Orumio — Standing Orders

Privacy Policy

Version 1.0 · Effective 16 August 2026 · Operated by Orumio

Orumio — Standing Orders does not store the personal data of your buyers. The app schedules B2B draft orders in your Shopify store. It reads company contact names and email addresses so that you can pick the right buyer when setting up a standing order, shows them to you in your own admin, and then discards them. What it keeps in its own database is your schedule and opaque Shopify identifiers — never the person behind them.

1. Who we are

Orumio — Standing Orders (the “app”) is built and operated by Orumio (“we”, “us”).

OperatorOrumio
RepresentativeMasanori Iwata
AddressMitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan
Contactsupport@orumio.com
TelephoneWe will disclose this without delay in writing or by email upon request. Please send requests to the contact address above.

When you install the app in your Shopify store, you are the controller of the personal data in that store and we act as your processor: we process it only to provide the app to you, on your instructions. The terms of that relationship are set out in our Data Processing Agreement, which forms part of your agreement with us.

2. What personal data the app processes

2.1 Read from Shopify, shown to you, never stored

When you create or edit a standing order, the app reads the name and email address of the company contacts at the company location you selected, so that you can choose the buyer the recurring order belongs to. Those values are rendered to you in your Shopify admin and held in memory for the length of that one request. They are never written to our database, never copied into logs, and never sent anywhere else.

The app also reads draft order contents (line items, prices, payment terms) when it reconciles an order it created or renders your activity history. Only the order’s Shopify identifier is stored.

2.2 Deliberately not requested

The app does not request access to customer phone numbers or addresses. It has no use for them: Shopify applies the company location’s addresses to the draft order on its own side, and the app never reads them.

2.3 Stored by the app

DataPersonal data?Why it exists
Your shop’s myshopify domainNo — a business identifierIdentifies your installation
Shopify access and refresh tokensNo — credentialsLets the app create scheduled orders while nobody is signed in. Encrypted (§5)
Company, company location, company contact and product variant identifiersNo — opaque Shopify IDsPoints at the entities your standing order refers to. Shopify remains the source of truth for all of them
Schedule, quantities, timezone, next run timeNoThe standing order itself
Execution and activity recordsNoDuplicate-safe order creation and the activity history you see in the app
Subscription plan and statusNoBilling
Notification email addressYes — your business contactWhere we send you a message when a scheduled order permanently fails, or when the app loses access to your store. Seeded from the store owner’s address and editable by you

A company contact identifier is stored; the person behind it is not. That is what keeps our retention obligations, our deletion obligations and the consequences of any breach small.

3. Why we process it

One purpose only: to provide the app — store management, and creating scheduled B2B draft orders for your company locations on your behalf. These are the purposes we declared to Shopify when we requested access to protected customer data, and they are enforced in the code: every read of a protected field must declare one of a fixed list of permitted purposes.

We do not, and the app has no mechanism to:

The app makes no automated decisions about people. It creates draft orders on a schedule you configured; the decision is yours, made in advance, and has no legal or similarly significant effect on any buyer.

4. Who else processes it (sub-processors)

The app talks to a deliberately small number of external services. There is no analytics SDK, no error-reporting service receiving payloads, and no third-party script in the server path.

ServiceRolePersonal data it can see
ShopifyThe platform your store runs onAll store data — Shopify is the source of truth, and its own privacy terms govern it
VercelApplication hosting (United States)Data in transit while a request is being served, plus our runtime logs (§6)
NeonManaged Postgres database (United States)Everything listed in §2.3, at rest
ResendTransactional email deliveryYour notification email address, and the text of the failure message sent to it
ChecklyUptime monitoringNone. It requests a health-check endpoint that returns scheduler timing only

Our database and application servers are located in the United States. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside that region; the safeguards for that transfer are set out in the Data Processing Agreement.

5. How it is protected

We maintain a written data protection policy and a security incident response policy, and we review both whenever what the app does with data changes.

6. Logging

The app writes operational logs so that failures can be diagnosed. Those logs record identifiers, classifications, counts and timestamps — never access tokens, never webhook payloads, and never buyer personal data. Your notification email address is not logged either: a notification log line records which store and which execution, not the address it went to.

Where the app reads a protected customer field, it records an access log entry containing the purpose, the resource, the names of the fields read, whether a person or the scheduler triggered it, and how many records were involved. It never records the values.

The app reports page-performance measurements (such as load time and layout stability) for its own admin screens, tagged with your shop domain and the screen name. These contain no personal data and are used only to keep the app fast.

Logs are held in our hosting provider’s runtime log storage. No log data is forwarded to any third-party log or analytics service.

7. Cookies and tracking

The app sets no advertising, analytics or tracking cookies. Inside the Shopify admin it authenticates with Shopify session tokens rather than its own login. Shopify may set its own cookies as part of the admin and the installation flow; those are governed by Shopify’s privacy terms, not this policy.

This policy covers the app. Our listing page on the Shopify App Store is a Shopify-operated page, and we use Shopify’s own listing-analytics feature there (Google Analytics) to see how merchants find the listing. That is separate from the app: it never runs inside the admin, it never sees your store’s or your buyers’ data, and nothing measured there is joined to anything in this policy.

8. How long it is kept

9. Requests from buyers

If a buyer asks to access or delete their personal data, that request belongs to the merchant whose store holds it. Shopify forwards such requests to us as well, and we handle them as follows:

If you are a buyer and are not sure which merchant holds your data, write to support@orumio.com and we will help you reach them.

10. Security incidents

If we confirm an incident affecting personal data, we notify the affected merchants directly and in plain language — what happened, what data was involved, what we have done, and what if anything you need to do — targeting within 72 hours of confirming it. We also report incidents involving protected customer data or platform credentials to Shopify promptly, without waiting for a complete root-cause analysis.

11. Changes to this policy

If we change what the app does with personal data, we update this page and its version number before the change ships. Material changes are announced to installed merchants by email at the notification address on file.

12. Contact

Questions, requests, or anything that looks wrong in this policy: support@orumio.com.