Feediqo Shopify application portfolio

Privacy Policy

This notice describes how [[TRADING_NAME]] handles personal and operational information when merchants, authorized users, buyers, customers, suppliers, advisers, or others interact with our Shopify applications and support services.

Effective [[EFFECTIVE_DATE]]Last updated [[LAST_UPDATED_DATE]]Version [[POLICY_VERSION]]

At a glance

Quick summary

Email the privacy contact

On this page

Who we are

Legal entity
[[LEGAL_COMPANY_NAME]]
Trading name
[[TRADING_NAME]]
Registration
[[COMPANY_NUMBER]], [[COUNTRY_OF_REGISTRATION]]
Registered address
[[REGISTERED_ADDRESS]]
Privacy contact
[[PRIVACY_EMAIL]]

Scope of this policy

This policy covers the eight applications listed below, their embedded administration, Shopify POS extensions where applicable, support interactions, connected integrations, and this privacy-policy website. It does not replace a merchant’s own customer privacy policy.

Processing depends on the app installed and the features, permissions, uploads, and integrations the merchant chooses. One app’s disclosure should not be read as a statement about another app.

Our privacy roles

For store, buyer, customer, supplier, order, accounting, logistics, packaging, inventory, or fiscal information used to provide an app, we may generally act on the merchant’s instructions, subject to contracts and applicable law.

We may determine purposes for account administration, billing and entitlements, security, misuse prevention, support, legal compliance, reliability, and business communications. Our role depends on the activity, relationship, contract, and law; we are not always a controller or always a processor.

Information we process

These are potential portfolio-wide categories, not a claim that every app uses every field. The “applies to” and “required or optional” columns define the boundary.

Shared operational information across the application portfolio
CategoryExamplesSourcePurposeApplicable appsRequired or optional
Merchant and installationOrganization name, shop domain, Shopify IDs, plan, capabilities, installer and authorized-user business detailsShopify and authorized usersInstall, authenticate, authorize, and operate the selected appAll eight appsRequired for installed apps
Credentials and configurationEncrypted Shopify tokens, encrypted integration credentials, app settings, roles, permissions, notificationsShopify, merchant, and selected integrationsConnect permitted systems and provide configured featuresOnly the installed app and its enabled integrationsRequired or optional by integration
Billing and entitlementsPlan, subscription state, billing events, cancellation, freeze, usage-meter recordsShopify App Store billing systemsAdminister plans, access, and usageApps that use Shopify billingRequired when a paid or metered plan applies
SupportSupport messages, merchant-provided evidence, support-session audit detailsMerchant or authorized userRespond to requests and investigate reported issuesThe app named in the support requestOptional; only when support is requested
Operations and securityFeature events, timestamps, errors, IP address, browser/device metadata, security logs, webhook IDs, audit historyUse of the selected app, infrastructure, and Shopify webhooksSecure services, prevent misuse, diagnose errors, and preserve audit trailsApps generating the relevant eventRequired, with fields minimized by event
Uploads and connected recordsFiles intentionally uploaded and data from merchant-selected integrationsAuthorized users and configured systemsProvide the feature for which the upload or integration was enabledCreditOps B2B, FulfillGuard, PackProof, OrderDesk Match, LedgerRoute, MarketQA, or StockySafe when the feature is usedOptional; feature-, upload-, permission-, or integration-dependent

Shopify normally administers App Store subscription billing. The company may receive plan, entitlement, subscription, billing event, cancellation, freeze, and usage information. Whether the company directly handles payment-card data remains a configured declaration above.

App-specific disclosures

Every application has its own disclosure. Required, optional, future, and not-used states are explicit and are not interchangeable.

App-specific disclosure

CommerceGuard Revenue Assurance

Also known as: CommerceGuard

Tests revenue-critical Shopify workflows, correlates failures with observable changes, estimates revenue at risk, and supports controlled recovery.

Current release posture

Read-first monitoring with progressive optional permissions. Write access is disabled by default; any narrow remediation requires explicit enablement, preview, approval, verification, and rollback where supported.

Information by use level

Store, catalog, and configuration

Required
Examples
shop and product IDs; Markets; inventory; discounts; theme metadata
Source
Shopify
Purpose
Discover the store and build monitoring coverage.

Synthetic journey evidence

Required
Examples
test results; redacted screenshots; timing; selected console and network errors
Source
Controlled browser runs
Purpose
Detect and investigate workflow failures.

Order-derived and customer-event metrics

Optional
Examples
aggregated order or revenue metrics; selected protected order fields; pixel events
Source
Shopify, when separately enabled
Purpose
Measure impact and verify configured journeys.

Narrow remediation data

Future
Examples
resource state; preview; approval; verification; rollback record
Source
Shopify and authorized users
Purpose
Support a future, controlled remediation feature.

Customer identity and payment secrets

Not used
Examples
customer passwords; payment credentials; unnecessary names or full addresses
Source
Not intentionally requested
Purpose
These fields are normally avoided.

