B2B Procurement OS

Privacy Policy

How B2B Procurement OS handles data on behalf of the Shopify stores that install it.

Last updated: 31 August 2026

1. Who this covers

This policy applies to the "B2B Procurement OS" Shopify app ("the App"). The App is installed by a Shopify merchant ("the Merchant") to run B2B/wholesale workflows. When the App processes data, it acts as a data processor on behalf of the Merchant, who is the data controller.

2. What data we access

We do not collect payment card numbers, bank details, passwords or government IDs. Buyer identity in the storefront portal is established by Shopify's own signed logged_in_customer_id — the App never asks customers to type credentials.

3. How we use it

Strictly to provide the App's features to the Merchant: showing a buyer their open balance and remaining credit, routing orders through approval workflows, generating reorder lists and quotes, and tracking sales-rep commission. We do not sell data, and we do not use it to train models or for advertising.

4. Where it is stored & retention

Operational records (approvals, edit requests, lists, events) are stored in a private PostgreSQL database hosted on Railway. Financial figures such as credit used are not copied — they are derived live from Shopify on each request, so Shopify remains the single source of truth. Records are automatically purged 180 days after they are resolved.

5. Third parties

6. GDPR & your rights

The App implements Shopify's mandatory GDPR webhooks. On request through the Merchant we can export the data held about a customer, redact a customer's data, and erase all store data when the App is uninstalled. To exercise any right, contact the Merchant you purchased from, or us at the address below.

7. Security

Access tokens are stored server-side and refreshed automatically; storefront requests are verified by Shopify's App Proxy signature and per-order ownership checks so one buyer can never see or edit another's orders. We maintain a documented incident-response process with 72-hour breach notification.

8. Contact

Email busseozgenoglu@gmail.com. We respond within 30 days.