Privacy policy
What we store, why, for how long and how to have it removed.
Data we store for a store that installs the app
The myshopify domain, the granted scopes, the catalog snapshot, the documents you upload or forward, the lines and issues extracted from them, the rules you configure, and a minimised audit trail of actions taken.
Why we store it
Only to perform the request you made: read a purchase order, match it to your catalog and create a draft order you approved.
Where it is processed
On servers we operate in the deployment region, plus the object store holding the original files. The list of processors is on the subprocessors page.
File retention
Original files and intermediate results are kept for the retention period you choose, 7, 30 or 90 days. The minimised review summary is kept for 180 days. (7 / 30 / 90 · 180 Date)
Requests and deletion
Shopify privacy webhooks for customer data access, customer redaction and shop redaction are implemented. Uninstalling stops processing and queues deletion of the app data for the store.
Stated plainly
- It creates draft orders only.
- A person has to review and approve every document before a draft is created.
- Supported input: PDF, PNG, JPG, CSV and XLSX.
- Files are processed on our own servers in the deployment region, not in the browser and not on the merchant’s device.
- Original files and intermediate results are kept for 7, 30 or 90 days, chosen by the merchant. The minimised review summary is kept for 180 days.
We do not claim SOC 2, ISO 27001 or GDPR certification. No such certification has been obtained.