Sources

  • Shopify Admin GraphQL API
  • Shopify webhooks
  • controlled synthetic journeys
  • merchant configuration
  • merchant-selected integrations

Purposes

  • Discover configuration
  • run synthetic checks
  • manage incidents
  • estimate exposure as a range
  • notify teams
  • verify recovery
  • maintain an audit trail
CommerceGuard Revenue Assurance Shopify access-scope posture
ScopeStatusWhyReview
read_products● RequiredCatalog assertions.Confirm this scope and its status against the production app configuration.
read_inventory● RequiredInventory controls.Confirm this scope and its status against the production app configuration.
read_locations● RequiredLocation-aware controls.Confirm this scope and its status against the production app configuration.
read_discounts● RequiredPromotion checks.Confirm this scope and its status against the production app configuration.
read_markets◇ OptionalMarket-aware monitoring when enabled.Confirm this scope and its status against the production app configuration.
read_themes◇ OptionalTheme monitoring pack.Confirm this scope and its status against the production app configuration.
read_orders◷ FutureOptional order-derived verification; not core initial access.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
write scopes◷ FutureNarrow remediation only; never requested during initial installation.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_COMMERCEGUARD_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • Evidence summarization
  • plausible-cause ranking
  • draft incident briefs

Limitations

  • Must show confidence and evidence
  • must not invent loss
  • must not silently change production
  • must not use customer PII for shared model training
Decisions and write access

Automated decisioning

Operational severity and risk estimates are not decisions about a person. Assumptions and confidence should be visible and overridable with an audit note.

Write access

Write access is disabled by default. Any future remediation must use narrow scopes, current-state checks, authorization, approval, idempotency, audit logging, verification, and rollback where supported.

Protected customer data posture: Confirmation required.

Minimization
  • Prefer aggregate and synthetic data
  • redact screenshots, URLs, headers, and cookies
  • mask test credentials
  • never store payment credentials
Retention and uninstall

Retention notes

  • Configuration, synthetic evidence, incidents, audit events, order-derived metrics, and secrets each require a confirmed period.

On uninstall

  • Normal app processing and active jobs stop; active sessions and connector access are revoked.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

CreditOps B2B

Reconciles Shopify B2B activity with accounting records, applies merchant-defined credit policy, and coordinates receivables work.

Current release posture

Merchant-defined policies remain authoritative. CreditOps is not a lender, factor, credit bureau, payment processor, law firm, or autonomous debt-collection service.

Information by use level

B2B company and buyer records

Required
Examples
company and location IDs; business contacts; payment terms
Source
Shopify B2B
Purpose
Reconcile accounts and apply merchant policy.

Accounting and receivables

Required
Examples
invoices; payments; credit memos; balances; overdue status
Source
Merchant-selected accounting system
Purpose
Calculate exposure and coordinate receivables.

Communications and attachments

Optional
Examples
reminders; replies; remittance records; dispute attachments
Source
Merchant users and enabled communications
Purpose
Manage collections and disputes.

AI-assisted extraction and matching

Future
Examples
classification; summaries; matching suggestions; draft replies
Source
Configured records only
Purpose
Assist reviewers if released.

Autonomous final financial decisions

Not used
Examples
unexplained limit changes; autonomous write-offs; legal threats; uncertain payment posting
Source
Not permitted
Purpose
Keep money-impacting decisions reviewable.

Sources

  • Shopify
  • merchant-selected accounting system
  • authorized users
  • buyer portal
  • merchant uploads

Purposes

  • Reconcile B2B records
  • calculate exposure and available credit
  • route orders for review
  • manage holds
  • coordinate receivables
  • track disputes and approvals
CreditOps B2B Shopify access-scope posture
ScopeStatusWhyReview
read_companies● RequiredB2B company and location reconciliation.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_orders● RequiredOrder exposure and payment-term workflows.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
write_draft_orders◇ OptionalOnly for an approved, implemented order-control workflow.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_CREDITOPS_ACCOUNTING_AND_COMMUNICATION_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • Extraction
  • classification
  • remittance matching suggestions
  • draft responses

Limitations

  • No unexplained final credit decision
  • no autonomous write-off, settlement, legal threat, or uncertain payment posting
Decisions and write access

Automated decisioning

Merchant policy determines credit and collections actions. Any automated assistance must remain explainable and subject to configured review and override controls.

Write access

Exact Shopify and accounting write behavior must be confirmed. No automatic accounting posting is claimed until implemented and approved.

Protected customer data posture: Confirmation required.

Minimization
  • Restrict buyer data to enabled workflows
  • isolate companies and locations
  • keep internal risk notes hidden from buyers
  • retain explainable money-impacting records
Retention and uninstall

Retention notes

  • Financial, communication, attachment, policy, decision, and audit records require confirmed periods and any lawful accounting exceptions.

