Privacy Policy
Last updated: September 26, 2026
This policy explains what information the B2B Supercharge Shopify app collects, why we collect it, who we share it with, how long we keep it and how to ask us to delete it. It covers the app, and the B2B Supercharge website where noted.
1. Who we are
B2B Supercharge is a Shopify app built and operated by B2B Supercharge, a Canadian company ("B2B Supercharge", "we", "us"). In this policy, "merchant" means a Shopify store that installs the app, including the store owner and staff who use it. "Buyer" means a merchant's business customer, such as a company contact who signs in to the merchant's store.
For any privacy question or request, email support@b2b-supercharge.com.
2. What the app does
The app adds business-to-business features to a Shopify store. Merchants choose which modules to turn on:
- Quote Management: buyers request quotes on the storefront, merchants price them in the Shopify admin, and buyers accept them. Quotes are Shopify draft orders, with branded PDF quotes and quote emails.
- Order Approval: orders above a threshold are held for an approver at the buyer's company, who approves or rejects them from the customer account.
- User Management: merchants and company admins add company contacts and assign roles, including by CSV import.
- QuickPad / OrderPad: fast ordering by SKU for signed-in buyers.
- Wishlist: buyers save products to named lists, download a PDF and share a list by link or email.
- POS B2B Orders: staff ring up company orders in Shopify POS.
Shopify remains the system of record for customers, companies, orders and draft orders. The app reads and writes that data through Shopify's APIs and keeps a limited copy in its own database so the features work quickly and reliably.
3. Our role for each type of data
Merchant data. For information about merchants and their staff (for example, the store's account details and who installed the app), B2B Supercharge decides how the data is used. We act as a controller (GDPR) and a business (CCPA/CPRA).
Buyer data. For information about a merchant's buyers, the merchant decides how it is used, and we process it only to provide the app to that merchant. We act as a processor (GDPR) and a service provider (CCPA/CPRA) on the merchant's behalf. The merchant's own privacy policy governs how the merchant uses its customers' data. Buyers who want to exercise their rights should contact the merchant first. We will help the merchant respond.
4. Information we collect
4.1 Merchants (store owner and staff)
| Information | Source | Why we need it |
|---|---|---|
| Store details: store name, domain, myshopify domain, store email, customer-facing email, store owner name, phone, address, currency, time zone and Shopify plan | Shopify, when the app is installed and when the store is updated | To identify the store, format prices and dates, and address emails and PDFs correctly |
| Staff session details: Shopify user ID, first and last name, email, whether the user is the account owner, and Shopify access tokens | Shopify, when a staff member opens the app | To authenticate staff inside the Shopify admin and call Shopify's APIs for the store |
| App settings: branding, logo, PDF sender details (name, address lines, phone), email sender settings, notification settings, and optional custom SMTP credentials | The merchant, in the app settings | To brand quotes, PDFs and emails and to send email from the merchant's own mail server if chosen |
| Sales rep name and email on a quote, and staff comments on quotes | The merchant, in the app | To show who owns a quote and keep the quote's history |
| Billing and module records: which modules are enabled, trial dates, Shopify subscription status | The app and Shopify Billing | To turn modules on and off and charge through Shopify |
| Support emails you send us | You | To answer you |
We do not receive merchants' payment card details. App charges are billed through Shopify.
4.2 Buyers (the merchant's customers)
We process this data on the merchant's behalf. Some of it is stored only in Shopify and read when needed. Some is copied into the app's database.
