This policy explains how Triple-Aces processes information when a merchant installs or uses the Triple-Aces Shopify app. It applies to the app, its merchant workspace, and the support and fulfillment operations connected to that workspace.
Information we process
Shop and merchant information
We process the shop name, permanent myshopify.com domain, store currency, merchant contact email, granted access scopes, installation status, and Shopify authentication sessions.
Order and fulfillment information
The app reads order identifiers, dates, payment and fulfillment status, destination country, tracking information, line items, SKUs, quantities, and order prices. The app does not request customer email, phone number, full address, customer name, or recipient name through the Shopify API.
Triple-Aces operational information
We process organization settings, store connections, onboarding service requirements, balances, top-ups, fulfillment charges, invoices, and audit events. An organization can also have a separately approved Google Sheet data source that may contain order and logistics information.
Technical information
We generate security, authentication, error, and audit logs needed to operate, protect, and troubleshoot the app. We do not use the app to track visitors on a merchant's storefront for advertising.
How we use information
- Authenticate the merchant and connect authorized stores.
- Provide order, balance, invoice, and fulfillment visibility.
- Keep each merchant organization and its data isolated.
- Provide support, investigate errors, and prevent misuse.
- Meet privacy, accounting, security, and legal obligations.
We do not sell personal information and do not use Shopify customer data for independent advertising or unrelated profiling.
Service providers and international processing
We use Shopify and carefully selected infrastructure, database, hosting, monitoring, and workspace providers to operate the app. Information may be processed in countries other than the country in which a merchant or customer is located. We limit provider access to the services required and use contractual and technical safeguards appropriate to the data and processing.
Retention and deletion
Shopify sessions are deleted when the app is uninstalled. Shopify sends the shop redaction request after uninstall, and the app then removes access credentials, pseudonymizes the shop connection, and removes organization data-source access when no active store remains.
Customer access and deletion requests are reviewed against both the app database and the organization's approved external data source. We respond within the period required by Shopify. Financial ledger, invoice, fraud-prevention, and audit records may be retained where required for accounting, tax, contractual, legal, or dispute purposes. Retained records are restricted and are not used for marketing.
Security and tenant isolation
Production and development environments use separate Shopify clients and databases. Access is authenticated through Shopify, secrets remain server-side, and every store, data source, balance, and ledger query is constrained by its organization. Posted financial entries are immutable and corrections use reversal entries.
Your rights and requests
Depending on applicable law, individuals may have rights to access, correct, delete, or restrict processing of personal information. Customers should normally submit a request through the Shopify merchant with whom they placed an order. Merchants can contact us directly.
Privacy contact: support@triple-aces.com
Changes to this policy
We may update this policy when the app, providers, or legal requirements change. We will update the effective date and provide additional notice when a material change requires it.