On uninstall

  • Synchronization, collections sequences, and buyer-portal access stop; pending writes are quarantined.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

FulfillGuard

Audits 3PL invoices against effective contract rules and available Shopify, warehouse, carrier, and operational evidence.

Current release posture

Findings distinguish claim-ready, review-only, missing-evidence, unmatched, excluded, and resolved states. External claims and provider messages require merchant approval.

Information by use level

Orders and fulfillment evidence

Required
Examples
order and line IDs; SKUs; locations; fulfillments; tracking IDs
Source
Shopify and operational systems
Purpose
Match operational evidence to invoice lines.

3PL invoices and contracts

Required
Examples
invoice lines; rates; taxes; rate cards; commercial clauses
Source
3PLs, contracts, merchant uploads
Purpose
Calculate expected charges and identify variances.

Claims and provider communications

Optional
Examples
findings; claims; responses; credits; approvals
Source
Authorized users and providers
Purpose
Manage approved recovery workflows.

Assistive document analysis

Future
Examples
contract extraction; mapping suggestions; finding summaries
Source
Configured documents
Purpose
Assist human review if released.

Unrelated customer identity

Not used
Examples
customer names; emails; phone numbers; full addresses; payment information
Source
Avoided where IDs and zones suffice
Purpose
Minimize protected customer data.

Sources

  • Shopify
  • 3PL invoices
  • contracts
  • WMS and carrier systems
  • SFTP
  • email attachments
  • merchant uploads

Purposes

  • Reconcile invoice charges
  • apply contract rules
  • calculate expected charges with deterministic decimal arithmetic
  • prepare evidence packages
  • manage invoice-close, claim, response, and credit workflows
FulfillGuard Shopify access-scope posture
ScopeStatusWhyReview
read_orders● RequiredOrder-to-invoice matching.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_fulfillments● RequiredFulfillment evidence.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_products● RequiredSKU and product matching.Confirm this scope and its status against the production app configuration.
write_orders— Not usedFulfillGuard does not automatically change Shopify orders.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_FULFILLGUARD_3PL_WMS_CARRIER_ACCOUNTING_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • Contract field extraction
  • mapping suggestions
  • document classification
  • finding summaries

Limitations

  • Deterministic arithmetic is the financial source of truth
  • no unapproved claims
  • no accusations
  • missing evidence remains visible
Decisions and write access

Automated decisioning

Findings support merchant review; they do not independently determine fraud, contractual liability, or recoverability.

Write access

FulfillGuard does not automatically change Shopify orders. Provider communications and financial actions require configured authority and human approval.

Protected customer data posture: Confirmation required.

Minimization
  • Prefer Shopify IDs, merchant order numbers, hashes, tokens, country, and shipping zone
  • redact evidence exports
  • avoid unrelated customer records
Retention and uninstall

Retention notes

  • Uploaded files, contracts, invoices, findings, claims, credits, and approved evidence each require a confirmed period.

On uninstall

  • Invoice ingestion, audits, and provider communications stop; connectors are revoked.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

PackProof

Manages packaging bills of materials, supplier evidence, reporting workflows, and jurisdiction-specific packaging-compliance support.

Current release posture

Compliance-support software, not a law firm or substitute for legal advice. Legal classifications and submissions require merchant review and authority.

Information by use level

Catalog and packaging composition

Required
Examples
products; SKUs; packaging components; materials; weights; recycled content
Source
Shopify, merchant, suppliers
Purpose
Calculate packaging quantities.

Supplier and compliance evidence

Required
Examples
business contacts; declarations; certificates; specifications; registrations
Source
Suppliers and authorized users
Purpose
Maintain evidence and assess configured obligations.

Sales allocation and filing records

Optional
Examples
aggregate sales; shipments; fees; submissions; acknowledgements
Source
Shopify and selected reporting systems
Purpose
Prepare reports and preserve filing evidence.

Assistive extraction

Future
Examples
document extraction; mapping; evidence summaries
Source
Configured supplier documents
Purpose
Improve data quality if released.

Unnecessary consumer identity

Not used
Examples
consumer names; emails; full delivery addresses
Source
Aggregate allocation preferred
Purpose
Avoid customer identity.

Sources

  • Shopify
  • suppliers and packaging partners
  • merchant uploads
  • authorized users
  • merchant-selected reporting services

Purposes

  • Maintain packaging records
  • coordinate supplier evidence
  • calculate quantities
  • support configured obligation assessments
  • prepare reports
  • support audits and reduction planning
PackProof Shopify access-scope posture
ScopeStatusWhyReview
read_products● RequiredCatalog-to-packaging mapping.Confirm this scope and its status against the production app configuration.
read_markets◇ OptionalMarket-aware reporting when enabled.Confirm this scope and its status against the production app configuration.
read_orders◇ OptionalSales allocation only when required; aggregate results are preferred.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_PACKPROOF_SUPPLIER_AND_REPORTING_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • Document extraction
  • mapping
  • classification
  • evidence summaries

Limitations

  • No final legal classification
  • no unapproved filing
  • no invented supplier evidence
  • no silent change to deterministic rules
Decisions and write access

Automated decisioning

Configured rules may flag possible obligations, but merchants and advisers remain responsible for legal classifications and submissions.

