This policy explains what the Shopify apps Product Multiplier!, Quantity Linker and Reorderfy (together, "the apps") process when a merchant installs them, why, for how long, and what rights merchants and their customers have. The apps are operated by Product Multiplier ("we", "us"). Contact: use the contact form at the end of this page.
1. Roles
For your store's data you are the data controller and we act as your processor under these terms and the Terms of Service. For the contact details you give us directly (for example when you register interest on this website or email support) we are the controller.
2. What we process and why
| Data | Source | Purpose | Stored? |
|---|---|---|---|
| Shop domain, an API access token, granted permissions | Shopify, on install | Authenticate the app for your store | Yes, until uninstall |
| Products, variants, SKUs, prices, costs, images, inventory levels, locations, sales channels (publications) | Shopify Admin API and webhooks | Show your catalog, link quantities, create variants and products you ask for, keep inventory in sync | Yes, while installed |
| Order and refund line items: SKU, quantity, unit price, discounts, shipping amounts, currency, order number, date, sales channel, location | Shopify order and refund webhooks | Adjust linked quantities when something sells or is refunded; sales history per variant; add bundle pack contents to an order | Yes, while installed |
| Customer name, email, phone, billing and shipping address, order notes, checkout tokens, browser/IP details | Present in Shopify's order webhooks | None. Removed before storage. | No |
| Supplier order text or screenshots you paste or upload (Reorderfy, Product Multiplier) | You | Extract SKUs, quantities and costs to restock and record purchase history | Extracted results yes; the raw text/image is processed and not kept |
| Your email address and store name when you register interest or contact support | You | Reply to you; product news if you opted in | Yes, until you unsubscribe or ask us to delete it |
We only request the Shopify permissions each app needs. None of the apps requests access to your customer records. Order and refund webhooks are used solely for the line-item fields above.
3. What we never do
- We do not sell, rent or share personal data for advertising or profiling.
- We do not contact your customers.
- We do not make automated decisions about people that have legal or similarly significant effects.
- We do not use your store's data to train machine-learning models.
4. Retention
| Data | Retention |
|---|---|
| Catalog, inventory links, settings, sales history, purchase history | While the app is installed. Deleted when Shopify sends the post-uninstall shop/redact request (48 hours after uninstall), and in any case within 30 days of uninstall. |
| Access token | Deleted immediately on uninstall. |
| Incoming order/refund webhook payloads (already stripped of customer fields) | Held in a processing queue and deleted 30 days after processing. |
| Log of privacy requests (customer ID, hashed email, order IDs, outcome) | 2 years, as evidence the request was honoured. |
| Operational logs at our hosting provider | Up to 30 days. |
5. Where data is processed (sub-processors)
| Provider | Role | Location |
|---|---|---|
| Shopify | Platform the apps run inside; source of all store data | Per your Shopify agreement |
| Render | Application hosting and PostgreSQL database | United States (Ohio) |
| Cloudflare | Hosts this website | Global edge network |
| Resend | Sends operational emails to us (sync reports, alerts). These contain no customer personal data for merchant stores. | United States |
| Groq, OpenAI, Replicate | Only when you use the extraction tools: the supplier order text or image you provide is sent for text/SKU extraction or image clean-up, then discarded by us | United States |
| Google reCAPTCHA | Spam protection on this website's forms | Global |
6. Security
- All traffic between Shopify, your browser, the apps and the database uses TLS.
- The database is encrypted at rest by our hosting provider.
- Access tokens and credentials are stored server-side only and never sent to the browser.
- Each store's data is isolated by store identifier in every query; access to production is limited to the operator.
7. Your rights and your customers' rights
You can export or delete your store's data at any time by uninstalling the app or by contacting us. We honour Shopify's mandatory privacy webhooks automatically:
- customers/data_request – we compile everything we hold about the named customer or orders and send it to you within 30 days (for merchant stores this is normally only order numbers and line items, because customer fields are never stored).
- customers/redact – we erase or anonymise everything tied to the named customer or orders.
- shop/redact – we delete all of your store's data.
Depending on where you or your customers live (for example the GDPR in the EU/UK, the CCPA/CPRA in California, or the Australian Privacy Act) you may have rights of access, correction, deletion, portability and objection. Send requests through the contact form below, choosing "Privacy request"; we respond within 30 days. You may also complain to your local data protection authority.
8. Children
The apps are business tools for merchants and are not directed at children under 16. We do not knowingly collect information from children.
9. Changes
When this policy changes materially we will update the date above and notify installed merchants through the app. Continued use after the change means you accept the new policy.
10. Contact
Use this form; it reaches the right mailbox for your question and we reply by email, normally within a few business days (privacy requests within 30 days).