Last updated August 2026
OrderBased is order-management and customer-retention software for florists and similar retailers. This policy explains what we collect, why, and how long we keep it.
When you connect a Shopify store, we receive order webhooks and store the following so your team can fulfil and follow up on orders:
We request the read_orders scope only. The integration is strictly one-way and read-only: OrderBased never creates, edits or cancels anything in your Shopify store, never alters prices, shipping or discounts, and never adds upsells or charges to a buyer's order.
To display and manage orders, to let staff contact customers about their orders, and to surface repeat-purchase reminders. We do not sell personal data, and we do not use it to train machine-learning models for other customers.
Each merchant's data lives in a separate, isolated database. Shopify access tokens are encrypted at rest. Access within your workspace is limited by role (owner, manager, staff, driver).
Order and customer records are kept for as long as your workspace is active, because they are your business records. If you uninstall the app, we stop syncing immediately and delete the Shopify data we hold within 48 hours of Shopify's redaction request. You can ask us to delete your workspace at any time.
We support Shopify's privacy webhooks. When a shopper asks Shopify for their data, we compile what we hold and send it to the merchant, who is the data controller. When a shopper asks to be erased, we remove their name, email, phone, address and any free-text notes, keeping only the anonymised financial record the merchant needs for accounting.
We use third parties for hosting, transactional email, payment processing (for non-Shopify subscriptions) and optional AI assistance. Each is bound by contract to process data only on our instructions.
For any privacy request, email [email protected]. We respond within 30 days.