Legal

Privacy Policy

Last updated: September 26, 2026

This policy explains what information the B2B Supercharge Shopify app collects, why we collect it, who we share it with, how long we keep it and how to ask us to delete it. It covers the app, and the B2B Supercharge website where noted.

1. Who we are

B2B Supercharge is a Shopify app built and operated by B2B Supercharge, a Canadian company ("B2B Supercharge", "we", "us"). In this policy, "merchant" means a Shopify store that installs the app, including the store owner and staff who use it. "Buyer" means a merchant's business customer, such as a company contact who signs in to the merchant's store.

For any privacy question or request, email support@b2b-supercharge.com.

2. What the app does

The app adds business-to-business features to a Shopify store. Merchants choose which modules to turn on:

  • Quote Management: buyers request quotes on the storefront, merchants price them in the Shopify admin, and buyers accept them. Quotes are Shopify draft orders, with branded PDF quotes and quote emails.
  • Order Approval: orders above a threshold are held for an approver at the buyer's company, who approves or rejects them from the customer account.
  • User Management: merchants and company admins add company contacts and assign roles, including by CSV import.
  • QuickPad / OrderPad: fast ordering by SKU for signed-in buyers.
  • Wishlist: buyers save products to named lists, download a PDF and share a list by link or email.
  • POS B2B Orders: staff ring up company orders in Shopify POS.

Shopify remains the system of record for customers, companies, orders and draft orders. The app reads and writes that data through Shopify's APIs and keeps a limited copy in its own database so the features work quickly and reliably.

3. Our role for each type of data

Merchant data. For information about merchants and their staff (for example, the store's account details and who installed the app), B2B Supercharge decides how the data is used. We act as a controller (GDPR) and a business (CCPA/CPRA).

Buyer data. For information about a merchant's buyers, the merchant decides how it is used, and we process it only to provide the app to that merchant. We act as a processor (GDPR) and a service provider (CCPA/CPRA) on the merchant's behalf. The merchant's own privacy policy governs how the merchant uses its customers' data. Buyers who want to exercise their rights should contact the merchant first. We will help the merchant respond.

4. Information we collect

4.1 Merchants (store owner and staff)

InformationSourceWhy we need it
Store details: store name, domain, myshopify domain, store email, customer-facing email, store owner name, phone, address, currency, time zone and Shopify planShopify, when the app is installed and when the store is updatedTo identify the store, format prices and dates, and address emails and PDFs correctly
Staff session details: Shopify user ID, first and last name, email, whether the user is the account owner, and Shopify access tokensShopify, when a staff member opens the appTo authenticate staff inside the Shopify admin and call Shopify's APIs for the store
App settings: branding, logo, PDF sender details (name, address lines, phone), email sender settings, notification settings, and optional custom SMTP credentialsThe merchant, in the app settingsTo brand quotes, PDFs and emails and to send email from the merchant's own mail server if chosen
Sales rep name and email on a quote, and staff comments on quotesThe merchant, in the appTo show who owns a quote and keep the quote's history
Billing and module records: which modules are enabled, trial dates, Shopify subscription statusThe app and Shopify BillingTo turn modules on and off and charge through Shopify
Support emails you send usYouTo answer you

We do not receive merchants' payment card details. App charges are billed through Shopify.

4.2 Buyers (the merchant's customers)

We process this data on the merchant's behalf. Some of it is stored only in Shopify and read when needed. Some is copied into the app's database.

InformationWhere it livesWhy the app uses it
Customer ID, email, first and last nameShopify, with a copy in the app databaseTo recognise a signed-in buyer and link them to their company
Company, company location and company contact records, and contact role assignments (for example "Ordering only" or "Location admin"), including company and location names and external IDsShopify, with a copy in the app databaseTo decide what each buyer can see and do, such as who can approve orders or manage users
Phone number and addresses (default shipping address and saved addresses)Shopify only. Read when a buyer opens the quote form and held in server memory for up to 5 minutesTo prefill the quote request form
Quote contents: products, quantities, prices, totals, taxes, shipping line, notes, PO number, status and dates, plus comments between buyer and merchantShopify draft order, with a copy in the app databaseTo list, price, send and track quotes
Quote PDFsGenerated by the app and stored in file storage at an unguessable linkTo let the merchant and buyer download the quote
Approval requests: buyer name and email, company and location name, order contents and total, approver, decision and rejection reasonApp database, with approval status also written to the Shopify draft orderTo route orders to the right approver and record the decision
Wishlists: list names, saved products, sharing settings, and the email addresses a buyer shares a list withApp databaseTo save, share and export lists, and suggest recent recipients
Contacts added by CSV import: name, email, company location and roleCreated in Shopify. The file's rows pass through our background job service while the import runsTo create company contacts in bulk
Order data for approvals, quotes and POS ordersShopify. Read when needed and not stored as a separate order tableTo apply payment terms, detect converted quotes and complete approvals
Shopify event notifications (webhooks) about companies, contacts, customers, draft orders, orders and productsApp database, for a limited time (see section 8)To keep the app in step with Shopify and to retry failed updates
In-progress OrderPad linesThe buyer's own browser (local storage)So a buyer does not lose an order they are building

