← OrderBased

Privacy Policy

Last updated August 2026

Who we are

OrderBased is order-management and customer-retention software for florists and similar retailers. This policy explains what we collect, why, and how long we keep it.

Data we process for merchants

When you connect a Shopify store, we receive order webhooks and store the following so your team can fulfil and follow up on orders:

  • Order details: number, line items, totals, status, delivery date and time window
  • Customer contact details: name, email address and phone number
  • Delivery address for each order
  • Order notes, including delivery or pickup details supplied at checkout

We request the read_orders scope only. The integration is strictly one-way and read-only: OrderBased never creates, edits or cancels anything in your Shopify store, never alters prices, shipping or discounts, and never adds upsells or charges to a buyer's order.

Why we process it

To display and manage orders, to let staff contact customers about their orders, and to surface repeat-purchase reminders. We do not sell personal data, and we do not use it to train machine-learning models for other customers.

Where it is stored

Each merchant's data lives in a separate, isolated database. Shopify access tokens are encrypted at rest. Access within your workspace is limited by role (owner, manager, staff, driver).

How long we keep it

Order and customer records are kept for as long as your workspace is active, because they are your business records. If you uninstall the app, we stop syncing immediately and delete the Shopify data we hold within 48 hours of Shopify's redaction request. You can ask us to delete your workspace at any time.

Your customers' rights

We support Shopify's privacy webhooks. When a shopper asks Shopify for their data, we compile what we hold and send it to the merchant, who is the data controller. When a shopper asks to be erased, we remove their name, email, phone, address and any free-text notes, keeping only the anonymised financial record the merchant needs for accounting.

Sub-processors

We use third parties for hosting, transactional email, payment processing (for non-Shopify subscriptions) and optional AI assistance. Each is bound by contract to process data only on our instructions.

Contact

For any privacy request, email [email protected]. We respond within 30 days.