Orumio — Standing Orders
Privacy Policy
Orumio — Standing Orders does not store the personal data of your buyers. The app schedules B2B draft orders in your Shopify store. It reads company contact names and email addresses so that you can pick the right buyer when setting up a standing order, shows them to you in your own admin, and then discards them. What it keeps in its own database is your schedule and opaque Shopify identifiers — never the person behind them.
1. Who we are
Orumio — Standing Orders (the “app”) is built and operated by Orumio (“we”, “us”).
| Operator | Orumio |
|---|---|
| Representative | Masanori Iwata |
| Address | Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan |
| Contact | support@orumio.com |
| Telephone | We will disclose this without delay in writing or by email upon request. Please send requests to the contact address above. |
When you install the app in your Shopify store, you are the controller of the personal data in that store and we act as your processor: we process it only to provide the app to you, on your instructions. The terms of that relationship are set out in our Data Processing Agreement, which forms part of your agreement with us.
2. What personal data the app processes
2.1 Read from Shopify, shown to you, never stored
When you create or edit a standing order, the app reads the name and email address of the company contacts at the company location you selected, so that you can choose the buyer the recurring order belongs to. Those values are rendered to you in your Shopify admin and held in memory for the length of that one request. They are never written to our database, never copied into logs, and never sent anywhere else.
The app also reads draft order contents (line items, prices, payment terms) when it reconciles an order it created or renders your activity history. Only the order’s Shopify identifier is stored.
2.2 Deliberately not requested
The app does not request access to customer phone numbers or addresses. It has no use for them: Shopify applies the company location’s addresses to the draft order on its own side, and the app never reads them.
2.3 Stored by the app
| Data | Personal data? | Why it exists |
|---|---|---|
| Your shop’s myshopify domain | No — a business identifier | Identifies your installation |
| Shopify access and refresh tokens | No — credentials | Lets the app create scheduled orders while nobody is signed in. Encrypted (§5) |
| Company, company location, company contact and product variant identifiers | No — opaque Shopify IDs | Points at the entities your standing order refers to. Shopify remains the source of truth for all of them |
| Schedule, quantities, timezone, next run time | No | The standing order itself |
| Execution and activity records | No | Duplicate-safe order creation and the activity history you see in the app |
| Subscription plan and status | No | Billing |
| Notification email address | Yes — your business contact | Where we send you a message when a scheduled order permanently fails, or when the app loses access to your store. Seeded from the store owner’s address and editable by you |
A company contact identifier is stored; the person behind it is not. That is what keeps our retention obligations, our deletion obligations and the consequences of any breach small.
3. Why we process it
One purpose only: to provide the app — store management, and creating scheduled B2B draft orders for your company locations on your behalf. These are the purposes we declared to Shopify when we requested access to protected customer data, and they are enforced in the code: every read of a protected field must declare one of a fixed list of permitted purposes.
We do not, and the app has no mechanism to:
- use personal data for marketing, advertising or profiling;
- sell or share personal data with anyone;
- use personal data to train machine-learning models;
- build analytics or audience products out of your data.
The app makes no automated decisions about people. It creates draft orders on a schedule you configured; the decision is yours, made in advance, and has no legal or similarly significant effect on any buyer.
4. Who else processes it (sub-processors)
The app talks to a deliberately small number of external services. There is no analytics SDK, no error-reporting service receiving payloads, and no third-party script in the server path.
| Service | Role | Personal data it can see |
|---|---|---|
| Shopify | The platform your store runs on | All store data — Shopify is the source of truth, and its own privacy terms govern it |
| Vercel | Application hosting (United States) | Data in transit while a request is being served, plus our runtime logs (§6) |
| Neon | Managed Postgres database (United States) | Everything listed in §2.3, at rest |
| Resend | Transactional email delivery | Your notification email address, and the text of the failure message sent to it |
| Checkly | Uptime monitoring | None. It requests a health-check endpoint that returns scheduler timing only |
Our database and application servers are located in the United States. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside that region; the safeguards for that transfer are set out in the Data Processing Agreement.
