Data retention policy

Last updated: 28 September 2026

Purchase-order files

Source purchase order files are not kept in long-term storage. PDFs, scans, spreadsheets, and email attachments reside only in short-lived volatile memory or an encrypted temporary bucket while Google Gemini multimodal vision extraction runs.

As soon as line-item extraction finishes and the Draft Order payload is sent to the Shopify GraphQL Admin API, the source file is permanently purged.

If temporary storage is utilized during worker queuing, an automated lifecycle policy hard-deletes the file within 24 to 72 hours at the absolute latest. OrderHoist maintains no permanent document repository or file archive on Supabase, Railway, or external storage services.

Operational database records

The Supabase PostgreSQL database retains only non-sensitive operational configuration records:

  • Shopify merchant offline access session tokens.
  • Store preferences: dedicated forwarding address slug, wholesale tag rules, and packaging multipliers.
  • SKU alias mappings: confirmed buyer shorthand linked to Shopify Variant IDs.
  • Order audit logs: inbound timestamp, extracted PO number, Shopify Draft Order ID, and processing status (Auto-Drafted or Needs Review).

OrderHoist never collects, accesses, or stores payment credentials, card numbers, or bank account credentials.

Shopify webhook lifecycles

Data retention strictly mirrors Shopify's mandatory GDPR and CCPA webhooks:

  • customers/data_request — OrderHoist returns operational log entries linked to the requested customer email address.
  • customers/redact — OrderHoist deletes database logs and records associated with that customer email address.
  • shop/redact — When a merchant uninstalls OrderHoist, Shopify sends this webhook 48 hours later. OrderHoist immediately erases that store's session tokens, configuration settings, alias memory, and processing logs.

For retention inquiries, email [email protected].