SaleWizr Privacy Policy
Last updated: 17 July 2026
What we collect, why we collect it, who we share it with, and what you can ask us to do about it — in plain language.
SaleWizr (“we”, “us”, “our”) is a wholesale B2B app for Shopify merchants. This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what rights merchants and their buyers have.
If you install or use SaleWizr, this policy applies to you. If you are a wholesale buyer using a merchant’s SaleWizr buyer portal, the sections about buyer data apply to you as well.
1. What we collect
We collect only the information needed to run the app. We do not collect payment card numbers, and we do not store Shopify customer IDs for buyers — buyers are identified within SaleWizr by their email address scoped to your store.
Merchant data (the Shopify store that installs SaleWizr)
| What we collect | Why |
|---|---|
Shop domain (e.g. your-store.myshopify.com) | To identify your store and keep your data separate from other merchants. |
| Shopify access token (encrypted) | To act on your behalf through Shopify’s APIs — for example, reading products for your wholesale catalogue and syncing orders. |
| Merchant email, sender name, and branding settings | To configure your branded buyer portal and send transactional emails (invitations, invoices, notifications) on your behalf. |
Buyer data (your wholesale customers who use the buyer portal)
| What we collect | Why |
|---|---|
| Email address | Portal login, account invitations, and delivery of invoices and order-related emails. |
| Name, company name, phone number, and billing address | Account management, display on invoices and order records, creation of a matching customer record in your Shopify store, and sharing invoice-ready details with a connected accounting provider when you choose to use one. |
| Invoice, order, and billing details | Net-terms invoicing, order history, payment tracking, and credit management for your wholesale programme. |
What we do not collect
- Payment card data — all card payments are handled by Shopify; SaleWizr never sees or stores card numbers.
- Advertising or marketing tracking — we do not use third-party analytics or ad trackers to profile buyers or merchants.
- Shopify customer IDs — buyer records in SaleWizr are matched by email address within your store, not by Shopify’s customer ID.
Operational metrics shown in your dashboard (such as wholesale revenue or buyer activity) are calculated from your Shopify order data and SaleWizr’s own records. They are not sold or used for advertising.
2. How we use your data
We use the information above only to provide and operate SaleWizr:
| Category | Purpose |
|---|---|
| Shop domain | Identify your store and scope all data so each merchant’s information stays isolated. |
| Shopify access token | Connect to Shopify on your behalf — read products and inventory, create draft orders for online-payment checkout, read orders for sync and settlement, and — for wholesale buyers you approve — create or update a customer record and apply your wholesale (B2B) tags in your own Shopify store. |
| Merchant email, sender name, branding | Power your branded buyer portal and send transactional emails and merchant notifications. |
| Buyer email | Authenticate buyers in the portal, send invitations, and deliver invoices and order-related messages. |
| Buyer name, company, phone, billing address | Manage buyer accounts, show accurate details on invoices and orders, create a matching customer record in your Shopify store for buyers you approve, and share invoice-ready details with a connected accounting provider when you choose to use one. |
| Invoice, order, and billing details | Run net-terms invoicing, order history, payment recording, and credit limits for your wholesale buyers. |
We do not use your data or your buyers’ data for our own marketing, and we donot sell personal information to third parties.
3. Who we share data with
We share data only with service providers that help us run the app. They process data on our instructions and do not use it for their own marketing.
| Provider | What is shared | Why |
|---|---|---|
| Resend | Merchant and buyer email addresses and the content of transactional emails | Deliver invitations, invoices, reminders, and notifications. |
| Supabase | Data stored in SaleWizr (database records and generated invoice PDF files) | Database hosting and file storage. |
| Vercel | Application data in transit during hosting | Host and run the SaleWizr application. |
| Cloudflare | None stored — DNS routing only | Route traffic to SaleWizr; Cloudflare does not host application data. |
| Shopify | Operates your store; billing for the SaleWizr subscription | Platform integration and Shopify Billing API for app subscription charges. |
| Xero (only when you connect it) | Buyer contact details (name, company, email, phone, billing address) and their invoices, credit notes, and payments | Mirror your wholesale invoicing and payments into your Xero accounting organisation. |
| Sentry | Technical error and diagnostic data (may include identifiers) | Monitor and diagnose application errors so we can keep the app reliable. |
| Inngest | Background-job event data (identifiers for shops, orders, and invoices) | Run scheduled and queued tasks such as accounting sync, invoice reminders, and statements. |
Accounting data is shared with Xero only if you, the merchant, choose to connect the integration; if you never connect it, no data is sent to it.
We do not use Stripe or any separate payment processor for buyer checkout — buyer payments go through Shopify’s checkout when online payment is enabled.
We do not share data with advertisers, data brokers, or social networks.
4. How long we keep data
| Data | Retention |
|---|---|
| Merchant data | Kept while SaleWizr is installed on your store. After you uninstall, we retain data only for Shopify’s post-uninstall retention window, then permanently delete it when Shopify sends a shop/redact request. |
| Shopify access token | Revoked immediately when you uninstall the app; deleted from our systems on shop/redact. |
| Buyer personal data | Kept while the app is installed and the buyer account is active. Deleted when Shopify sends a customers/redact request for that buyer, or when all shop data is deleted on shop/redact. |
| Invoice and order records | Deleted with the shop on shop/redact. Buyer-specific deletion on customers/redact removes the buyer’s personal data and related order/invoice records for that buyer. |
Our internal retention and purge practices align with Shopify’s mandatory data-erasure webhooks and retention window.
5. Your rights
SaleWizr supports Shopify’s GDPR compliance webhooks and your rights under applicable privacy laws.
Merchants
- Access: You can see most of your configured data inside the SaleWizr admin. For a full export of what we hold, contact us (see Section 7).
- Deletion: Uninstalling SaleWizr starts Shopify’s uninstall process. After the retention window, Shopify sends
shop/redactand we permanently delete all data for your store.
Buyers (wholesale customers)
- Access: Buyers may ask their merchant (the Shopify store) to see what data apps hold about them. Shopify forwards
customers/data_requestto installed apps; SaleWizr compiles the buyer’s data and makes it available to the merchant to fulfil the request. - Deletion: Buyers may ask for deletion through Shopify. Shopify sends
customers/redact; SaleWizr deletes the buyer’s account and related personal data matched by email address within that store.
How to exercise your rights
- Buyers: Contact the merchant whose portal you use, or use Shopify’s customer privacy tools where available.
- Merchants: Contact us at the email in Section 7, or uninstall the app from your Shopify admin to begin data removal after Shopify’s retention period.
We will respond to verified privacy requests within a reasonable time and in line with applicable law.
6. Security
We take reasonable technical and organisational measures to protect personal information:
- Encryption in transit — all communication with SaleWizr uses HTTPS.
- Encryption at rest — Shopify access tokens are encrypted before storage.
- Multi-tenant isolation — every database query is scoped by shop so one merchant cannot access another’s data.
- No card data — SaleWizr never processes or stores payment card numbers; Shopify handles all payment card processing.
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
7. Contact us
For privacy questions, data requests, or concerns about this policy:
Email: privacy@salewizr.com
We will respond within a reasonable time, typically within 30 days for formal requests.
8. Changes to this policy
We may update this policy when our practices change, when we add features, or when law requires it. When we make material changes, we will update the Last updated date at the top of this page. For significant changes, we may also notify merchants by email or through an in-app notice.
Please review this page periodically. Continued use of SaleWizr after an update means you accept the revised policy.