Write access

Any external submission or Shopify write requires a configured feature, merchant authority, and appropriate controls; exact behavior must be confirmed.

Protected customer data posture: Confirmation required.

Minimization
  • Use aggregate sales and shipment allocation where possible
  • avoid consumer identity
  • limit evidence access by role
Retention and uninstall

Retention notes

  • Packaging evidence, supplier files, reports, filings, acknowledgements, and audit records require confirmed periods and legal exceptions.

On uninstall

  • Regulatory workflows and scheduled reports stop; supplier and Shopify connectors are revoked.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

OrderDesk Match

Ingests B2B purchase orders, extracts and maps order information, validates commercial rules, and creates controlled Shopify draft orders.

Current release posture

Uncertain fields and product matches require review under merchant policy. Draft-order creation follows configured approvals and does not silently create final orders.

Information by use level

B2B purchase orders and contacts

Required
Examples
PO number; buyer codes; quantities; prices; addresses; business contacts
Source
Configured mailbox, upload, SFTP, or API
Purpose
Structure and validate incoming POs.

Catalog and commercial rules

Required
Examples
products; SKUs; buyer aliases; prices; inventory; budgets
Source
Shopify and merchant configuration
Purpose
Map products and validate commercial rules.

ERP and accounting context

Optional
Examples
customer records; credit status; order references
Source
Merchant-selected integrations
Purpose
Support enabled approval workflows.

AI extraction and matching

Future
Examples
field extraction; product suggestions; exception classification
Source
Submitted documents
Purpose
Assist review if released.

Autonomous PO approval

Not used
Examples
silent order approval; invented prices or quantities; approval bypass
Source
Not permitted
Purpose
Keep merchant approvals authoritative.

Sources

  • Shopify
  • configured mailbox
  • PDF and spreadsheet uploads
  • SFTP or API
  • ERP, accounting, or procurement systems

Purposes

  • Ingest and structure POs
  • map buyer codes
  • convert units
  • validate quantity, price, inventory, and duplicates
  • route exceptions
  • create controlled draft orders
  • retain approval evidence
OrderDesk Match Shopify access-scope posture
ScopeStatusWhyReview
read_products● RequiredCatalog matching.Confirm this scope and its status against the production app configuration.
read_inventory● RequiredAvailability validation.Confirm this scope and its status against the production app configuration.
read_companies◇ OptionalB2B company validation when enabled.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
write_draft_orders● RequiredApproved draft-order creation.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_ORDERDESK_MAILBOX_ERP_ACCOUNTING_PROCUREMENT_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • PO field extraction
  • product-match suggestions
  • exception classification

Limitations

  • Uncertain fields require review
  • no autonomous PO approval
  • no invented quantity or price
  • no unrelated model training
Decisions and write access

Automated decisioning

Commercial validation and mapping suggestions support merchant review; approval policy remains merchant-controlled.

Write access

Controlled draft-order creation follows configured approvals. The app does not silently create final orders or bypass commercial review.

Protected customer data posture: Confirmation required.

Minimization
  • Restrict mailbox access to configured messages
  • use documents only for the requested workflow
  • limit buyer data and document access by role
Retention and uninstall

Retention notes

  • PO documents, extracted text, attachments, mappings, exceptions, drafts, and audit history require confirmed periods.

On uninstall

  • Mailbox and document ingestion stop; order creation stops and pending draft work is quarantined.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

LedgerRoute

Determines configured fiscal-document workflows and generates, validates, routes, receives, reconciles, and archives structured fiscal documents.

Current release posture

Compliance-support software, not legal or tax advice. Deterministic jurisdiction rules and configured authority govern final submissions.

Information by use level

Legal entities and tax registrations

Required
Examples
establishments; tax IDs; jurisdictions; seller and buyer company data
Source
Merchant, Shopify, ERP
Purpose
Determine configured fiscal-document workflows.

Fiscal and commercial documents

Required
Examples
orders; invoices; credit notes; taxes; totals; fiscal XML/JSON/PDF
Source
Shopify, ERP, generated records
Purpose
Generate, validate, route, and reconcile documents.

Network and authority responses

Optional
Examples
provider IDs; submissions; acknowledgements; status; errors
Source
Configured fiscal provider or authority
Purpose
Operate enabled country workflows.

Assistive mapping

Future
Examples
extraction; classification; exception summaries
Source
Configured fiscal records
Purpose
Assist review if released.

Unsupported autonomous tax conclusions

Not used
Examples
invented tax IDs; invented legal obligations; hidden validation failures
Source
Not permitted
Purpose
Keep obligations tied to deterministic rules and review.

