Effective date: 25 July 2026
Simple B2B ("the App") is operated by Frankenstein Digital ("we", "us"). This policy explains what data the App collects when a merchant installs it on their Shopify store, and how that data is used.
When a store installs the App, Shopify issues us an access token for that store. We store this token, together with the store's Shopify domain, so the App can continue to operate without asking the merchant to sign in again. This is the only data we hold in our own database.
The App does not access, collect, or store any personal data about a merchant's customers. It does not request permission to read customer names, emails, addresses, or order history. The only Shopify data it reads or writes is product information and Company records (Shopify's native B2B feature) — specifically, which products are assigned to which company. That assignment is stored directly on the Company record inside the merchant's own Shopify store, not in our database.
The access token is used solely to make the API calls the App needs to function: reading product and company data, and writing the merchant's chosen product assignments back to Shopify. We do not use any data for advertising, analytics profiling, or any purpose beyond operating the App's core feature.
We do not sell or share data with third parties, other than the infrastructure providers needed to run the App (Shopify itself, and our hosting provider, Railway). These providers process data only on our behalf, to deliver the service.
If a merchant uninstalls the App, we delete the stored access token immediately. As a safeguard, we also process Shopify's shop-redaction webhook, which independently confirms deletion of any remaining data within 48 hours of uninstall. Product-to-company assignments live on the merchant's own store and are managed by Shopify according to its own data retention rules.
Because the App never collects personal data about a merchant's customers, we have nothing to provide or delete in response to an individual customer's data request — there is no customer data on our side to act on.
All communication with the App happens over HTTPS. Authentication is handled entirely through Shopify's standard OAuth flow; we never see or store a merchant's Shopify password.
If this policy changes, the updated version will be posted at this same address with a new effective date.
Questions about this policy or how the App handles data can be sent to hello@frankensteindigital.com.