5. How it is protected
- Minimisation first. Buyer personal data is never written to our database. Data that was never stored cannot be leaked from storage, exposed in a backup, or taken in a database breach.
- Encryption in transit. The app is served only over HTTPS, and the database connection requires TLS with channel binding.
- Encryption at rest. Our database provider encrypts all data and backups at rest. There is no self-managed backup, export, or snapshot pipeline, so no unencrypted copy of the database exists anywhere.
- Credentials encrypted a second time. Your Shopify access and refresh tokens are additionally encrypted with AES-256-GCM before they reach the database, cryptographically bound to your shop domain — a stolen database row cannot be replayed against another store.
- Tenant isolation. Every record reaches your installation by foreign key, and every query filters through it.
- Access control. The app is operated by a single person. There are no staff accounts, contractors, or support agents with access to merchant data. Every account with access is protected by two-factor authentication and a unique password generated and stored in a password manager.
We maintain a written data protection policy and a security incident response policy, and we review both whenever what the app does with data changes.
6. Logging
The app writes operational logs so that failures can be diagnosed. Those logs record identifiers, classifications, counts and timestamps — never access tokens, never webhook payloads, and never buyer personal data. Your notification email address is not logged either: a notification log line records which store and which execution, not the address it went to.
Where the app reads a protected customer field, it records an access log entry containing the purpose, the resource, the names of the fields read, whether a person or the scheduler triggered it, and how many records were involved. It never records the values.
The app reports page-performance measurements (such as load time and layout stability) for its own admin screens, tagged with your shop domain and the screen name. These contain no personal data and are used only to keep the app fast.
Logs are held in our hosting provider’s runtime log storage. No log data is forwarded to any third-party log or analytics service.
7. Cookies and tracking
The app sets no advertising, analytics or tracking cookies. Inside the Shopify admin it authenticates with Shopify session tokens rather than its own login. Shopify may set its own cookies as part of the admin and the installation flow; those are governed by Shopify’s privacy terms, not this policy.
This policy covers the app. Our listing page on the Shopify App Store is a Shopify-operated page, and we use Shopify’s own listing-analytics feature there (Google Analytics) to see how merchants find the listing. That is separate from the app: it never runs inside the admin, it never sees your store’s or your buyers’ data, and nothing measured there is joined to anything in this policy.
8. How long it is kept
- Buyer personal data: not retained at all, so there is nothing to expire.
- Your configuration and history are kept while the app is installed, because they are the app.
- When you uninstall, the app immediately revokes the stored credentials so no further processing can happen, and cancels every scheduled occurrence that had not yet run.
- Deletion. Shopify sends us a shop redaction request approximately 48 hours after uninstall; that deletes your installation record and everything attached to it — entitlement, standing orders, order lines, execution records and activity events.
- Backstop. Because that request is a webhook and can fail to arrive, the app itself deletes any installation that has been uninstalled for more than 30 days, with the same cascade. The window is long enough never to pre-empt a reinstall, and finite so that a lost message cannot become indefinite retention.
9. Requests from buyers
If a buyer asks to access or delete their personal data, that request belongs to the merchant whose store holds it. Shopify forwards such requests to us as well, and we handle them as follows:
- Data request: we return nothing, because we hold no buyer personal data.
- Customer redaction: no action is required for the same reason. A standing order refers to a company contact by Shopify identifier, which is a pointer into Shopify, not personal data we own.
- Shop redaction: we delete the merchant’s entire tenant as described in §8.
If you are a buyer and are not sure which merchant holds your data, write to support@orumio.com and we will help you reach them.
10. Security incidents
If we confirm an incident affecting personal data, we notify the affected merchants directly and in plain language — what happened, what data was involved, what we have done, and what if anything you need to do — targeting within 72 hours of confirming it. We also report incidents involving protected customer data or platform credentials to Shopify promptly, without waiting for a complete root-cause analysis.
11. Changes to this policy
If we change what the app does with personal data, we update this page and its version number before the change ships. Material changes are announced to installed merchants by email at the notification address on file.
12. Contact
Questions, requests, or anything that looks wrong in this policy: support@orumio.com.