Privacy
Privacy and data handling
PO to Draft stores purchase-order files and extracted order data only to prepare Shopify draft orders for merchant review.
Data processed
- Uploaded purchase-order files or pasted email content.
- Extracted buyer, address, line item, price, and note fields.
- Shopify customer, product variant, and draft-order references.
- Operational audit events for review and draft creation.
Retention and deletion
Uploaded documents, extracted PO records, line items, and audit events are deleted by the scheduled retention cleanup job after 30 days by default. When a shop uninstalls the app, the app also deletes shop-owned uploaded documents, extracted PO records, line items, audit events, and Shopify sessions. Only legally necessary metadata needed to prove and retry deletion requests can be retained separately from PO content.
AI processing and service providers
Source content is sent to OpenAI for structured extraction. Model responses are requested without API response storage, and temporary uploaded user-data files are deleted after extraction. The app also relies on Shopify and the configured hosting, database, queue, monitoring, and private object-storage providers.
The app retains request-level OpenAI token counts, model, response identifier, latency, status, retry attempt, and an optional cost estimate for up to 24 months. These records use a one-way keyed shop identifier and never contain PO contents, filenames, buyer details, addresses, prompts, or API credentials.
Configured subprocessors: Shopify, OpenAI.
Shopify data
The app requests product, customer, and draft-order access only for matching and draft-order creation after merchant confirmation.
Product analytics
The app records a small set of product milestones such as landing-page visits, access intent, first upload, first processed PO, first draft, failures, and cancellation. Merchant shops are represented only by a one-way keyed identifier. Analytics never store PO contents, buyer names or emails, addresses, filenames, Shopify credentials, or API credentials. Analytics events are deleted after 395 days by the scheduled retention job.
Billing and usage records
Subscription verification stores the shop domain in a local billing snapshot while the app is installed. Monthly usage periods and accepted-upload reservations use an HMAC-derived shop identifier, not the shop domain, and never contain PO contents, filenames, buyer details, or addresses. Raw billing snapshots are deleted on uninstall or shop redaction. Pseudonymous usage periods are deleted on mandatory shop redaction or after the configured retention period, currently 24 months.
Privacy requests
Shopify privacy webhooks are recorded as auditable requests with due dates and completion status. Failed source-file deletion is retained as a retry task and surfaced to the operator.
Privacy contact: privacy@clintelio.com