Privacy Policy
Last updated: 2026-07-05
Multistore Dropship Manager ("the App") is a Shopify application that helps merchants manage dropshipping order fulfillment across one or more stores. This policy explains what data the App collects from a merchant's Shopify store, why, where it is stored, and how it can be deleted.
Data we collect
When a merchant installs the App on a store, we access and store:
- Order data, including the recipient's name and shipping address, line items, and fulfillment/financial status.
- Product data (titles, SKUs, handles, images, status) used to detect sourcing information and build blog content.
- Store information (shop domain, plan, install status, webhook subscription status).
We do not collect payment card details — Shopify itself handles all payment processing, and the App never receives cardholder data.
Purpose of processing
This data is used solely to power the App's order-fulfillment dashboard: displaying a merchant's orders across their connected stores, letting them record a sourcing marketplace order number, and writing tracking information back to the corresponding Shopify order once shipped. Product data additionally powers an optional, Pro-plan blog auto-publish feature (see "Third-party processing" below).
Where data is stored
Data is stored in a managed Postgres database (Supabase) hosted on AWS infrastructure in the ap-southeast-1 (Singapore) region. All data in transit is encrypted with TLS, and data at rest is encrypted by the underlying storage infrastructure.
Third-party processing (OpenAI)
The App's optional blog auto-publish feature (available on the Pro plan) uses OpenAI's API to generate blog post drafts. Only a generated topic string and the connected products' handles and titles are sent to OpenAI for this purpose. Customer names, shipping addresses, order numbers, and any other customer or order data are never sent to OpenAI or any other third-party AI service.
No other third-party sharing
We do not sell, rent, or share merchant or customer data with any third party other than the OpenAI processing described above, which is strictly limited to non-personal product/topic text.
Data deletion
The App implements Shopify's mandatory GDPR webhooks:
- customers/redact — deletes any stored data tied to the specified customer when a merchant requests it on their customer's behalf.
- shop/redact — deletes all stored data for a shop 48 hours after uninstall, as required by Shopify.
- customers/data_request — supports a merchant's request to provide a copy of a customer's data on their behalf.
Uninstalling the App also immediately revokes and invalidates its stored Shopify access token for that store.
Contact
Questions about this policy or a data request can be sent to cs@shopidream.com.