Privacy Policy
Last updated August 16, 2026
Who we are
Requisly (“we”, “us”) provides a Shopify embedded app for merchant procurement: purchase orders, supplier collaboration, inventory reporting, and related workflows. This policy explains what data we process when a merchant installs and uses Requisly.
Contact: daultonjlee3@gmail.com (API / privacy contact registered with Shopify for this app).
Roles
For storefront customer data obtained through Shopify APIs, the merchant is typically the controller and Requisly acts as a processor on the merchant’s behalf, limited to providing the app’s features. For account and billing data about the merchant or their staff, we process that information to operate the service.
What we collect from merchants
- Shopify shop domain, install/session metadata, and OAuth access scopes (including optional
read_orderswhen granted). - Offline access and refresh tokens needed to call Shopify Admin APIs on the merchant’s behalf (stored server-side).
- Workspace data the merchant enters: suppliers, contacts, purchase orders, receipts, catalog mappings, notification settings, and similar B2B procurement records.
- Staff invite / auth identifiers for users who sign in to the merchant-facing web surfaces.
- Operational logs needed to run and secure the service (for example webhook delivery and compliance audit events).
Shopify Orders data (protected customer data)
When a merchant grants optional read_orders, we sync a read-only Orders cache for Report Builder and inventory / sell-through planning. We request Level 1 protected customer data for Order resources, line economics, and the order email Shopify requires us to match on customers/data_request and customers/redact. We do not request the Customers resource (read_customers).
We store:
- Order id and order name
- Processed date/time
- Order currency and total
- Line items: title, SKU, quantity, unit price, and variant id
- Customer Shopify id and email — used only to match
customers/data_requestandcustomers/redact - Order tags / note when needed to exclude synthetic test orders
We do not request or store customer name, phone, or address. Supplier and staff emails the merchant enters are B2B contact data for procurement, not storefront customer PII collected from Shopify Customers APIs.
How we use data
- Provide procurement, receiving, supplier-link, reporting, and inventory planning features inside Shopify Admin and related surfaces.
- Reconcile purchase-order spend with sell-through using the Orders cache when
read_ordersis granted. - Authenticate the app, enforce billing, deliver transactional notifications the merchant configures, and meet Shopify’s mandatory privacy webhooks.
We do not sell personal data. We do not use storefront customer data for advertising or unrelated profiling. Processing is limited to the purposes described here and in the product UI (for example the optional Orders scope grant for Report Builder).
Sharing
We use infrastructure processors such as hosting, database, and email delivery providers to operate Requisly. They process data only to provide those services to us. We do not sell merchant or customer data to third parties.
Retention
We retain workspace and synced Orders data while the merchant uses Requisly and the relevant features remain enabled. We delete or anonymize data when it is no longer needed for those purposes, and we honor Shopify’s mandatory compliance webhooks:
customers/data_request— compile any stored data tied to a customer when Shopify askscustomers/redact— delete matching Orders-cache rows and related recordsshop/redact/ uninstall — purge the shop’s workspace data after the required timeline
Security
Data is transmitted over HTTPS. Application data and sessions are stored in hosted databases with encryption at rest provided by our infrastructure vendors. Access tokens and service credentials are kept server-side and not exposed to the browser.
Consent, sales opt-out, and automated decisions
Requisly does not sell personal data and does not run customer-facing marketing consent flows. Automated reporting or reorder suggestions are tools for the merchant’s operations; they are not intended to produce legal or similarly significant effects on individual customers. Where laws give customers access, correction, or deletion rights, merchants (and Shopify’s compliance webhooks) are the primary path; we process those webhook requests as described above.
Merchant transparency
Merchants choose whether to grant optional Orders access. In-app copy explains that read_orders is used so Report Builder can show revenue / sell-through against procurement spend. This privacy policy is the written agreement describing that processing.
Children
Requisly is a B2B Shopify app for merchants and is not directed at children.
Changes
We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Material changes that affect Shopify protected customer data use will be reflected here before or as those features ship.