Privacy

Privacy and data handling

PO to Draft stores purchase-order files and extracted order data only to prepare Shopify draft orders for merchant review.

Data processed

Retention and deletion

Uploaded documents, extracted PO records, line items, and audit events are deleted by the scheduled retention cleanup job after 30 days by default. When a shop uninstalls the app, the app also deletes shop-owned uploaded documents, extracted PO records, line items, audit events, and Shopify sessions. Only legally necessary metadata needed to prove and retry deletion requests can be retained separately from PO content.

AI processing and service providers

Source content is sent to OpenAI for structured extraction. Model responses are requested without API response storage, and temporary uploaded user-data files are deleted after extraction. The app also relies on Shopify and the configured hosting, database, queue, monitoring, and private object-storage providers.

The app retains request-level OpenAI token counts, model, response identifier, latency, status, retry attempt, and an optional cost estimate for up to 24 months. These records use a one-way keyed shop identifier and never contain PO contents, filenames, buyer details, addresses, prompts, or API credentials.

Configured subprocessors: Shopify, OpenAI.

Shopify data

The app requests product, customer, and draft-order access only for matching and draft-order creation after merchant confirmation.

Product analytics

The app records a small set of product milestones such as landing-page visits, access intent, first upload, first processed PO, first draft, failures, and cancellation. Merchant shops are represented only by a one-way keyed identifier. Analytics never store PO contents, buyer names or emails, addresses, filenames, Shopify credentials, or API credentials. Analytics events are deleted after 395 days by the scheduled retention job.

Billing and usage records

Subscription verification stores the shop domain in a local billing snapshot while the app is installed. Monthly usage periods and accepted-upload reservations use an HMAC-derived shop identifier, not the shop domain, and never contain PO contents, filenames, buyer details, or addresses. Raw billing snapshots are deleted on uninstall or shop redaction. Pseudonymous usage periods are deleted on mandatory shop redaction or after the configured retention period, currently 24 months.

Privacy requests

Shopify privacy webhooks are recorded as auditable requests with due dates and completion status. Failed source-file deletion is retained as a retry task and surfaced to the operator.

Privacy contact: privacy@clintelio.com