Privacy Policy
Last updated: August 1, 2026
OrderLink Up ("the app") is a Shopify app that imports historical order data into a merchant's Shopify store from a CSV or Excel file. This policy explains what data the app collects, how it's used, and how it can be removed.
Information we collect
When a merchant uses OrderLink Up, we process:
- Order data from uploaded files — customer name, email, phone number, shipping and billing address, and order/product details contained in the file the merchant uploads.
- Shopify store and session data — obtained via Shopify's standard OAuth flow when the app is installed, used only to authenticate API requests to the merchant's own store.
- Import records — a log of each import job (filename, row count, status, and which Shopify orders it created), so the merchant can review history and roll back an import if needed.
How we use this information
Order data from an uploaded file is used solely to create the corresponding draft or completed orders in the merchant's own Shopify store via the Shopify Admin API. Import records are kept so the merchant can view their import history and reverse an import. We do not use this data for any other purpose, and we do not sell it.
Data storage and sharing
Data is stored in a hosted PostgreSQL database and processed by our application server. The only third party we share data with is Shopify itself, via the Admin API calls required to create orders. We do not share merchant or customer data with any other third party.
Data retention and deletion
- Import records — including any personal data they contain — are automatically deleted 24 months after creation, or sooner if the merchant deletes them manually.
- Merchants can permanently delete any import's history at any time from the app's Activity page — this removes our stored record of that import, though it does not affect orders already created in Shopify.
- OrderLink Up implements Shopify's mandatory privacy webhooks: a customer data request is logged for manual fulfillment, a customer redaction request results in the affected order's stored data being redacted, and a shop redaction request (sent after the app is uninstalled) results in all of that shop's data being permanently deleted from our systems.
- We keep a minimal access log (which shop, what action, when — never the personal data itself) for security accountability, including after the records above are deleted.
Security
Data is encrypted in transit (HTTPS) and at rest. Access to the merchant's store is scoped to the minimum permissions the app needs (product lookup, and order/draft order creation) and is authenticated using Shopify's standard OAuth token flow. Further detail on our security and data-processing practices is available in our Terms of Service & Data Processing Agreement.
Changes to this policy
If this policy changes, the updated version will be posted at this same URL with a revised "Last updated" date.
Contact
Questions about this policy or your data can be sent to support@orderlinkup.app (replace with your real support address before publishing).