Sources

  • Shopify
  • merchant legal and tax configuration
  • accounting or ERP systems
  • fiscal networks and providers
  • authorities

Purposes

  • Determine configured obligations
  • generate and validate fiscal documents
  • route and receive responses
  • manage corrections
  • reconcile commercial records
  • preserve required evidence
LedgerRoute Shopify access-scope posture
ScopeStatusWhyReview
read_orders● RequiredCommercial-event and document generation.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_products● RequiredLine and tax mapping.Confirm this scope and its status against the production app configuration.
read_customers◇ OptionalOnly where required for an enabled fiscal workflow.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_LEDGERROUTE_FISCAL_NETWORK_ERP_ACCOUNTING_INTEGRATIONS]]

AI status: Confirmation required. Generative AI: confirmation required.

Configured or proposed uses

  • Extraction
  • mapping
  • classification
  • exception summaries

Limitations

  • No unsupported submission
  • no invented identifiers or obligations
  • no override of deterministic country rules
  • validation failures remain visible
Decisions and write access

Automated decisioning

Configured deterministic rules may route fiscal workflows; merchants and advisers remain responsible for legal and tax decisions.

Write access

Final submissions require deterministic validation, configured authority, audit records, and the exact enabled provider behavior documented in configuration.

Protected customer data posture: Confirmation required.

Minimization
  • Limit buyer and address data to jurisdiction requirements
  • separate ordinary operational data from lawfully retained fiscal records
  • restrict archive access
Retention and uninstall

Retention notes

  • Fiscal, tax, accounting, and regulatory records may require longer jurisdiction-specific retention; every period and exception must be confirmed.

On uninstall

  • New fiscal processing and submissions stop; connectors are revoked. Required legal records may be isolated and retained while ordinary data follows deletion policy.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

MarketQA

Also known as: FulfillmentGuard MarketQA, MarketQA 2.0

Verifies approved Shopify shipping and fulfillment paths from configuration through Cart, controlled Checkout, optional order verification, and optional fulfillment verification.

Current release posture

Read-first, deterministic assurance using merchant-approved scenarios and test-address fixtures. Real customer addresses are not used by default. Browser tests stop before payment; production orders are not created by default. Cart evidence is not universal Checkout proof.

Information by use level

Store, Market, product, inventory, and shipping configuration

Required
Examples
Markets; products; locations; delivery profiles; rates; topology; configuration hashes
Source
Shopify and observable app/carrier configuration
Purpose
Resolve capability and test approved shipping paths.

Controlled scenarios and test addresses

Required
Examples
country; subdivision; city; postal code; complete test address when required; address hash; access events
Source
Merchant-approved fixtures; never automatically imported from customers
Purpose
Execute geographically meaningful tests.

Cart and controlled Checkout evidence

Required
Examples
Cart options and completeness; redacted screenshots; normalized DOM; browser status; Cart/Checkout comparison
Source
Controlled Cart and browser runs
Purpose
Evaluate the configured evidence level without completing payment.

Order, fulfillment, and actual-cost evidence

Optional
Examples
controlled order shipping line; fulfillment routing; carrier or 3PL cost
Source
Optional, separately enabled APIs and integrations
Purpose
Verify later operational stages or provide cost-backed analysis.

Assistive AI

Future
Examples
draft policies; coverage suggestions; evidence summaries
Source
Not active
Purpose
Roadmap only; not rendered as active AI.

Real customers and payment completion

Not used
Examples
real customer profiles by default; payment cards; customer passwords; production-order completion by default; raw Cart secrets
Source
Not intentionally requested for core use
Purpose
Protect customers and keep tests controlled.

Sources

  • Shopify Admin GraphQL API
  • Storefront Cart interfaces
  • Shopify webhooks and Markets
  • controlled browser workers
  • merchant scenarios and test fixtures
  • optional order, fulfillment, carrier, or cost integrations

Purposes

  • Map shipping and fulfillment topology
  • test delivery scenarios
  • compare Cart with controlled Checkout
  • optionally verify orders and fulfillment
  • detect drift
  • label evidence strength, freshness, completeness, and reproducibility
  • manage incidents and launch gates
MarketQA Shopify access-scope posture
ScopeStatusWhyReview
read_products● RequiredScenario fixtures and product context.Confirm this scope and its status against the production app configuration.
read_inventory◇ OptionalOnly when inventory affects scenarios.Confirm this scope and its status against the production app configuration.
read_locations● RequiredOrigin and routing context.Confirm this scope and its status against the production app configuration.
read_markets◇ OptionalWhen Market-aware testing is enabled.Confirm this scope and its status against the production app configuration.
read_orders◇ OptionalControlled order verification only; not needed for the core product.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_all_orders— Not usedNot required for the core product.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
fulfillment-order read scopes◇ OptionalOnly when fulfillment verification is enabled; exact production scopes must be verified.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
write scopes◷ FutureNot requested initially; any remediation would be narrow and progressive.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_MARKETQA_CARRIER_COST_AND_PRIVATE_WORKER_INTEGRATIONS]]

AI status: Not active. Generative AI: not active.

