Last updated 2026-05-17
CheckoutPanda (“we”, “our”) is a checkout-replacement service for Shopify merchants. We act as a data processor for shopper data on behalf of merchants and a data controller for merchant account data.
Controller for purposes of GDPR for merchant accounts: CheckoutPanda. Contact: privacy@checkoutpanda.se.
For shoppers, our processing is performed on behalf of the merchant under their lawful basis (typically performance of a contract — completing the purchase — or legitimate interest for fraud prevention and analytics). For merchants, our processing of account data is performed on the basis of performance of a contract with the merchant.
We rely on the following sub-processors. Each is contractually bound to GDPR-equivalent terms:
Under GDPR you have the right to:
To exercise these rights, contact the merchant whose checkout you used — they are the controller of your purchase data. For account-level requests, email privacy@checkoutpanda.se.
All traffic is TLS-encrypted in transit. Card data never touches our servers — it goes directly from the buyer's browser to Adyen, Stripe, or Klarna. Database storage is encrypted at rest. Webhook payloads are HMAC-verified. Access to merchant data is scoped by merchant ownership at the API layer.
We'll update the “Last updated” date at the top whenever this policy changes. For material changes we'll notify merchants by email.
This document is a baseline template provided in good faith and is not legal advice. Merchants should consult a qualified lawyer for their own jurisdiction.