Privacy Policy

Last updated: May 2026

Introduction

Keystone B2B ("we", "our", or "us") operates a Shopify application that helps merchants sync their store data with our platform. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Shopify app.

By installing and using our app, you agree to the collection and use of information in accordance with this policy.

Information We Collect and Why

When you install our app, we collect only the information necessary to provide our services through Shopify's APIs. Below we explain what data we collect and the specific purpose for each data type:

Store Information

DataPurpose
Store name and domainTo identify your store and display it in your dashboard
Store owner emailTo create your admin account and send important notifications
Store plan typeTo enable features appropriate to your Shopify plan (e.g., B2B)
Currency and timezoneTo display data in your preferred format and generate accurate reports

Order Data

DataPurpose
Order numbers and amountsTo track sales, generate reports, and calculate commissions
Line itemsTo provide product-level sales analytics and inventory insights
Shipping and fulfillment statusTo track order progress and send shipment notifications
Payment statusTo reconcile payments and generate accurate financial reports

Product Data

DataPurpose
Product titles and SKUsTo identify products in orders and generate sales reports
Pricing informationTo calculate margins, commissions, and revenue analytics
Inventory levelsTo provide inventory visibility and availability information
Product variantsTo enable detailed size/color level reporting and ordering

Customer Data (Protected)

The following data is classified as protected customer data under Shopify's policies and receives additional security protections:

DataPurpose
Customer namesTo identify customers and personalize communications
Email addressesTo send order confirmations and shipment notifications
Phone numbersFor shipping carrier requirements and urgent delivery notifications
Shipping addressesTo fulfill orders and calculate shipping costs
Billing addressesTo generate invoices and process payments
Order historyTo provide customer purchase analytics and reorder suggestions
B2B company associationsTo manage wholesale accounts and company-level purchasing

Data Minimization

We only collect and process the minimum data necessary to provide our services. We do not collect or store sensitive information such as payment card details, Social Security numbers, or government IDs. Payment processing is handled entirely by Shopify.

How We Use Your Information

We use the collected information to:

  • Synchronize your Shopify store data with our platform
  • Process and track orders across systems
  • Generate reports and analytics
  • Provide customer support
  • Improve our services and develop new features
  • Communicate important updates about our service

Data Storage and Security

We take the security of your data seriously. Your information is:

  • Stored on secure, encrypted servers
  • Protected by industry-standard security measures
  • Accessible only to authorized personnel
  • Never sold to third parties

We use Supabase for data storage, which employs encryption at rest and in transit. Access tokens are stored securely and are only used to communicate with Shopify's APIs on your behalf.

Data Retention

We retain different types of data for different periods based on business necessity and legal requirements:

Data TypeRetention Period
Active merchant dataDuration of app installation
Customer data after uninstallDeleted within 30 days of erasure request
Compliance and audit logs7 years (legal requirement)
System logs90 days

When you uninstall the app:

  • Your access token is immediately revoked
  • Your store is marked as inactive in our system
  • All protected customer data is permanently deleted within 30 days of receiving Shopify's shop data erasure request, as required by GDPR

Your Rights

Under applicable data protection laws (including GDPR and CCPA), you have the right to:

  • Access - Request a copy of the data we hold about you
  • Rectification - Request correction of inaccurate data
  • Erasure - Request deletion of your data
  • Portability - Request a machine-readable copy of your data
  • Objection - Object to certain processing of your data

To exercise any of these rights, please contact us at privacy@keystoneb2b.io. Storefront customers should typically contact the merchant whose store they purchased from; Shopify forwards such requests to us via the customers/data_request webhook and we deliver the gathered data to the merchant within 30 days.

Third-Party Services (Sub-processors)

We use the following third-party services to process your data. Each sub-processor is contractually bound to protect your data:

ServicePurposeLocation
ShopifyAccessing your store data via APIsUnited States
SupabaseSecure database and authenticationUnited States
VercelApplication hostingUnited States
AWS EventBridgeReal-time webhook processingUnited States

Each sub-processor maintains SOC 2 certification and encryption standards. We have Data Processing Agreements in place with all sub-processors.

Data Processing Agreement

By using our app, you enter into a Data Processing Agreement (DPA) with us that governs our processing of personal data on your behalf. The DPA includes Standard Contractual Clauses for international data transfers and details our security measures. For a copy of the DPA, please contact us at privacy@keystoneb2b.io

Cookies

Our app uses essential cookies to manage your session during the installation and onboarding process. These cookies are necessary for the app to function and do not track you across other websites. We do not use advertising or analytics cookies.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the app after any changes constitutes acceptance of the new policy.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: