SupplygoodsSupplygoods

Privacy

What the Supplygoods app reads from a Shopify store, why it needs it, who else sees it, and what happens when somebody asks for it to be erased. It is written from what the software does, not from what a policy usually says.

Last updated 28 September 2026

How this works

You sell a product in your Shopify store. Our supply partner in China sources it, checks it, packs it and ships it to your customer. Supplygoods is the software the two of you work in: your store connected to their bench, with the quotes, the orders, the tracking and the conversation in one place.

You buy from them. They quote the price, they invoice you, you pay them, and they ship the parcel. When you sell a product through Supplygoods you enter into an agreement with that company. Money you pay for goods and freight is never held by the platform at any point.

That is the short version. Who each of them is, and what this policy covers, is below.

Who is who

The supplier is , registered in , China, legal representative . They source and inspect the goods, they set the price, and they invoice you.

The warehouse is a company in , China, which holds the goods, packs them and hands the parcel to a carrier. It is a different company from the supplier, and it is the one that receives a delivery address so a parcel can be addressed. Neither of them receives anything else about your customers. Ask us who it is and we will tell you, in writing, by mail to .

The platform is operated by , reachable at . It runs the software and is your point of contact. It is not a seller and not a carrier, it does not own or hold the goods, and it is not a party to the sale of them. This policy describes what it does with personal data, and its registration is under Company details at the end of this page.

What the app reads from Shopify

A merchant approves four scopes when they install, and the app asks for nothing beyond them. Each one is here because something would not work without it.

read_products

Products and variants: title, options, SKU, price, images, weight.

The supplier prices a product before it can be sold. A quote is tied to the Shopify variant id, and a snapshot of the product as it was priced is kept as the evidence in a dispute.

write_orders

Orders, including the customer's name, shipping address, and the email or phone the shop holds for delivery. Writing is used for one thing only: correcting a shipping address.

A parcel needs an address. An order that cannot be delivered is stuck until somebody corrects it, and making the merchant leave the dashboard to do that is how it stays stuck. It is the widest thing we ask for, which is why it is worth saying exactly what it is for.

write_fulfillments

Marks an order fulfilled and puts the carrier and tracking number on it.

Two systems disagreeing about whether an order has shipped is the thing this product exists to remove.

write_merchant_managed_fulfillment_orders

The fulfilment orders held at a location the shop manages itself.

It is the narrowest scope that allows fulfilling at all. The two wider ones would let us see orders belonging to another fulfilment service that we still could not ship.

We never write to a merchant's catalogue and could not: the products scope is read only. We do not read customer accounts, marketing consent, or anything about shoppers who have not placed an order that is being fulfilled.

The one transfer worth naming

A shipping address leaves the European Union. The warehouse that packs and ships the parcel is in , China, and it cannot address a box without the name and address on it. That is an international transfer of personal data and it is the whole reason the app exists, so it is stated here rather than buried: install the app and the delivery details of the orders you fulfil through us are handled by our supplier in China.

Nothing else about a shopper goes there. Not their order history, not their other purchases, not their payment details, which the platform never receives at all.

What else we hold

Analytics and advertising

On our public website we use analytics and advertising cookies to see how the site is used and to measure our advertising. They do not run until you have said yes, and refusing is one press. What each one is, who it belongs to and how long it lasts is on the cookies page, and you can change your answer at any time from the link at the bottom of this page.

What we count without asking. Every visit to the public website tells our own server which advertisement link it arrived on, whether the page stayed on screen for ten and thirty seconds, whether it was scrolled to halfway and to the end, and whether the sign-up form was opened. We keep only a number per day per advertisement. Nothing is stored on your device or read from it, and we keep no IP address, browser, device or anything else that could tell one visitor from another, so none of it is about you.

When you sign up after saying yes, our server also tells Meta that a sign-up came from its advertisement: your email address and phone number in hashed form (a one way code Meta can only match against what it already holds), the click id on the link, your IP address and your browser. That is the same thing the Meta pixel on the page does, sent a second way so it is not lost when a browser blocks the pixel. Without a yes it is not sent.

The dashboard is different. There is no analytics and no advertising tag on any signed-in screen. What happens inside a merchant's account is not measured for marketing.

How long we keep it

Personal details are kept for as long as they are needed to process an order and to deal with anything arising from it, and then removed.

Financial records are kept for seven years, because the law requires it. That means the amount, the date and the order number, not the name and the address of the person the parcel went to. Those come off when the order is settled or when somebody asks for them to be removed, which is the same thing the erasure webhook below does automatically.

Erasing

Shopify sends three privacy requests to every app, whatever the app does. All three arrive here, are refused unless Shopify signed them, and are answered.

A shopper asks for their data

customers/data_request This one needs a person: we hold no way to reach a shopper directly, so the request becomes an open item on our own platform screen and is answered through the merchant. The record of having been asked is kept, because that is the thing anybody has to be able to show later.

A shopper asks to be erased

customers/redact Their name and address come off the orders they are on, immediately and automatically. The amount and the date stay for the seven years above. A ledger row is a bookkeeping record of a payment between two businesses, not a record about a person.

A merchant uninstalls

shop/redact Sent by Shopify forty eight hours after the app is removed. Everything of that shop's goes, except the financial records, and those keep only amounts and dates. The access token is dropped the moment the app is uninstalled, before that, so nothing can be read from the store in between.

Who else sees it

Your rights

If you are in the European Union or the United Kingdom you can ask to see what we hold about you, to have it corrected, to have it erased, to object to us holding it, and to have it handed to you in a portable form. Write to the address at the top of this page. If you are a shopper rather than a merchant, ask the shop you bought from: they hold the relationship, and Shopify's own request reaches us through them, which is the route above.

You can also complain to your national data protection authority.

Company details

The controller for the processing described above is , , . Reachable at . Write to that address about anything on this page, including a request to see, correct or erase what we hold.