Privacy Policy
Last updated: 28 September 2026
Who controls this data
OrderHoist is a Shopify app that turns wholesale purchase orders into Draft Orders. Responsibility for personal data splits by operational role:
- The merchant is the data controller for buyer and customer personal data held in their Shopify store.
- OrderHoist is the data processor for purchase-order document contents forwarded by the merchant so a Draft Order can be created.
- OrderHoist is the data controller for merchant app configuration stored for the shop: the private routing inbox address, store preferences, and SKU alias memory.
Privacy and redaction inquiries for either role should be directed to support@getorderhoist.com.
Ephemeral document processing
Customer PDFs, scans, and spreadsheets are held in a temporary volatile processing buffer only while multimodal extraction runs. The file is permanently deleted immediately after the Draft Order is created in Shopify Admin. OrderHoist does not keep a persistent file archive, an object storage repository, or an external copy of source documents.
What we retain
We store only the minimum operational metadata needed to run the service:
- The Shopify shop domain identifier and merchant offline API session tokens.
- Private inbound routing configuration and store preferences.
- SKU alias memory: mappings between buyer shorthand and Shopify variant IDs confirmed by the merchant.
- A minimal operational log: timestamp, extracted PO number, Shopify Draft Order ID, and status (
Auto-DraftedorNeeds Review).
These records are stored securely in Supabase (managed PostgreSQL over SSL). They do not include original source documents.
Sub-processors
OrderHoist uses the following sub-processors to deliver the service:
| Sub-processor | Role |
|---|---|
| Supabase | Managed PostgreSQL database for session tokens, settings, and alias memory. |
| Railway | Cloud compute container service executing the backend app engine. |
| Inngest | Asynchronous event orchestration and queue worker execution. |
| Google Gemini API | Multimodal document extraction from the temporary file buffer. |
| Resend | Inbound email transport and webhook routing for forwarded purchase orders. |
Shopify compliance webhooks
OrderHoist complies with Shopify's mandatory GDPR and CCPA privacy webhooks. Because source documents are not retained, these actions operate on residual operational logs and alias memory:
customers/data_request— We return any operational log record tied to that customer's email.customers/redact— We delete residual customer logs and alias records linked to that customer email.shop/redact— After a store uninstalls OrderHoist and Shopify dispatches this webhook (typically 48 hours later), we permanently purge all session tokens, store preferences, alias mappings, and order logs.
GDPR and CCPA requests
Merchants and buyers may request data access, correction, or deletion at any time by contacting support@getorderhoist.com. Requests will be fulfilled against the settings store and confirmed within standard statutory timeframes.
Contact
OrderHoist · support@getorderhoist.com