Legal
Last updated 15 August 2026 · Tensortactic Solutions Private Limited
COD Verify is a Shopify app that verifies Cash on Delivery orders over WhatsApp and SMS, collects advance payments, sends order and delivery updates, and recovers abandoned carts. Doing that means handling personal data belonging to a merchant's customers. This page explains exactly what is handled, why, and for how long.
It covers COD Verify specifically. COD Verify is published under the CODPilot brand, which is a trading name of Tensortactic Solutions Private Limited and not a separate company — the controller and processor roles below are Tensortactic Solutions Private Limited's. Any other CODPilot product carries its own policy describing what that product handles.
When a merchant installs COD Verify, the merchant is the data controller for their customers' personal data. Tensortactic Solutions Private Limited acts as a data processor, handling that data only to provide the features the merchant has switched on.
For the merchant's own account information — store details, billing and support correspondence — Tensortactic Solutions Private Limited is the controller.
The app requests only the permissions its features use. Shopify shows this list at install.
| Permission | Why it is needed |
|---|---|
| read_orders | Detect a new order, whether it is Cash on Delivery, and what to say in the confirmation message. |
| write_orders | Tag orders as verified, unverified or auto-cancelled, and cancel orders a customer never confirms. |
| read_customers | Get the phone number to send the verification code and order updates to. |
| read_checkouts | Recover abandoned carts by messaging the customer who left one behind. |
| read_fulfillments | Send shipping and delivery updates when the courier status changes. |
| write_draft_orders | Rebuild a Cash-on-Delivery order as a draft order the customer can pay online, through your own Shopify checkout. |
| write_payment_customizations | Hide Cash on Delivery at checkout for the rules a merchant configures. |
| Category | Details |
|---|---|
| Store details | Shop domain, store name, contact email, plan, currency, timezone and locale. |
| Order records | Order number and total, payment method, fulfillment and tracking status, and the customer's name, phone number and email address. |
| Abandoned checkouts | Checkout token, cart total, and the customer's name, phone number and email address. |
| Message logs | Recipient phone number, the message body as sent, channel, delivery status, provider message id and cost. |
| Verification records | A single-use confirmation token per order, attempt count and outcome. Codes are not reusable and expire. |
| Payment links | A single-use link token and the amount requested. No card or bank details. |
| Opt-outs | Phone numbers that replied STOP, kept deliberately so they are never messaged again. |
| Provider credentials | The API keys a merchant enters for their WhatsApp, SMS and payment providers. Encrypted at rest. |
To deliver a message or take a payment, the relevant details are passed to the provider a merchant has connected. COD Verify does not sell personal data, and does not share it for advertising.
| Recipient | What they receive |
|---|---|
| The merchant's WhatsApp provider — Gupshup, or Meta's WhatsApp Cloud API | Recipient phone number and message content. |
| The merchant's SMS provider | Recipient phone number and message content. |
| The merchant's payment gateway | Order reference and amount, to create a payment link. |
| Amazon Web Services | Hosting and database storage. |
Each provider is chosen by the merchant and is subject to that provider's own terms and privacy policy.
COD Verify runs on Amazon Web Services in the Asia Pacific (Mumbai) region, and customer data is stored there. Messaging and payment providers may process data in other countries depending on the provider a merchant connects.
Order records, message logs and settings are kept while the app is installed, because they are what the merchant's reporting, billing and audit history are built from.
COD Verify implements Shopify's mandatory privacy webhooks, so a request made through the merchant's store reaches the app automatically.
A customer should contact the store they ordered from, since the merchant is the controller. Merchants can reach us directly at admin@codpilot.shop.
This marketing site sets no cookies and runs no analytics or tracking scripts. Inside the app, Shopify sets the session cookies required to keep a merchant signed in to their admin.
If what the app collects changes, this page changes with it and the date at the top is updated. Material changes affecting merchants will also be sent to the contact email on the store's account.
Tensortactic Solutions Private Limited (Private Limited Company)
2nd Floor, No. 17, 7th Main Road, II Stage Indiranagar, Bengaluru, Karnataka 560038, India
GSTIN 29AALCT6911D1Z6
admin@codpilot.shop