BrightLanding Privacy Policy

Operated by Arqam360 Version 1.1 — Effective 14 June 2026 Last updated: 14 June 2026


1. Who we are

BrightLanding is a Shopify application operated by Arqam360 ("Arqam360", "we", "us", or "our"). BrightLanding generates cash-on-delivery (COD) landing pages and processes COD order submissions on behalf of the Shopify merchants who install it.

This policy explains how we handle personal data in connection with the BrightLanding application. It covers two distinct relationships, which we treat differently under data-protection law:

This distinction matters: we process end-customer personal data only to provide the order-processing service to the merchant, under the merchant's instructions, and we do not use it for our own purposes.

Privacy contact: privacy@brightlanding.io


2. The data we process

2.1 Merchant account data (Arqam360 as controller)

When a merchant installs BrightLanding, we process:

We use this data solely to operate the BrightLanding service for that merchant: authenticating with their Shopify store, generating their pages, and processing their orders.

2.2 End-customer personal data (Arqam360 as processor)

When a customer submits a COD order through a BrightLanding-generated page, we process the following fields, which the customer provides:

We collect these fields for one purpose only: to create and fulfil the customer's cash-on-delivery order on behalf of the merchant. We do not use end-customer personal data for marketing, profiling, advertising, resale, or any purpose other than processing the order the customer placed.

The phone number may additionally be used for order-verification (one-time-password) messaging where the merchant enables that feature. (This verification feature is not active in the current version and is described here for transparency; see Section 9, "Changes to this policy".)


3. How we use end-customer data

End-customer personal data flows through BrightLanding for the sole purpose of creating and fulfilling the COD order:

  1. The customer submits the order form on a BrightLanding-generated page.
  2. BrightLanding validates the submission and creates the corresponding order in the merchant's Shopify store.
  3. BrightLanding stores a record of the order so the merchant can manage and fulfil it.

We process this data under the merchant's instructions, as their processor. The merchant, as controller, is responsible for the lawful basis on which the order data is collected from their customers.


4. How we protect end-customer data

All end-customer personal data is encrypted at rest. Name, phone number, email address, and delivery address are each encrypted before storage; the stored records contain only encrypted values, not readable personal data.

We store end-customer order data in a database hosted within the European Union, on infrastructure provided by Amazon Web Services (AWS), in the eu-west-1 (Ireland) region. Keeping the data in the EU means that, for customers resident in the EU, their personal data is processed and stored within the EU.

Access to the systems that process this data is restricted to the operation of the BrightLanding service.


5. Who we share data with (sub-processors)

We share end-customer personal data only with the parties necessary to deliver the order-processing service:

Sub-processor Purpose Data shared
Shopify Creating and storing the order in the merchant's own Shopify store Name, phone, email, delivery address
Amazon Web Services (AWS) (eu-west-1 / Ireland) Hosting the database that stores order records Encrypted order records

Service providers that do not process end-customer data

To generate landing pages, BrightLanding retrieves public product information (such as title, images, and description) from a product URL the merchant submits. We use the following service provider for this, which processes only the merchant-submitted URL and does not receive any end-customer personal data:

Service provider Purpose Data shared
Crawlbase Retrieving public product information from a merchant-submitted product URL, to generate the landing page The product URL only (no end-customer personal data)

We do not share end-customer personal data with analytics, advertising, or tracking providers. BrightLanding does not run analytics or tracking that collects end-customer personal data.

Future sub-processor — disclosed in advance: When the order-verification and WhatsApp-messaging features become active in a future version, a WhatsApp Business Solution Provider (BSP) will process customer phone numbers to deliver those messages. We will update this policy and identify that sub-processor, including its data-processing location, before the feature is activated. See Section 9.


6. How long we keep data

We retain end-customer order data for as long as the merchant's BrightLanding account is active and the merchant has not deleted the relevant order data. Because we act as the merchant's processor, the merchant controls the retention of their customers' order data.

When a merchant uninstalls BrightLanding from their Shopify store, Shopify sends us a shop/redact data-erasure webhook (typically within 48 hours of uninstall, and within 30 days at the outer bound under Shopify's specification). On receiving that webhook, we perform a hard delete of all end-customer order data associated with that store, including the encrypted personal-data records. We will complete this deletion within 30 days of the merchant's account termination. In normal operation, deletion completes in well under 48 hours.

Merchant account data is retained for the life of the merchant's account and deleted within 30 days of account termination, by the same mechanism.


7. Data-subject rights

End-customers have rights over their personal data under the EU General Data Protection Regulation (GDPR) and equivalent laws, including the rights to access, rectify, and erase their personal data, and to restrict or object to its processing.

Because the merchant is the controller of end-customer data, customers should direct rights requests to the merchant from whom they ordered. As the merchant's processor, Arqam360 supports these requests: when a merchant instructs us to delete a customer's order data, we action that deletion, including erasing the encrypted personal-data records we hold.

(The customer-data deletion mechanism is delivered through BrightLanding's data-handling layer. The self-service deletion interface is being finalised alongside production data-encryption key management; until then, deletion requests are actioned operationally on the merchant's instruction. See Section 9.)

Merchants, as controllers of their own account data, may exercise their rights by contacting us at privacy@brightlanding.io.


8. International data transfers

We host end-customer order data within the European Union. Where any processing necessarily involves a transfer of personal data outside the EU/EEA — for example, where a sub-processor processes data in another region — we ensure an appropriate safeguard is in place, such as the European Commission's Standard Contractual Clauses.

Shopify processes order data in accordance with its own data-processing terms and transfer mechanisms, which apply to the merchant's use of Shopify.


9. Changes to this policy

We will update this policy when BrightLanding's data handling changes. In particular, we will update it before activating the following features, and will identify any new sub-processor and its data-processing location at that time:

The current version of this policy is always served at the URL above. We will post the updated policy with a revised "Last updated" date. Prior versions are retained in our source-code repository's version history.

Version history:


10. Contact

For any question about this policy or about how Arqam360 handles personal data in BrightLanding, contact us at:

privacy@brightlanding.io

Arqam360 has not appointed a Data Protection Officer or an EU representative. Under the GDPR, neither is required given the scale and nature of our processing at this stage; we will revisit this position as the service grows.


This policy reflects BrightLanding's data handling as of version 1.0. BrightLanding is operated by Arqam360.