Privacy Policy
Last updated: 2026-06-29
SweetRelease Pre-orders ("the App") is provided by International Supply Consulting ("we", "us"). It is a Shopify app that holds preorder fulfillment orders at a gated location and releases them to a live location on the merchant's schedule. This policy explains what data the App processes, why, how long it is kept, and the rights available to merchants and their customers.
Our role
For personal data belonging to a merchant's customers, the merchant is the data controller and the App is a data processor acting on the merchant's instructions. We process customer personal data only to provide the App's functionality to that merchant.
What we collect and why
| Data | Purpose |
|---|---|
| Customer name and email (per held order) | Show ops who an order belongs to in the queue |
| Order identifiers and item summary (SKUs/titles) | Detect, hold, and release the correct preorder |
| Shopify access tokens & staff session details | Authenticate API calls on the merchant's behalf |
| Shop record (domain, configured locations, install timestamps) | Operate and scope the App per shop |
| Webhook event metadata (identifiers only — no name, email, phone, or address) | Debugging, de-duplication, and audit |
Data minimization. We do not store raw webhook payloads — incoming webhooks are reduced to non-personal identifiers before storage. We do not request the customer-read scope; the customer name we display is read from the order's own shipping/billing address, not from the customer record.
What we do NOT do
- We do not sell or share personal data (CCPA/CPRA "Do Not Sell or Share").
- We do not use customer data for advertising or profiling.
- We do not transfer data to any party other than the sub-processors below.
Sub-processors
- Shopify — source of order/fulfillment data; store hosting.
- Vercel — application hosting / compute (United States).
- Neon (Postgres) — application database (United States).
International transfers. Data is stored in the United States. For EU/UK merchants and customers, transfers rely on the applicable safeguards of these sub-processors (e.g. EU-US Data Privacy Framework and/or Standard Contractual Clauses). Merchants requiring an EU data region should contact us before installing.
Data retention
- Webhook event metadata: deleted after 30 days.
- Compiled data-access requests: deleted after 30 days.
- Released orders: customer name and email are stripped from released queue items after 90 days; non-personal operational fields may be retained for reporting.
- On uninstall: processing stops and all shop data is deleted within ~48 hours (via Shopify's
shop/redact), or sooner on request.
Your rights (GDPR / CCPA / CPRA and similar)
Customers exercise their rights through the merchant (the controller). When a merchant forwards a request via Shopify's mandatory compliance webhooks, the App automatically:
- Access / "right to know" — compiles the data the App holds about the customer for the merchant.
- Deletion / "right to delete" — removes the customer's personal data (name, email, item details) from the App.
- Shop deletion — deletes all of the shop's data from the App.
Security
- All connections use TLS.
- Database access is restricted to the application via secrets.
- Every webhook is verified by signature; every admin route is authenticated and scoped to the requesting shop; scheduled jobs require a secret token.
Data Processing Agreement
Our Data Processing Addendum (DPA) governs how we process personal data on the merchant's behalf, including sub-processors, security measures, and breach notification.
Contact
International Supply Consulting — for privacy questions or to exercise data rights: patrickward@isc-na.com.