← Back

Privacy Policy

Last updated: April 4, 2026

B2B Order Flow ("we", "our", "the app") is a purchase order processing tool that helps merchants convert purchase order documents into Shopify draft orders. This policy explains what data we collect, why, and how we protect it.

1. Data We Collect

Account data

Shopify store data

Purchase order data

Business configuration

Automatically collected

2. How We Use Your Data

We do not use your data for advertising, analytics profiling, or any purpose unrelated to purchase order processing.

3. Third-Party AI Services

Important: The app sends your data to third-party AI services for processing. By using the app, you acknowledge and accept the data sharing described below.

To extract data from purchase orders and match products, the app sends information to third-party AI providers. This includes:

AI providers we may use

The app currently uses and may use any of the following AI services, and may add additional providers in the future:

How AI providers handle your data

Once data is sent to a third-party AI provider, it is governed by that provider's own privacy policy and terms of service. We have no control over how AI providers store, process, use, or retain your data after it is transmitted to them. Specifically:

Your responsibility

By using the app, you acknowledge that sensitive business data (customer names, addresses, emails, order details, product information) will be shared with third-party AI services. If you have confidentiality obligations regarding this data, you should evaluate whether use of this app is appropriate.

4. Shopify

We connect to your Shopify store via their API to read products and customers, and to create draft orders. Data exchanged with Shopify is governed by Shopify's Privacy Policy. We request only the permissions necessary for the app to function: product read/write, customer read/write, and draft order read/write.

We do not sell, rent, or share your data with any parties other than those listed above.

5. Data Security

Data not encrypted at rest

The following data is stored without encryption at rest. While access is protected by authentication and server-level controls, the data itself is stored in plaintext:

6. Data Retention

7. Your Rights

You have the right to:

Limitation on deletion: Deleting your account removes data from our systems, but it cannot recall data already transmitted to third-party AI providers. Data previously sent to AI services for processing may be retained by those providers according to their own policies, and we have no ability to delete it from their systems.
Automated decision-making: The app uses AI to extract data from purchase orders and suggest product matches. These suggestions are always presented for your review before any action is taken in Shopify. No automated decisions with legal or significant effects are made without human review.

8. Cookies & Sessions

We use a single session cookie for authentication. This cookie is essential for the app to function (keeping you logged in). We do not use advertising cookies, tracking pixels, or third-party analytics.

9. Data Processing for Shopify Merchants

When you connect your Shopify store, the app accesses customer personal data (names, emails, addresses) solely to match purchase order contacts against your existing Shopify customers and to populate draft orders. This data is:

10. Children's Privacy

This app is a B2B tool designed for business use. We do not knowingly collect data from anyone under the age of 18.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated through the app. The "Last updated" date at the top reflects the most recent revision.

12. Contact

If you have questions about this privacy policy or your data, contact us:

B2B Order Flow

Email: privacy@b2borderflow.com

Website: b2borderflow.com