People who open a shared wishlist link do not need an account, and the app does not collect information about them. The app does not place advertising cookies on a merchant's storefront and does not sell buyer data.

4.3 Technical information

When the app runs, our hosting provider records standard server logs, such as request paths, timestamps, status codes and IP addresses. Our own log lines and error reports identify the store (by internal store ID) and the operation that ran. We also record a product analytics event when a quote changes status. That event contains the Shopify customer ID, store ID, quote number, status, total, currency, item count and company location ID. It does not include names or email addresses.

5. How we use information and our legal bases

We use information only to provide, secure, support and improve the app, to bill for it, and to meet legal obligations. We do not use buyer data for our own marketing, and we do not sell personal information.

PurposeLegal basis (GDPR / UK GDPR)
Providing the app's features to the merchant, including processing buyer dataPerformance of our contract with the merchant. For buyer data, we act on the merchant's instructions, and the merchant is responsible for its own legal basis.
Sending quote, approval and wishlist emails that the merchant has turned onPerformance of contract, on the merchant's instructions
Billing through Shopify, trials and module accessPerformance of contract
Security, fraud and abuse prevention, error monitoring and troubleshootingLegitimate interests in keeping the app secure and working
Understanding how features are used, so we can improve themLegitimate interests, using limited, non-contact data (section 4.3)
Answering support requestsPerformance of contract and legitimate interests
Keeping records required by law and responding to lawful requestsLegal obligation

6. Sharing and subprocessors

We share information only with the service providers that run the app, listed below, and only as needed for the services they provide to us. Each one processes data on our instructions.

ProviderWhat they do for usData involved
ShopifyThe platform the app runs on. System of record for store, customer, company and order data, and app billingAll app data originates in or is written back to the merchant's Shopify store
VercelApplication hosting, file storage for quote PDFs, and server logsAll data the app processes passes through its servers. PDFs and logs are stored there
NeonPostgreSQL databaseThe app database described in section 4
InngestBackground job processingJob inputs and results, which can include webhook contents and CSV import rows
UpstashShort-term cacheStore settings, including PDF sender details, and internal routing lists, for up to 1 hour
SentryError monitoringError details tagged with store ID and job information
AxiomLog storage and alertingCopies of application logs
PostHogProduct analyticsQuote status events described in section 4.3
ResendEmail delivery for emails sent from our default senderRecipient email address, sender and reply-to address, and email content (for example a quote summary)

Merchant's own email server. If a merchant sets up custom SMTP in the app, emails are sent through the merchant's own mail provider instead of ours. That provider works for the merchant, not for us.

Shared wishlists. When a buyer shares a wishlist, anyone with the link can view the list. When the buyer shares by email, the recipients receive the link.

Other disclosures. We may disclose information if the law requires it, to protect the rights, safety or property of B2B Supercharge, our users or others, or as part of a merger, acquisition or sale of assets. In a sale, this policy would continue to apply to the data transferred.

7. International transfers

B2B Supercharge is based in Canada. The app is hosted in the United States, and our providers may process data in the United States and other countries. Those countries may have different data protection laws from yours. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses and the UK equivalent included in our providers' data processing terms.

8. Retention and deletion

We keep information only as long as we need it for the purposes in this policy.