Limitations

  • Core product remains deterministic
  • future AI must not convert Cart evidence into Checkout proof
  • must not hide uncertainty, bypass approvals, complete payment, or resolve below the required evidence level
Decisions and write access

Automated decisioning

MarketQA evaluates merchant-defined operational policies, not people. Merchant users configure policies, approve baselines, make release decisions, and accept risk.

Write access

MarketQA is read-first. Any future remediation requires progressive permission, exact preview, authorization, approval, idempotency, audit logging, verification, and rollback where supported.

Protected customer data posture: Confirmation required.

Minimization
  • Use test identities; do not import customer addresses
  • encrypt complete test addresses and use hashes
  • redact screenshots, DOM, URLs, cookies, and headers
  • stop before payment and avoid production orders
  • separate observation from causality
Retention and uninstall

Retention notes

  • Separate periods are required for complete test addresses, address hashes, Cart evidence, screenshots, browser logs, DOM evidence, incidents, order evidence, fulfillment evidence, cost evidence, policies, changes, audits, support, and backups.

On uninstall

  • Scheduled tests, workers, browser sessions, Cart and Checkout verification stop; queued work is quarantined.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.

App-specific disclosure

StockySafe

Safety-first purchasing and inventory operations for suppliers, purchase orders, receiving, POS, stocktakes, transfers, replenishment, reports, migration, and synchronization.

Current release posture

Every new store begins in Shadow Mode, which simulates and validates changes but performs no Shopify inventory writes. Live Mode requires explicit authorized activation and safety checks. Commands are idempotent, auditable, and reconciled, with an emergency kill switch.

Information by use level

Catalog, locations, and inventory

Required
Examples
products; SKUs; barcodes; locations; inventory quantities; snapshots
Source
Shopify
Purpose
Synchronize operational inventory context.

Suppliers, purchase orders, and receiving

Required
Examples
supplier business contacts; supplier-product records; POs; receipts; discrepancies; attachments
Source
Authorized users, suppliers, imports
Purpose
Operate purchasing and receiving.

Inventory commands, reconciliation, stocktakes, and transfers

Required
Examples
expected values; deltas; idempotency keys; Shopify responses; counts; transfer lines
Source
App users, POS, Shopify
Purpose
Simulate in Shadow Mode and apply authorized Live Mode operations.

Sales forecasting, supplier finance, reports, migration, and Archive Vault

Optional
Examples
sales aggregates; raw order data when necessary; supplier invoices; exports; migration files; archive manifests
Source
Shopify and merchant-enabled uploads/features
Purpose
Provide enabled planning, finance, reporting, and migration workflows.

Generative AI

Future
Examples
No generative-AI feature is defined
Source
Not active
Purpose
A future release would require a policy and vendor update.

Unnecessary customer identity and payment cards

Not used
Examples
customer names and addresses when aggregates suffice; payment-card numbers; payment tokens; passwords
Source
Not intentionally requested
Purpose
Minimize protected customer data.

Sources

  • Shopify Admin GraphQL API, OAuth, webhooks, Bulk Operations, App Bridge, and POS extensions
  • authorized app and POS users
  • CSV, XLSX, Stocky exports, supplier and invoice documents
  • inventory commands, reconciliation jobs, migration and Archive Vault records

Purposes

  • Manage suppliers and POs
  • receive with barcodes and POS
  • simulate and apply inventory changes
  • reconcile commands
  • run stocktakes and transfers
  • calculate explainable replenishment recommendations
  • report and migrate records
  • maintain audit history
StockySafe Shopify access-scope posture
ScopeStatusWhyReview
read_products● RequiredCatalog and supplier-product mapping.Confirm this scope and its status against the production app configuration.
read_inventory● RequiredInventory context and reconciliation.Confirm this scope and its status against the production app configuration.
write_inventory◇ OptionalRequired only for explicitly enabled Live Mode inventory operations; Shadow Mode performs no writes.Confirm this scope and its status against the production app configuration.
read_locations● RequiredReceiving, stocktake, transfer, and POS location context.Confirm this scope and its status against the production app configuration.
read_orders◇ OptionalSales analysis and forecasting only when enabled.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
read_all_orders◇ OptionalHistorical analysis only after approval and demonstrated need.Protected customer data review may be required. Confirm this scope and its status against the production app configuration.
write_inventory_transfers◇ OptionalOnly when native transfer functionality is enabled; verify exact API schema.Confirm this scope and its status against the production app configuration.
write_inventory_shipments◇ OptionalOnly when native shipment functionality is enabled; verify exact API schema.Confirm this scope and its status against the production app configuration.
write_inventory_shipments_received_items◇ OptionalOnly when native transfer receiving is enabled; verify exact API schema.Confirm this scope and its status against the production app configuration.
Integrations and AI

Integrations

  • [[CONFIRM_STOCKYSAFE_SUPPLIER_EMAIL_NOTIFICATION_AND_STORAGE_INTEGRATIONS]]

AI status: Not active. Generative AI: not active.

