Privacy Policy

What personal information reaches Memorabilia Management, why it is used, and the choices available to the people it relates to.

Last updated: 4 September 2026

Who we are and who this policy covers

Memorabilia Management is operated by CDS Aviation Limited, trading as HDS App, a company registered in England and Wales under company number 06499277.

The portal is a UK business service for authorised owners and staff aged 18 or over. This policy applies to personal information handled through the portal about:

  • merchant owners, staff and other authorised workspace users;
  • customers whose details are entered by an authorised user or received through a separately approved connection;
  • people who send an enquiry or stock request; and
  • suppliers or sellers recorded in inventory, purchase or receipt documents.

CDS Aviation Limited decides how personal information is used for portal accounts, security, support and its own legal duties. Each tenant decides why it keeps and uses customer, order and business records in its workspace. For those tenant-controlled records, CDS Aviation Limited acts on the tenant's instructions to provide Memorabilia Management. Each tenant must also explain its own use of customer information in its storefront privacy notice.

Information the portal handles

Accounts and workspaces

  • Name, email address, optional phone number and sign-in details.
  • Business name, workspace, role, settings and authorised actions.

Business operations

  • Inventory, product, pricing, stock, images and listing information.
  • Orders, fulfilment, refunds, shipment and tracking records.
  • Purchase records, seller contacts, receipts and uploaded evidence.

Customers and communications

  • Names, email addresses, phone numbers, billing and delivery details.
  • Order, marketplace and fulfilment references.
  • Enquiries, stock requests, notes and communication history.

Connections and security

  • Connected-shop identifiers, permissions, encrypted Shopify installation tokens and connection health.
  • Webhook and synchronisation records, error details and audit history.
  • Authentication cookies, browser information and hashed network addresses used to prevent abuse.

Information comes from portal users, connected commerce services, tenant storefront forms and technical records created when the service is used. Authorised users can add information to notes and uploads. They must only add sensitive information or identity documents where it is necessary, lawful and authorised, and must not collect more than the business purpose requires.

Why information is used

  • Create accounts, authenticate users and maintain separate tenant workspaces.
  • Manage inventory, products, images, purchases, receipts and audit history.
  • Publish and synchronise catalogue products and stock with Shopify.
  • Process orders, support fulfilment and respond to customer enquiries or stock requests.
  • Protect the portal, limit abusive requests, diagnose faults and maintain reliable service.
  • Respond to support, privacy, regulatory or legal requests.

The portal is an operations service. This release has no newsletter signup, subscriber-management or campaign-sending feature. It does not process customer card payments, run advertising, track users for marketing, or use personal information for automated profiling or decisions with legal or similarly significant effects.

What happens when a shop is connected

A tenant can authorise the Memorabilia Management Shopify app for its own store. The connection uses Shopify's authorisation process and is bound to that tenant and shop.

  • The released connection requests product, publication, inventory and location permissions only.
  • The portal keeps the shop domain and Shopify shop ID, granted permissions, encrypted expiring access and refresh tokens, and connection and webhook status.
  • Product and inventory information is received through Shopify APIs and signed catalogue webhooks.
  • The portal does not request, load, display or store Shopify orders, customers, refunds, fulfilment, tracking, contact details or addresses. Merchants manage those records in Shopify Admin.
  • A future feature requiring Shopify protected customer data would need Shopify approval, an explicit service release and an updated privacy notice before it could be enabled.
  • Disconnecting or uninstalling clears installation tokens. Shopify's signed mandatory privacy requests are accepted without retaining their request payload in the catalogue-only service. If legacy matched data exists, the applicable redaction process anonymises it.

Who may receive information

Information is made available only where needed to operate the service:

  • authorised users within the tenant workspace;
  • Shopify, when the tenant chooses to connect its Shopify store;
  • Supabase, which provides database, authentication and file-storage services;
  • Railway, which hosts and runs the portal;
  • Cloudflare Turnstile, which protects public forms from abuse; and
  • professional advisers, regulators or public authorities where disclosure is required.

These providers may process information outside the UK where their infrastructure or support services require it. Where UK law treats this as a restricted transfer, CDS Aviation Limited uses an applicable safeguard, such as UK adequacy regulations or approved contractual protections. Current provider and transfer details can be requested through thesupport page.

Keeping the service working safely

The portal uses a small number of technologies needed to provide and protect the service:

  • authentication cookies keep authorised users signed in;
  • a short-lived, signed cookie links a Shopify connection to the correct browser, user, tenant and shop; and
  • Cloudflare Turnstile receives technical request information to check that public forms are not being abused.

Access controls, tenant and role checks, audit records and protected server credentials are used to reduce unauthorised access. Shopify installation tokens are encrypted before storage. No analytics, advertising or session-replay cookies are used. No online service can remove every security risk.

How long information is kept

Information is kept only while it is needed to operate the workspace, provide requested services, protect the platform, follow a tenant's instructions, resolve disputes, or meet applicable legal and regulatory duties. The period depends on:

  • Account and workspace information is kept while the service is active. After a verified closure request, information that is not required for another reason is deleted or anonymised as soon as reasonably possible.
  • Transaction, receipt, tax and accounting records, including the customer and order details needed to understand them, are normally kept for six years from the end of the relevant financial year.
  • Support, security, audit, webhook and synchronisation records are kept for the shortest period needed for their purpose and are reviewed at least annually. Records connected to an incident, dispute or legal claim may be kept for longer while that matter remains open.
  • Shopify credentials are cleared when a connection is disconnected or uninstalled. Mandatory Shopify privacy requests do not create a retained copy of their payload. If legacy matched personal or channel data exists, an applicable redaction request anonymises it.
  • Deleted information may remain in restricted backups until the provider's normal backup cycle overwrites it. Backup copies are used only for recovery and are not returned to normal use.

Records are deleted, anonymised or restricted when they are no longer needed. A deletion request can be limited where information must still be kept for legal obligations, fraud prevention, security, disputes or legal claims.

Your information and your choices

Depending on the circumstances and applicable law, a person may ask to:

  • receive a copy of their personal information;
  • correct information that is inaccurate or incomplete;
  • delete information or restrict how it is used;
  • receive portable information in an appropriate case; or
  • object to particular uses of their information.

Your right to object

You may object on grounds connected with your situation where personal information is used on the basis of legitimate interests. We will consider the request and stop that use unless there is a compelling lawful reason to continue.

These rights are not absolute and can depend on the reason the information is used. If your request concerns a purchase or account with a tenant's Shopify store, contact that merchant first. The merchant controls that customer relationship and can send an applicable Shopify privacy request to connected apps.

Questions, requests and complaints

Privacy requests are handled by HDS App on behalf of CDS Aviation Limited. Email harry@hdsapp.co.uk or use the support page. No Data Protection Officer has been appointed.

Please explain whether you are a portal user, a tenant's customer or an enquirer so the request can be routed correctly. Identity may need to be checked before personal information is disclosed or changed.

If a concern is not resolved, you can complain to the Information Commissioner's Office or another data-protection regulator that applies to you.

This policy may be updated when the service, connected providers or legal requirements change. The date at the top shows the latest revision.