InformationHow long we keep it
Store, buyer, quote, approval, wishlist and settings data in the app databaseWhile the app is installed. Deleted when the app is uninstalled (below)
Shopify event notifications (webhooks)7 days after they are processed successfully, or 90 days if processing failed or the event was not needed. Deleted sooner if the app is uninstalled
Background job records90 days
Email delivery records (used so each email is sent once)90 days, or until uninstall
Cached store settingsUp to 1 hour
Buyer form prefill (name, email, phone, addresses)Up to 5 minutes, in server memory only
Server logs, error reports, job history at our job provider, and analytics eventsFor the limited periods set in each provider's retention settings, then deleted

When a merchant uninstalls the app

When Shopify tells us the app has been uninstalled, we turn off every module and delete the store's data from the app database: the copies of companies, locations, contacts, role assignments and customers, and all quotes, quote comments, PDF records, approval requests, approver assignments, wishlists, wishlist items and share records, settings, staff sessions, email delivery records and stored webhook events. This runs automatically in the background as soon as the notification is processed.

We keep a minimal record of the store (its Shopify ID, domain and the store details Shopify provided), marked as uninstalled, and the history of which modules used a free trial. This lets a reinstall start cleanly and stops a free trial from being used twice. Data in the merchant's Shopify store, such as draft orders created as quotes, stays in Shopify and is not affected.

Generated quote PDF files in file storage are not yet removed automatically when the app is uninstalled. We delete them on request (see below).

Shopify's privacy requests

The app is subscribed to Shopify's three mandatory privacy webhooks:

  • Customer data request (customers/data_request): when a buyer asks a merchant for their data, we give the merchant the data we hold about that buyer within 30 days.
  • Customer erasure (customers/redact): we delete the personal data we hold about that buyer for that store within 30 days, unless we must keep it by law.
  • Store erasure (shop/redact): Shopify sends this 48 hours after a merchant uninstalls. We delete the remaining store record within 30 days, except the module trial history, which holds no personal information.

Asking us to delete data

Merchants can ask us to delete their data, including quote PDF files, at any time by emailing support@b2b-supercharge.com from the store's account email. Buyers should contact the merchant. If a buyer contacts us directly, we will pass the request to the merchant.

9. Security

We use technical and organisational measures appropriate to the data we handle, including:

  • Encryption in transit (HTTPS) for all traffic to and from the app.
  • Encryption at rest provided by our database and hosting providers.
  • Verification of Shopify's signatures on every webhook and storefront request, and signed tokens for customer account and POS requests.
  • Database-level isolation between stores (row-level security), so one store's data cannot be read in the context of another store.
  • Custom SMTP passwords encrypted with AES-256-GCM before they are stored.
  • Access to production systems limited to B2B Supercharge staff who need it to run and support the app.

No system is completely secure. If we become aware of a breach that affects personal data, we will notify affected merchants and authorities as the law requires.

10. Your rights

Depending on where you live, you may have the rights below. Merchants can exercise them by emailing us. Buyers should contact the merchant whose store they buy from, because the merchant controls buyer data. We will help the merchant respond. We may need to verify your identity before acting on a request. We respond within the time the law requires, usually within 30 days.

EU, EEA and UK (GDPR and UK GDPR)

You can ask to access, correct or delete your personal data, restrict or object to how we process it, and receive a portable copy. Where we rely on legitimate interests, you can object. You can also complain to your local data protection authority.

California (CCPA as amended by the CPRA)

You can ask to know what personal information we collect, use and disclose, to delete it, and to correct it. You have the right not to be discriminated against for using these rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that would require a right to limit. You can use an authorised agent to make a request.

Canada (PIPEDA)

You can ask to access the personal information we hold about you and to correct it if it is wrong. You can withdraw consent, subject to legal or contractual limits, and we will explain the effect of doing so. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada.

11. This website

If you use the "Book a demo" form on b2b-supercharge.com, we collect your name, work email, company, store URL and monthly B2B order volume. We store these in our customer relationship management system (Attio) to follow up with you, and we send an automatic reply through Resend. Scheduling a call uses an embedded Cal.com calendar, which collects the details you enter there. The website is hosted by Vercel. We use this information to respond to your request and to follow up about B2B Supercharge, based on our legitimate interest in answering business enquiries. You can ask us to delete it at any time.

12. Children

The app and this website are for businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy when the app or the law changes. We will change the "Last updated" date at the top of this page. If a change materially affects how we handle personal information, we will tell merchants in the app or by email before it takes effect.

14. Contact us

B2B Supercharge
Email: support@b2b-supercharge.com

Please include your store's myshopify domain in any request about app data.