, Suite 300, San Francisco, CA 94107, USA, is the hosting provider for the application and the PostgreSQL database. Primary server location: Frankfurt, Germany (EU). Render is certified under the EU-US Data Privacy Framework since 6 January 2025; subsidiarily, EU Standard Contractual Clauses 2021/914 apply. Render operates the infrastructure but does not actively process personal data on our behalf beyond storage. Database backups are encrypted.
Resend Inc., 2261 Market Street, San Francisco, CA 94114, USA, sends the App's transactional emails (return confirmation, label email, optional rejection notice, merchant notification) using the sender address [email protected]. The sending infrastructure is located in the EU (Ireland, AWS eu-west-1); account metadata and sent logs reside on US infrastructure. Resend is certified under the EU-US Data Privacy Framework since March 2025; subsidiarily, EU Standard Contractual Clauses 2021/914 apply.
The App infrastructure and the database operate exclusively within the EU (Frankfurt, Germany). Transfers to third countries occur only with the sub-processors listed in Section 5 and are safeguarded as follows:
Supplementary technical and organisational measures (transport encryption, access restrictions) apply.
PackFlow implements appropriate technical and organisational measures under Art. 32 GDPR:
The following retention periods apply:
PackFlow does not carry out any automated individual decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects.
PackFlow processes return data on behalf of the merchant for customers who have previously placed an order with the shop. Age verification at the point of sale is the merchant's responsibility. The App does not collect data directly from minors and is not directed at children under 16 within the meaning of Art. 8 GDPR.
If you are a customer of a merchant using the App, you have the following rights regarding your personal data:
Note on the right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.
To exercise these rights, please contact the merchant (shop owner) directly as they are the controller. The merchant can forward data subject requests to us, which we handle via Shopify's mandatory compliance webhooks.
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for Timmgard GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2-4
40213 Düsseldorf, Germany
Timmgard GmbH is not required to appoint a data protection officer under Section 38(1) of the German Federal Data Protection Act (BDSG) because it has fewer than 250 staff and no core activity involving large-scale regular monitoring or the processing of special categories of data. Privacy requests are handled centrally at [email protected] and answered within the statutory deadlines (Art. 12(3) GDPR, generally no longer than 30 days).
The App implements all Shopify-required GDPR compliance webhooks:
The App does not set cookies or use browser local storage for identification. Authentication within the embedded admin is handled via Shopify session tokens.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the App after changes constitutes acceptance of the updated policy.
For questions about this Privacy Policy or data processing:
For data subject requests, please contact the merchant (shop owner) who installed the App on their Shopify store.