Privacy Policy
Last updated 24 July 2026
ApprovePilot (“ApprovePilot”, “we”, “us”) is a Shopify application that lets merchants collect, vet, and approve wholesale (B2B) account applications. This policy explains what data we handle, why, how long we keep it, and the choices you have. Questions? Email support@approvepilot.app.
Who this policy is for
- Merchants who install ApprovePilot on their Shopify store.
- Wholesale applicants — the buyers who submit a merchant’s application form.
- Website visitors who join our launch list at approvepilot.app.
Data we collect
From merchants (via Shopify). When you install the app we receive your store domain, store name, and store contact email, and the identifier of the staff user taking each action (for the audit trail). We request only these Shopify permissions: read/write companies, read/write customers, and read payment-terms templates. We request no access to orders, products, themes, or checkout.
From wholesale applicants (via the application form). The information a merchant’s form collects — typically business name and contact details (name, email, phone, address), tax/VAT identifiers, up to three resale or tax-exempt certificate files with their expiry dates, and optional trade references and notes.
From website visitors. If you join the launch list, the email address you enter. It is used only to notify you when ApprovePilot becomes available.
We do not use advertising trackers, and we do not build cross-site profiles.
How we use data
- To run the application, vetting, and approval workflow.
- To create the B2B company, contact, location, and payment terms in the merchant’s Shopify admin when the merchant approves an applicant.
- To send transactional emails (application received / approved / rejected / more-info to applicants; a new-application alert and certificate-expiry reminders to the merchant).
- To maintain a per-application audit trail for the merchant.
We do not sell personal data, and we do not use it to train machine- learning models.
Where data is stored & how it’s protected
- Application records are stored in a PostgreSQL database hosted on Railway.
- Certificate files are stored in a private Cloudflare R2 bucket — never public, never in Shopify Files. They are viewed only through short-lived signed links generated by the app.
- Data is encrypted in transit (HTTPS/TLS).
Service providers (sub-processors)
We share data only with the providers that make the app work:
- Shopify — to read store data and create B2B companies/customers on approval.
- Railway — application hosting and database.
- Cloudflare R2 — private storage for certificate files.
- Resend — delivery of transactional and notification emails.
How long we keep it & how it’s deleted
- We keep application data for as long as the merchant keeps the app installed and the record active.
- When a merchant uninstalls ApprovePilot, we purge that store’s data, including its certificate files.
- We honor Shopify’s GDPR webhooks: a data-request returns the stored data, and an erasure request deletes the relevant records and the associated certificate files — not just database rows.
Your rights
Depending on where you live (for example under the GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Wholesale applicants: because the merchant is the controller of your application, please direct requests to the merchant you applied to, or contact us at support@approvepilot.app and we will help route them.
Cookies & tracking
The embedded merchant app authenticates with Shopify session tokens, not tracking cookies. The marketing site sets no advertising or analytics tracking cookies.
Children
ApprovePilot is a business tool and is not directed to children, nor do we knowingly collect data from them.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.
Contact
ApprovePilot · support@approvepilot.app