B2B Price Guard Privacy Policy
1. Who this policy applies to
This policy describes how Creosmart (“we”, “us”) collects, uses, stores, and deletes information when you install or use the B2B Price Guard application (“the App”) on your Shopify store. The App is built for Shopify merchants who use native B2B company locations and wholesale pricing.
The App is not intended for buyers or end customers. We do not operate a consumer-facing website on your storefront and we do not place cookies or tracking technologies on buyer devices.
2. Information we collect through Shopify
With your permission through Shopify OAuth, the App accesses Shopify Admin data needed to enforce B2B floor prices, run catalog audits, and detect pricing incidents. Depending on how you use the App, this may include:
- Shop and session data: shop domain, Shopify shop identifier, currency, timezone, B2B eligibility signals, offline access tokens, and staff session metadata required for embedded admin access.
- B2B catalog data: companies, company locations, catalogs, catalog assignments, products, and variants (including titles, SKUs, and list prices).
- Merchant configuration: price policies, location assignments, floor rules, quantity tiers, currencies, and compiled validation payloads written to Shopify metafields.
- Order evidence: order identifiers, line items, variant identifiers, quantities, floor amounts, actual charged amounts, and undercharge calculations. We intentionally do not store buyer names, emails, phone numbers, or shipping addresses.
- Billing status: Shopify App Subscription identifiers and plan status for entitlement gating.
- Webhooks: webhook identifiers, topics, shop domain, and hashed payload fingerprints for idempotent processing.
3. Information you provide directly
- Alert email: an optional email address you set in Settings (or that we bootstrap from your Shopify shop contact email) to receive undercharge incident notifications.
- Floor rules and policies: pricing thresholds and related configuration you enter in the App.
- Support messages: if you use in-app chat, the content of messages you send to our support team.
4. Information about your customers
The App does not collect personal data directly from your store's buyers. We do not use storefront pixels, buyer cookies, or behavioral tracking. Order checks use transactional pricing evidence only.
If Shopify sends mandatory compliance webhooks relating to a customer's personal data, we acknowledge the request and confirm that we do not retain buyer personal data for the App's core functionality.
5. How we use information
We use collected information only to:
- Provide, operate, and improve the App's B2B floor pricing features.
- Sync catalog and company data, compile rules, and run scheduled audits.
- Validate checkout pricing and record pricing incidents.
- Send operational alert emails you configure.
- Process app billing through Shopify's billing APIs.
- Maintain security, prevent abuse, debug errors, and comply with law.
- Respond to support requests and mandatory Shopify compliance webhooks.
We do not sell personal data. We do not use merchant or buyer data for unrelated advertising.
6. Service providers
We use trusted subprocessors to host and operate the App. They process data on our instructions and only as needed to provide the service:
- Render — application hosting.
- Neon — PostgreSQL database hosting.
- Resend — transactional email delivery for incident alerts.
- Sentry — error monitoring (payloads are scrubbed to remove secrets and common personal data fields).
- Crisp — optional in-app merchant support chat when enabled.
- Shopify — platform APIs, OAuth, billing, webhooks, and checkout validation runtime.
7. Retention and deletion
We retain shop-scoped data for as long as the App is installed and needed to provide the service. When you uninstall the App, access tokens and active processing stop. Shopify may later send a shop/redact compliance webhook; when we receive it, we delete tenant-scoped business data (rules, audits, incidents, synced catalog copies, sessions, and related records) from our database.
Limited operational records (such as privacy request logs and webhook receipt metadata) may be retained for compliance and security for a short period where permitted by law.
8. Your rights and Shopify compliance webhooks
The App implements Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. Because we do not store buyer personal data, customer data requests and redactions are acknowledged without additional buyer records to export or erase.
Merchants may contact us to ask questions about this policy or to request information about data we hold for their shop.
9. Security
We use HTTPS for data in transit, tenant-scoped database access, Shopify HMAC webhook verification, and access controls on production infrastructure. No method of transmission or storage is completely secure; we work to protect data using reasonable industry practices.
10. International transfers
Data may be processed in the United States and other countries where our subprocessors operate. Where required, we rely on appropriate safeguards for cross-border transfers.
11. Changes
We may update this policy from time to time. We will revise the effective date above when we make material changes. Continued use of the App after an update means you accept the revised policy.
12. Contact
Questions about this policy or your shop's data in B2B Price Guard:
Email: support@creosmart.com