1. Who we are
PasteOrder ("we", "us", "our") is a Shopify app that turns purchase orders from a merchant’s wholesale buyers into Shopify draft orders. The app is operated by Conversion Guard LLC, registered at 2525 W. Grand Ronde Ave, Kennewick, WA.
Questions about this policy: privacy@pasteorder.com.
2. What data we collect
From Shopify, when you install the app
- Shop domain and basic store details (store name, contact email, currency, plan).
- Shopify access token, the credential Shopify issues so the app can read your catalog, companies and customers and create draft orders. It is encrypted at rest with AWS KMS and never leaves our systems.
- Catalog data: product and variant titles, SKUs, barcodes, options, vendors, product types, tags, prices, stock levels, images and, if you configure one, a pack-size metafield. A searchable snapshot of your catalog is stored so lines can be matched quickly.
- Company, company location, company contact and customer records are looked up live in Shopify when a purchase order is processed and when you search for a buyer. We store only the Shopify IDs of the buyer chosen for each import, plus the display name shown in the app.
Access scopes: write_draft_orders, read_products, read_inventory, read_companies, read_customers. No order history is read.
Protected customer data
The app requests Shopify’s protected customer data access at Level 2, limited to name, email and address. Purpose: identifying which company, location or customer a purchase order is for. Email addresses found in the document are matched against company contacts and customers, and ship-to addresses are compared with company location addresses. No phone numbers are requested or used.
What your staff paste or upload
- Purchase order text and files (pasted text, PDF, XLSX, CSV). The original is stored encrypted in AWS S3 for the retention period you choose (see section 6). It may contain your buyer’s business contact details.
- Redacted line text: before any text is analysed by the matching service or stored on a line record, email addresses, phone numbers and tax identification numbers (such as CPF, CNPJ, NIF or RFC) are removed, and street addresses are removed from all line-level analysis.
Generated while the app works
- Matching decisions: for each line, the catalog candidates considered, the chosen variant, confidence scores, flags (price mismatch, quantity rule, stock, pack size), and the answers returned by the matching service with the question-set and model version.
- Corrections: what your staff changed, which builds the per-buyer alias memory (a normalized product phrase mapped to a variant ID).
- Staff member ID from the Shopify session token, recorded on each import and correction.
- Column mappings for spreadsheets, remembered per buyer and header layout.
- Allowance records: one row per draft order created, used for plan limits. We never store card or payment details; Shopify handles billing.
What we do not collect
- No phone numbers.
- No email addresses, phone numbers or tax identification numbers are ever sent to the matching service.
- No order history from your store.
- No passwords or admin credentials beyond the Shopify access token.
3. How we use your data
| Data | Purpose |
|---|---|
| Shop domain, access token | Authenticate requests, read the catalog, create draft orders |
| Catalog snapshot | Retrieve candidate products for each line |
| Purchase order text and files | Parse lines; show the original beside the review table |
| Buyer IDs | Attach the draft order to the right company location or customer; price lines from their price list |
| Matching decisions and corrections | Show confidence and flags; learn your buyers’ product names; measure accuracy |
| Staff member ID | Attribute imports and corrections inside your own store |
| Allowance records | Enforce plan limits |
We do not use your data for advertising and we do not sell or rent it.
4. Third-party processors
TypeSafe AI (matching)
Redacted purchase order text, spreadsheet headers and sample values, and the titles and SKUs of candidate products from your catalog are sent to TypeSafe AI (San Francisco, United States) for its Jev decision model, which returns typed choices with probabilities. TypeSafe does not train on customer requests. We are putting a Data Processing Agreement and zero data retention in place with TypeSafe.
Email addresses, phone numbers and tax identification numbers are removed before sending. Street addresses are always removed from line-level requests. They reach document-level requests only if you turn on address matching in Settings, which is off by default; it exists to tell a company’s locations apart when the ship-to block is ambiguous.
Amazon Web Services
All infrastructure runs on AWS in the us-east-2 region: DynamoDB (the records above), S3 with KMS encryption (original documents, catalog snapshots), Lambda, EventBridge and KMS. Data leaves this region only for TypeSafe’s API.
Shopify
As a Shopify app we operate inside Shopify’s platform; Shopify’s privacy policy governs the data it holds about you and your buyers.
5. Data sharing
Data is shared only with the processors above and only to operate the app. We may disclose data if required by law or to protect the rights and safety of users and third parties.
6. Retention and deletion
- Original documents: 30 days by default. In Settings you can choose not to keep them (deleted within an hour of processing) or to keep them 90 days. Deletion is enforced by storage lifecycle rules and an hourly sweep. A change applies to documents imported after it.
- Redacted line text, matching decisions, corrections, aliases, pack sizes and column mappings: kept while the app is installed, because they are what makes matching improve over time.
- On uninstall: processing stops when Shopify sends
app/uninstalled. When Shopify sendsshop/redact(48 hours after uninstall), we delete every record and file for the store, including the catalog snapshot. - Customer requests: on
customers/redactwe delete every import linked to that customer ID, including its lines, decisions and original document. Oncustomers/data_requestwe report the import IDs that reference the customer; we hold no customer data beyond Shopify IDs. - On request: email privacy@pasteorder.com to delete your import history early. We act within 7 business days of receiving the request.
7. Your rights
Shopify compliance webhooks
| Webhook | Our response |
|---|---|
customers/data_request | We report which imports reference the customer’s Shopify ID; no other customer data is held. |
customers/redact | Imports linked to the customer are deleted. |
shop/redact | All data for the store is deleted within 48 hours. |
GDPR (EU and UK) and LGPD (Brazil)
You may access, correct, delete, restrict or port the personal data we hold, and object to processing. Contact privacy@pasteorder.com.
CCPA (California)
You may know what personal information we collect and how it is used, request deletion, and opt out of sale (we do not sell personal information). Contact privacy@pasteorder.com.
8. Security
- Shopify access tokens are encrypted at rest with AWS KMS; documents and snapshots are encrypted in S3 with KMS.
- All traffic uses TLS. API endpoints require a Shopify session token; webhooks are verified with Shopify’s HMAC signature.
- The storage bucket blocks all public access; documents are served to your staff through short-lived signed links.
- Every read is scoped to the store identified by the session token; the client never supplies a store identifier.
- The app writes only draft orders. Nothing from a pasted document can change anything other than the draft’s line items and notes.
If you believe your data has been compromised, contact privacy@pasteorder.com immediately.
9. Children’s privacy
The app is for merchants operating commercial stores. We do not knowingly collect data from individuals under 18.
10. Changes
We update the date above when this policy changes and notify merchants in the app or by email for material changes. Continued use after an update means acceptance.
11. Contact
- Privacy: privacy@pasteorder.com
- Support: support@pasteorder.com
- Post: Conversion Guard LLC, 2525 W. Grand Ronde Ave, Kennewick, WA