| Information | Where it lives | Why the app uses it |
|---|---|---|
| Customer ID, email, first and last name | Shopify, with a copy in the app database | To recognise a signed-in buyer and link them to their company |
| Company, company location and company contact records, and contact role assignments (for example "Ordering only" or "Location admin"), including company and location names and external IDs | Shopify, with a copy in the app database | To decide what each buyer can see and do, such as who can approve orders or manage users |
| Phone number and addresses (default shipping address and saved addresses) | Shopify only. Read when a buyer opens the quote form and held in server memory for up to 5 minutes | To prefill the quote request form |
| Quote contents: products, quantities, prices, totals, taxes, shipping line, notes, PO number, status and dates, plus comments between buyer and merchant | Shopify draft order, with a copy in the app database | To list, price, send and track quotes |
| Quote PDFs | Generated by the app and stored in file storage at an unguessable link | To let the merchant and buyer download the quote |
| Approval requests: buyer name and email, company and location name, order contents and total, approver, decision and rejection reason | App database, with approval status also written to the Shopify draft order | To route orders to the right approver and record the decision |
| Wishlists: list names, saved products, sharing settings, and the email addresses a buyer shares a list with | App database | To save, share and export lists, and suggest recent recipients |
| Contacts added by CSV import: name, email, company location and role | Created in Shopify. The file's rows pass through our background job service while the import runs | To create company contacts in bulk |
| Order data for approvals, quotes and POS orders | Shopify. Read when needed and not stored as a separate order table | To apply payment terms, detect converted quotes and complete approvals |
| Shopify event notifications (webhooks) about companies, contacts, customers, draft orders, orders and products | App database, for a limited time (see section 8) | To keep the app in step with Shopify and to retry failed updates |
| In-progress OrderPad lines | The buyer's own browser (local storage) | So a buyer does not lose an order they are building |
People who open a shared wishlist link do not need an account, and the app does not collect information about them. The app does not place advertising cookies on a merchant's storefront and does not sell buyer data.
4.3 Technical information
When the app runs, our hosting provider records standard server logs, such as request paths, timestamps, status codes and IP addresses. Our own log lines and error reports identify the store (by internal store ID) and the operation that ran. We also record a product analytics event when a quote changes status. That event contains the Shopify customer ID, store ID, quote number, status, total, currency, item count and company location ID. It does not include names or email addresses.
5. How we use information and our legal bases
We use information only to provide, secure, support and improve the app, to bill for it, and to meet legal obligations. We do not use buyer data for our own marketing, and we do not sell personal information.
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Providing the app's features to the merchant, including processing buyer data | Performance of our contract with the merchant. For buyer data, we act on the merchant's instructions, and the merchant is responsible for its own legal basis. |
| Sending quote, approval and wishlist emails that the merchant has turned on | Performance of contract, on the merchant's instructions |
| Billing through Shopify, trials and module access | Performance of contract |
| Security, fraud and abuse prevention, error monitoring and troubleshooting | Legitimate interests in keeping the app secure and working |
| Understanding how features are used, so we can improve them | Legitimate interests, using limited, non-contact data (section 4.3) |
| Answering support requests | Performance of contract and legitimate interests |
| Keeping records required by law and responding to lawful requests | Legal obligation |
7. International transfers
B2B Supercharge is based in Canada. The app is hosted in the United States, and our providers may process data in the United States and other countries. Those countries may have different data protection laws from yours. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses and the UK equivalent included in our providers' data processing terms.
8. Retention and deletion
We keep information only as long as we need it for the purposes in this policy.
| Information | How long we keep it |
|---|---|
| Store, buyer, quote, approval, wishlist and settings data in the app database | While the app is installed. Deleted when the app is uninstalled (below) |
| Shopify event notifications (webhooks) | 7 days after they are processed successfully, or 90 days if processing failed or the event was not needed. Deleted sooner if the app is uninstalled |
| Background job records | 90 days |
| Email delivery records (used so each email is sent once) | 90 days, or until uninstall |
| Cached store settings | Up to 1 hour |
| Buyer form prefill (name, email, phone, addresses) | Up to 5 minutes, in server memory only |
| Server logs, error reports, job history at our job provider, and analytics events | For the limited periods set in each provider's retention settings, then deleted |
When a merchant uninstalls the app
When Shopify tells us the app has been uninstalled, we turn off every module and delete the store's data from the app database: the copies of companies, locations, contacts, role assignments and customers, and all quotes, quote comments, PDF records, approval requests, approver assignments, wishlists, wishlist items and share records, settings, staff sessions, email delivery records and stored webhook events. This runs automatically in the background as soon as the notification is processed.
