Privacy Policy
Effective date: July 22, 2026
This Privacy Policy describes how Purchase Pulse ("we", "us", or "the App") collects, uses, and stores information when merchants install and use the App on Shopify.
1. Who we are
Purchase Pulse is a Shopify embedded admin app for purchase-order workflows (suppliers, purchase orders, email delivery of POs, printing / PDF export, and optional inventory receiving).
Contact: molyray630@gmail.com
2. Information we collect
2.1 Through Shopify APIs
- Shop domain and session / authentication tokens
- Product and variant data needed to build purchase orders
- Location data used as PO destinations
- Inventory quantities when merchants use receiving / transfer features
2.2 From merchants
- Supplier records (name, email, phone, address, payment terms)
- Purchase order content, notes, and email delivery logs
- Optional SMTP settings or Microsoft OAuth connection details used to send PO emails. Microsoft access and refresh tokens are encrypted at rest and are used only to send purchase-order emails from the connected mailbox.
2.3 From merchants' customers
Purchase Pulse does not collect Shopify customer personal data (names, emails, addresses, order history of end customers). The App is designed for merchant procurement operations.
3. How we use information
- Authenticate the merchant and run the embedded App
- Create, edit, print, and email purchase orders
- Update inventory when the merchant confirms receiving
- Respond to mandatory Shopify privacy webhooks
- Provide support when merchants contact us
We do not sell personal data. We do not use merchant data for advertising.
4. Storage and retention
App data is stored in a PostgreSQL database hosted by our infrastructure provider (currently Neon / Fly.io). Data is retained while the merchant uses the App.
When Shopify sends a shop/redact request after uninstall, we delete that shop's sessions, settings, suppliers, purchase orders, line items, email logs, and pending Microsoft OAuth authorization data.
5. Sharing
We share data only with infrastructure providers needed to run the App (hosting, database, and email transport configured by the merchant, including Microsoft Graph when the merchant connects a Microsoft mailbox). We do not share data with third-party advertisers.
6. Mandatory privacy webhooks
The App implements Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact.
7. Contact
Privacy questions: molyray630@gmail.com
App URL: https://purchase-pulse-moly.fly.dev