Limitations

  • Average sales, weighted velocity, seasonal comparisons, reorder points, safety stock, and target inventory are explainable formulas, not generative AI
Decisions and write access

Automated decisioning

StockySafe provides explainable recommendations that users can accept, edit, dismiss, or snooze. Inventory is not changed solely by an unexplained prediction.

Write access

Shadow Mode performs no Shopify inventory writes. Live Mode requires explicit authorization and uses a centralized, idempotent command service with expected-value checks, Shopify responses, audit events, reconciliation, role and feature restrictions, and an emergency kill switch.

Protected customer data posture: Confirmation required.

Minimization
  • Use sales aggregates where possible
  • avoid read_all_orders until required and approved
  • separate suppliers from customers
  • use expiring downloads and upload validation
  • protect against CSV formula injection
  • scope every query to the authenticated shop
Retention and uninstall

Retention notes

  • Separate periods are required for suppliers, POs, receiving, inventory commands, reconciliation, stocktakes, transfers, forecasting, sales aggregates, raw orders, invoices, reports, exports, migration files, Archive Vault, audits, jobs, support, and backups.

On uninstall

  • Sessions are invalidated, Live Mode is disabled, new inventory work is blocked, pending commands are quarantined, and late duplicate mutations are prevented.
  • Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
  • Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
  • Validated Shopify privacy webhooks are processed where required.
  • Reinstall requires fresh authorization.

How we use information

Depending on the selected app and enabled feature, we use information to authenticate users; synchronize permitted data; process uploads and connected records; provide app functionality; produce calculations, findings, documents, alerts, and reports; provide support; enforce permissions and entitlements; secure services; investigate misuse; monitor reliability; maintain audit records; meet legal obligations; and handle privacy requests.

We use minimized and appropriate operational information to improve reliability and features. We will not use information for materially unrelated purposes without an appropriate notice and legal basis.

Shopify and connected services

Information may come from Shopify APIs, webhooks, App Store billing and entitlement systems, merchants, authorized users, Shopify POS, uploads, configured mailboxes, and merchant-selected accounting, ERP, WMS, OMS, 3PL, carrier, supplier, analytics, collaboration, procurement, and fiscal-network systems.

Required scopes support core functionality. Optional scopes are requested only when a relevant feature is enabled. Scope posture is shown separately for each app and must match production. Uninstall or revocation stops normal access, although rotating backups and lawfully retained records may remain temporarily.

How we disclose information

We may disclose information to Shopify as the commerce platform and App Store provider; Shopify-connected services; configured subprocessors; integrations selected by merchants; professional advisers, auditors, and security assessors; authorities where required; and parties to a corporate transaction subject to appropriate safeguards.

Configured positions: sale — Not yet confirmed; cross-context advertising sharing — Not yet confirmed; targeted advertising — Not yet confirmed. If any position is confirmed as “Yes,” an appropriate legally required choice mechanism must be implemented before publication; an email link alone may not be sufficient.

Subprocessors

Shopify is described separately as the commerce platform and App Store provider; it is not classified here as our subprocessor without legal review. We update this list when our service-provider arrangements materially change.

Configured service providers
ProviderService and dataLocations and safeguardApplies to
[[ADD_REAL_VENDOR]][[CONFIRM_VENDOR_SERVICE]]
[[CONFIRM_VENDOR_DATA_CATEGORIES]]
[[CONFIRM_VENDOR_PROCESSING_LOCATION]]
[[TRANSFER_SAFEGUARD]]
All apps

International transfers

Hosting regions
[[HOSTING_REGION]]
Backup regions
[[BACKUP_REGION]]
Transfer approach
[[CONFIRM_INTERNATIONAL_TRANSFER_STATEMENT]]

Merchant-selected integrations may process information in additional locations under their own terms. We do not assume a transfer mechanism until it is confirmed in configuration.

Retention and deletion

We retain information only for the period reasonably necessary for the stated purposes, contractual commitments, security, dispute resolution, and legal obligations. Retention may depend on the selected app, merchant configuration, jurisdiction, record type, and applicable contract.

