How B2B Procurement OS handles data on behalf of the Shopify stores that install it.
Last updated: 31 August 2026
This policy applies to the "B2B Procurement OS" Shopify app ("the App"). The App is installed by a Shopify merchant ("the Merchant") to run B2B/wholesale workflows. When the App processes data, it acts as a data processor on behalf of the Merchant, who is the data controller.
We do not collect payment card numbers, bank details, passwords or government IDs. Buyer identity in the storefront portal is established by Shopify's own signed logged_in_customer_id — the App never asks customers to type credentials.
Strictly to provide the App's features to the Merchant: showing a buyer their open balance and remaining credit, routing orders through approval workflows, generating reorder lists and quotes, and tracking sales-rep commission. We do not sell data, and we do not use it to train models or for advertising.
Operational records (approvals, edit requests, lists, events) are stored in a private PostgreSQL database hosted on Railway. Financial figures such as credit used are not copied — they are derived live from Shopify on each request, so Shopify remains the single source of truth. Records are automatically purged 180 days after they are resolved.
The App implements Shopify's mandatory GDPR webhooks. On request through the Merchant we can export the data held about a customer, redact a customer's data, and erase all store data when the App is uninstalled. To exercise any right, contact the Merchant you purchased from, or us at the address below.
Access tokens are stored server-side and refreshed automatically; storefront requests are verified by Shopify's App Proxy signature and per-order ownership checks so one buyer can never see or edit another's orders. We maintain a documented incident-response process with 72-hour breach notification.
Email busseozgenoglu@gmail.com. We respond within 30 days.