Privacy Policy | SuiteFleet Connector for Shopify
1. Introduction
This Privacy Policy describes how SuiteFleet Inc. ("SuiteFleet", "we", "us", or "our") collects, uses, stores, and protects information obtained through the SuiteFleet Connector Shopify application (the "App").The App integrates your Shopify store with the SuiteFleet last-mile delivery management platform so that orders are automatically dispatched, tracked, and fulfilled.By installing or using the App you agree to the practices described in this policy. If you do not agree, please uninstall the App.
2. Information We Collect
We only access Shopify data that is necessary for the App to function. The specific data we collect or access includes:
2.1 Store & Session Information
- Shopify store domain and shop name.
- Shopify session tokens (access tokens, scopes) required to authenticate API calls on your behalf.
- Merchant account details (name, email, locale) associated with the Shopify session.
2.2 Order & Fulfillment Data
- Order details: order ID, line items (product title, quantity), total price, currency, payment status, custom attributes (delivery date, delivery time, delivery notes), and shipping address (street, city, province, zip, country, phone number).
- Fulfillment details: fulfillment ID, tracking number, tracking URL, fulfillment status, and associated location ID.
2.3 Location Data
- Shopify location information (name, address, phone) used as the "ship-from" origin when creating delivery tasks.
2.4 Customer Data
- End-customer name, delivery address, and phone number as they appear on Shopify orders — used solely to create and route delivery tasks.
3. Information We Collect
- Order-to-Task Synchronisation: When a fulfillment is created in Shopify, the App automatically maps the order and fulfillment data into a delivery task and sends it to the SuiteFleet platform.
- Status Updates: The App receives webhook callbacks from SuiteFleet (e.g., IN_TRANSIT, OUT_FOR_DELIVERY, DELIVERED, FAILED) and updates the corresponding Shopify fulfillment status and tracking information.
- Order Cancellation: When an order is cancelled in Shopify, the App forwards the cancellation to SuiteFleet.
- Delivery Scheduling Widget: The App stores your delivery calendar configuration and exposes it via Shopify theme app extensions so your customers can choose a delivery date and time slot at checkout.
- Logging & Troubleshooting: Task creation logs, task update logs, and cancellation logs are stored in our database to help diagnose integration issues and ensure data integrity.
- Authentication: Session and credential data is used to authenticate requests to both the Shopify Admin API and the SuiteFleet API.
4. Data Sharing and Disclosure
We do NOT sell, rent, or trade your data. We share data only in the following limited circumstances:
- SuiteFleet Platform: Order, fulfillment, customer delivery address, and item data is transmitted to your SuiteFleet tenant to create and manage delivery tasks. This is the core purpose of the App.
- Shopify: We write back fulfillment status updates, tracking URLs, and air-waybill (AWB) numbers to Shopify via the Admin GraphQL API.
- Infrastructure Providers: Data is stored in our database hosted on secure cloud infrastructure. Our hosting providers act as data processors under our instructions.
- Legal Obligations: We may disclose data if required to do so by law, regulation, subpoena, or court order.
5. Data Storage and Security
All data is stored in a database. Access to the database is restricted to authorised services and personnel. We implement the following safeguards:
- Encrypted connections (TLS/SSL) for all data in transit.
- Shopify access tokens and SuiteFleet API credentials are stored server-side only and never exposed to the browser.
- Webhook requests from Shopify are validated using HMAC verification.
- Webhook requests from SuiteFleet are authenticated using client ID and client secret headers.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Session Data: Retained while the App is installed. Upon uninstallation the session record (including SuiteFleet credentials) is deleted.
- Task & Update Logs: Order-to-task logs, task update logs, and cancellation logs are retained for a reasonable period (typically 12 months) for operational support and dispute resolution, after which they are purged.
- Delivery Calendar Configs: Retained while the App is installed and deleted upon uninstallation.
7. Shopify Mandatory Compliance Webhooks
The App implements all mandatory Shopify compliance webhook endpoints:
- Customer Data Request (customers/data_request) — we acknowledge the request and can provide a report of any stored personal data upon request.
- Customer Data Erasure (customers/redact) — upon receiving this webhook we delete or anonymise any personal customer data associated with the requesting customer.
Changes
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices, technologies, subprocessors, legal requirements, or for other operational, legal, or regulatory reasons.
Contact Us
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at info@azdan.com or by mail using the details provided below:
Azdan
Mazaya Business Avenue AA1, 2403, JLT, Dubai, UAE