Order2Supplier
Order2Supplier

Privacy Policy

Order2Supplier uses the minimum Shopify data needed to route orders to suppliers and deliver supplier order files.

Data we process

We process the shop domain, Shopify order ID and number, product and variant IDs, SKU, product and variant titles, and quantity. We also store supplier names, supplier email addresses, product-to-supplier mappings, uploaded supplier templates, template column mappings, generated supplier files, subscription status, and delivery logs.

Data we do not request

The current product does not request or store customer names, customer email addresses, phone numbers, shipping addresses, billing addresses, payment details, or other protected customer data.

How data is used

Data is used only to split orders by supplier, generate supplier-specific CSV or XLSX files, send those files, show delivery status, enforce the selected plan, prevent duplicate processing, and operate and secure the service.

Template mapping

Template headers are read inside Order2Supplier. Merchants manually choose and confirm the five required field mappings before a template is enabled.

Service providers

We use infrastructure providers for hosting, PostgreSQL database storage, transactional email, and error monitoring. They process only the data needed to provide their service under appropriate security and confidentiality terms.

Retention and deletion

Active-store data is retained while the app is installed and needed to provide the service. Uninstalling the app deletes sessions and shop-owned application records, including suppliers, mappings, templates, generated files, logs, and subscription cache. Encrypted infrastructure backups may retain deleted records for up to 30 days before automatic expiry. Shopify privacy webhooks are supported.

Security and contact

Secrets are stored in environment variables, traffic uses HTTPS in production, and access is authenticated through Shopify. For privacy requests, email support@order2supplier.app.