Cordon

Privacy policy

Last updated: August 6, 2026

This policy covers two things: this website (usecordon.com) and the Cordon app for Shopify. It is written in plain language on purpose.

This website

usecordon.com sets no cookies and loads no analytics unless you explicitly consent. If you accept the analytics prompt, we use PostHog and Google Analytics to understand which pages are useful. We do not run advertising trackers and we do not sell or share visitor data with anyone.

The free store scan

If you run a store scan, we make around seven requests to pages on that store that are already public, using a user agent that identifies us. We never log in and we change nothing. The products shown in your report are passed straight to your browser and are not saved. The scan result is cached against the store address for 30 minutes so a repeat scan does not hit the store again.

If you have accepted the analytics prompt, the store address you entered is included in the analytics event, so we can see which stores the tool is useful for. If you decline, nothing is recorded.

If you ask us to email the report

Giving us your email address on the results page is optional and the full report is on screen either way. If you do, we use it to send you that one report, and it is stored by Resend, our email provider, so we can honour a later request to delete it. We forward the same report to ourselves so we can follow up if you reply. We never sell it.

There is a separate, unticked box for occasional emails about keeping a store safe. We only add you to that list if you tick it, and it is the only thing that list is used for. Every one of those emails has a one-click unsubscribe. Ticking it is not required to get your report. To be removed from everything, email support@usecordon.com and it is done the same day.

The Cordon app

Cordon inspects storefront traffic to make allow-or-block decisions for the merchants who install it. In GDPR terms, the merchant is the data controller and Cordon is a data processor. A data processing agreement is available.

What the app processes

  • IP addresses, used in memory to make the blocking decision. In the visitor log, IPs are stored only as SHA-256 hashes computed with a salt that rotates daily. Once the salt rotates, historical hashes are permanently irreversible; neither we nor the merchant can recover the original IP.
  • Request metadata: country, network operator (ASN), user-agent string, and the rule that matched. None of this identifies a person.
  • Shop configuration: the merchant's rules, presets, and plan, tied to the shop, not to any customer.

What the app never does

  • Store raw IP addresses in long-term logs
  • Read customer names, emails, addresses, or order contents
  • Sell, share, or repurpose traffic data for anything beyond blocking
  • Track visitors across different stores

Data retention

Visitor log entries expire automatically. Shop configuration is deleted after the mandated retention window when a merchant uninstalls, following Shopify's GDPR webhook requirements (shop/redact, customers/redact, customers/data_request), which Cordon implements in full.

Your rights

Under the GDPR you can request access, correction, or deletion of personal data. Because the app stores IPs only as irreversible hashes, there is usually nothing personal to retrieve, but we will answer every request. Contact support@usecordon.com.

Contact

Cordon operates from the Netherlands and serves merchants in the EU and US. For any privacy question, email support@usecordon.com.