We keep a minimal record of the store (its Shopify ID, domain and the store details Shopify provided), marked as uninstalled, and the history of which modules used a free trial. This lets a reinstall start cleanly and stops a free trial from being used twice. Data in the merchant's Shopify store, such as draft orders created as quotes, stays in Shopify and is not affected.
Generated quote PDF files in file storage are not yet removed automatically when the app is uninstalled. We delete them on request (see below).
Shopify's privacy requests
The app is subscribed to Shopify's three mandatory privacy webhooks:
- Customer data request (
customers/data_request): when a buyer asks a merchant for their data, we give the merchant the data we hold about that buyer within 30 days. - Customer erasure (
customers/redact): we delete the personal data we hold about that buyer for that store within 30 days, unless we must keep it by law. - Store erasure (
shop/redact): Shopify sends this 48 hours after a merchant uninstalls. We delete the remaining store record within 30 days, except the module trial history, which holds no personal information.
Asking us to delete data
Merchants can ask us to delete their data, including quote PDF files, at any time by emailing support@b2b-supercharge.com from the store's account email. Buyers should contact the merchant. If a buyer contacts us directly, we will pass the request to the merchant.
9. Security
We use technical and organisational measures appropriate to the data we handle, including:
- Encryption in transit (HTTPS) for all traffic to and from the app.
- Encryption at rest provided by our database and hosting providers.
- Verification of Shopify's signatures on every webhook and storefront request, and signed tokens for customer account and POS requests.
- Database-level isolation between stores (row-level security), so one store's data cannot be read in the context of another store.
- Custom SMTP passwords encrypted with AES-256-GCM before they are stored.
- Access to production systems limited to B2B Supercharge staff who need it to run and support the app.
No system is completely secure. If we become aware of a breach that affects personal data, we will notify affected merchants and authorities as the law requires.
10. Your rights
Depending on where you live, you may have the rights below. Merchants can exercise them by emailing us. Buyers should contact the merchant whose store they buy from, because the merchant controls buyer data. We will help the merchant respond. We may need to verify your identity before acting on a request. We respond within the time the law requires, usually within 30 days.
EU, EEA and UK (GDPR and UK GDPR)
You can ask to access, correct or delete your personal data, restrict or object to how we process it, and receive a portable copy. Where we rely on legitimate interests, you can object. You can also complain to your local data protection authority.
California (CCPA as amended by the CPRA)
You can ask to know what personal information we collect, use and disclose, to delete it, and to correct it. You have the right not to be discriminated against for using these rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that would require a right to limit. You can use an authorised agent to make a request.
Canada (PIPEDA)
You can ask to access the personal information we hold about you and to correct it if it is wrong. You can withdraw consent, subject to legal or contractual limits, and we will explain the effect of doing so. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada.
11. This website
If you use the "Book a demo" form on b2b-supercharge.com, we collect your name, work email, company, store URL and monthly B2B order volume. We store these in our customer relationship management system (Attio) to follow up with you, and we send an automatic reply through Resend. Scheduling a call uses an embedded Cal.com calendar, which collects the details you enter there. The website is hosted by Vercel. We use this information to respond to your request and to follow up about B2B Supercharge, based on our legitimate interest in answering business enquiries. You can ask us to delete it at any time.
12. Children
The app and this website are for businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy when the app or the law changes. We will change the "Last updated" date at the top of this page. If a change materially affects how we handle personal information, we will tell merchants in the app or by email before it takes effect.
14. Contact us
B2B Supercharge
Email: support@b2b-supercharge.com
Please include your store's myshopify domain in any request about app data.