Configured retention rules by application and record type
Applies toRecord classDefault periodTrigger and exceptions
All appsAccount, security, billing-event, webhook, support, and audit records[[CONFIRM_RETENTION_PERIOD]]Record creation, resolution, replacement, or uninstall
CommerceGuard Revenue AssuranceConfiguration snapshots, synthetic runs, screenshots/logs, incidents, audit events, order-derived metrics, and secrets[[CONFIRM_RETENTION_PERIOD]]Run, incident closure, replacement, revocation, or uninstall
CreditOps B2BB2B, accounting, credit-policy, decision, collection, communication, attachment, and audit records[[CONFIRM_RETENTION_PERIOD]]Account closure, workflow resolution, or uninstall Confirmed accounting, dispute, or legal retention may apply.
FulfillGuardUploaded invoice, contract, CSV, XLSX, PDF, SFTP, and email-attachment files[[CONFIRM_RETENTION_PERIOD]]Upload, invoice close, claim resolution, or uninstall Approved evidence, dispute, contract, or legal retention may apply.
PackProofSupplier evidence, uploads, packaging records, reports, filings, acknowledgements, and audit records[[CONFIRM_RETENTION_PERIOD]]Supersession, reporting-period close, or uninstall Confirmed regulatory retention may apply.
OrderDesk MatchUploaded or emailed POs, extracted text, attachments, mappings, drafts, approvals, and audit history[[CONFIRM_RETENTION_PERIOD]]Ingestion, order completion, rejection, or uninstall
LedgerRouteFiscal documents, commercial records, acknowledgements, errors, reconciliation links, and archived evidence[[CONFIRM_RETENTION_PERIOD]]Document or reporting-period closure, supersession, or uninstall Jurisdiction-specific fiscal, tax, accounting, audit, dispute, or legal-hold rules may require longer isolation.
MarketQAComplete test addresses and address access events[[CONFIRM_RETENTION_PERIOD]]Scenario replacement, last use, or uninstall
MarketQATest-address hashes[[CONFIRM_RETENTION_PERIOD]]Scenario replacement or uninstall
MarketQACart evidence, browser screenshots, detailed browser logs, and normalized DOM evidence[[CONFIRM_RETENTION_PERIOD]]Test completion, incident closure, or uninstall
MarketQAIncidents, scenario/policy versions, configuration snapshots, change events, approvals, and risk acceptances[[CONFIRM_RETENTION_PERIOD]]Supersession, incident closure, or uninstall
MarketQAOptional order-verification, fulfillment-verification, and actual-cost evidence[[CONFIRM_RETENTION_PERIOD]]Verification, incident closure, integration removal, or uninstall
StockySafeSuppliers, supplier contacts, purchase orders, receiving sessions, stocktakes, transfers, and supplier finance records[[CONFIRM_RETENTION_PERIOD]]Record closure, supersession, or uninstall
StockySafeCatalog/inventory snapshots, inventory commands, reconciliation evidence, and audit events[[CONFIRM_RETENTION_PERIOD]]Snapshot replacement, command reconciliation, or uninstall
StockySafeForecast snapshots, sales aggregates, and raw order data[[CONFIRM_RETENTION_PERIOD]]Calculation, replacement, feature disablement, or uninstall
StockySafeMigration files, parsed migration records, Archive Vault records, labels/PDFs, routine reports, and exports[[CONFIRM_RETENTION_PERIOD]]Import completion, merchant instruction, link expiry, contract end, or uninstall

Uninstall disables normal processing: active jobs and sessions stop, access is revoked, and secrets are deleted or queued for deletion. Ordinary data is deleted or anonymized under the policy; backups expire through rotation. Restricted, isolated records may remain for confirmed fiscal, accounting, security, dispute, or legal-hold obligations.

Security

Only controls confirmed as implemented should appear here:

  • [[CONFIRM_IMPLEMENTED_SECURITY_CONTROLS_BEFORE_PUBLICATION]]

No method of transmission or storage is completely secure.

Your privacy rights

Depending on your location, our role, the nature of the processing, and applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, appeal, opt out of sale, sharing, or targeted advertising, obtain information about relevant automated decision-making, or complain to an authority. Not every right applies in every situation.

Send a privacy request by email. Include your name, app name, Shopify shop domain, relationship to the merchant, request type, country or state, and enough information to help verify the request. Additional verification may be required.

Do not email passwords, access tokens, payment-card data, secret keys, sensitive credentials, or identity documents unless we provide a secure process.

Shopify merchant and customer requests

Merchants may contact us about their installation. A person whose information came from a merchant store should normally contact that merchant first because the merchant controls the underlying commercial relationship. We validate and process mandatory Shopify privacy requests where required, may coordinate with the merchant, and handle requests within the period required by applicable law. Lawful retention can limit immediate deletion.

Children

These apps are business tools intended for merchants and authorized business users; they are not designed for children. Merchant stores may serve different audiences, and customer information may be processed on a merchant’s behalf. We do not claim that children’s information can never enter a merchant-provided dataset. Concerns can be sent to the privacy contact.

Changes to this policy

Version
[[POLICY_VERSION]]
Effective
[[EFFECTIVE_DATE]]
Last updated
[[LAST_UPDATED_DATE]]
Material-change notice
[[MATERIAL_CHANGE_NOTIFICATION_METHOD]]

Earlier versions are kept in source control and are available on request; this website does not publish a separate archive page.

Contact and complaints

[[LEGAL_COMPANY_NAME]]
[[REGISTERED_ADDRESS]]
[[PRIVACY_EMAIL]]
Security: [[SECURITY_EMAIL]]

Complaint-authority details will be added only after the relevant jurisdictions and official authority links are confirmed.