Privacy Policy

Last updated: 28 September 2026

Who controls this data

OrderHoist is a Shopify app that turns wholesale purchase orders into Draft Orders. Responsibility for personal data splits by operational role:

  • The merchant is the data controller for buyer and customer personal data held in their Shopify store.
  • OrderHoist is the data processor for purchase-order document contents forwarded by the merchant so a Draft Order can be created.
  • OrderHoist is the data controller for merchant app configuration stored for the shop: the private routing inbox address, store preferences, and SKU alias memory.

Privacy and redaction inquiries for either role should be directed to [email protected].

Ephemeral document processing

Customer PDFs, scans, and spreadsheets are held in a temporary volatile processing buffer only while multimodal extraction runs. The file is permanently deleted immediately after the Draft Order is created in Shopify Admin. OrderHoist does not keep a persistent file archive, an object storage repository, or an external copy of source documents.

What we retain

We store only the minimum operational metadata needed to run the service:

  • The Shopify shop domain identifier and merchant offline API session tokens.
  • Private inbound routing configuration and store preferences.
  • SKU alias memory: mappings between buyer shorthand and Shopify variant IDs confirmed by the merchant.
  • A minimal operational log: timestamp, extracted PO number, Shopify Draft Order ID, and status (Auto-Drafted or Needs Review).

These records are stored securely in Supabase (managed PostgreSQL over SSL). They do not include original source documents.

Sub-processors

OrderHoist uses the following sub-processors to deliver the service:

Sub-processorRole
SupabaseManaged PostgreSQL database for session tokens, settings, and alias memory.
RailwayCloud compute container service executing the backend app engine.
InngestAsynchronous event orchestration and queue worker execution.
Google Gemini APIMultimodal document extraction from the temporary file buffer.
ResendInbound email transport and webhook routing for forwarded purchase orders.

Shopify compliance webhooks

OrderHoist complies with Shopify's mandatory GDPR and CCPA privacy webhooks. Because source documents are not retained, these actions operate on residual operational logs and alias memory:

  • customers/data_request — We return any operational log record tied to that customer's email.
  • customers/redact — We delete residual customer logs and alias records linked to that customer email.
  • shop/redact — After a store uninstalls OrderHoist and Shopify dispatches this webhook (typically 48 hours later), we permanently purge all session tokens, store preferences, alias mappings, and order logs.

GDPR and CCPA requests

Merchants and buyers may request data access, correction, or deletion at any time by contacting [email protected]. Requests will be fulfilled against the settings store and confirmed within standard statutory timeframes.

Contact

OrderHoist · [email protected]