This policy describes how RippleStep (“we”, “us”) collects, uses, stores, and shares information when a merchant installs and uses POinbox (listed as “POinbox - PDF to Order”), a Shopify app that turns purchase-order files and inbound email into Shopify draft orders.
This describes our product practices. It is not legal advice. Privacy laws differ by country.
1. Who we are
POinbox is operated by RippleStep. The app runs inside Shopify Admin. We are not established in the European Economic Area. POinbox is a B2B merchant tool and is not directed at children.
Questions: [email protected]. If a law requires a postal address, email us and we will provide it.
2. Information we collect through Shopify’s APIs
After a merchant installs POinbox, Shopify gives us an access token for that shop. We use Shopify’s Admin API only to run the app:
- Shop domain and offline session tokens so the app can act on the merchant’s behalf.
- Staff email from an online Shopify session when Shopify provides one, used as the actor on audit logs. Sign-in is through Shopify; we do not collect a separate password.
- Products and variants (SKU, barcode, title, price) to match purchase-order lines.
- Customers and B2B companies (name, email, company and location names and IDs) to match the buyer and attach them to a draft order. We look these records up; we do not create or edit Shopify customer profiles.
- Draft orders we create (IDs, line items, and the assigned customer or company).
We do not use Shopify data for advertising, remarketing, or sale.
3. Information we collect from merchants
Merchants (and people who email the shop’s POinbox address) provide:
- Purchase-order files uploaded in Admin (PDF, CSV, XLSX, DOCX, HTML, TXT, and similar), including file name, type, size, and contents.
- Inbound email: sender address, recipient, subject, body, and attachments, when the merchant uses email ingest.
- App settings: inbound mailbox token, automation preferences, price mismatch tolerance, and mapping rules (SKU aliases, sender-to-customer mappings, units of measure).
- Job and audit logs (parse, match, validate, draft creation), including error messages and actions taken in the app.
Purchase orders often include buyer business details: company name, buyer name, email, phone if present, billing and shipping addresses, payment terms, line-item descriptions, quantities, and prices. We store those fields so the merchant can review exceptions and create a draft order.
4. Information we collect from merchants’ customers
POinbox is not installed on the storefront. We do not drop cookies, pixels, or other trackers on buyers’ devices, and we do not log how customers browse a merchant’s store.
Buyer personal data reaches us only because it appears in a purchase order the merchant uploads or forwards, or because we look up a matching Shopify customer or company to build a draft order.
5. How we use the information
We use this information only to provide POinbox:
- Parse purchase orders and extract headers and line items.
- Match buyers to Shopify customers or B2B companies, and match lines to product variants.
- Show a review screen for exceptions, then create a Shopify draft order when the merchant (or automation) confirms.
- Remember mapping rules the merchant confirms, for later POs.
- Operate, secure, debug, and support the app.
We do not sell personal information. We do not use it to advertise to merchants or their customers. We do not use it to train general-purpose AI models of our own.
To extract data from unstructured files, we may send table headers and sample rows, document text, or page images to a language-model provider (Groq by default, or OpenAI if the merchant environment is configured that way). That content can include names, emails, addresses, and line items from the purchase order. Those providers return structured fields; we do not use that processing for marketing.
6. Service providers
We share data with processors only to run POinbox:
- Shopify — authentication, Admin API, draft orders.
- Railway — application hosting and PostgreSQL.
- Object storage — S3-compatible storage for purchase-order files and inbound email MIME.
- Resend — inbound email receiving when the merchant uses email ingest.
- Groq (and OpenAI if configured) — classification and extraction of purchase-order content.
We may also disclose information if required by law, to protect the app or merchants from abuse, or as part of a merger or sale of the business (the buyer would have to honor this policy or give notice of changes).
7. Where data is stored and transferred
We are not established in Europe. The app and database run on Railway in the Netherlands (europe-west4). Purchase-order files sit in S3-compatible object storage. Resend, Groq, OpenAI (if used), and Shopify may process data in the United States or other countries where they operate.
If you are in the EEA, UK, or a similar jurisdiction, some personal data is transferred outside your region when those processors are used. We rely on Shopify’s platform terms, our contracts with processors, and (where used) standard contractual clauses or equivalent transfer tools those processors provide.
8. How long we keep data
- Shopify session tokens are kept while the app is installed.
- Purchase orders, files, inbound email, mappings, and audit logs are kept while the merchant uses the app, so history and review work are not lost.
- When the merchant uninstalls, we delete remaining shop data (sessions, purchase orders, files, inbound email, mappings, and audit logs). Shopify may later send a shop/redact webhook; that request runs the same deletion and is safe to repeat.
- When Shopify sends a customers/redact webhook, we clear that person’s buyer name, email, addresses, and Shopify customer links on matching records, and we remove matching sender mappings. We keep the purchase-order row for merchant history. Original files and email MIME may still contain that person’s details until the shop’s data is deleted (uninstall or shop/redact). We will not complete a deletion if a law requires us to keep a specific record.
Backups, if any, expire on the backup cycle. Cached copies at processors follow their retention settings.
9. Your rights and requests
Merchants and individuals may have rights to access, correct, delete, or restrict processing of personal data, depending on where they live (including GDPR, UK GDPR, and US state laws such as CPRA).
Email [email protected] from the merchant account, or ask the shop owner to contact us on a customer’s behalf. We also handle Shopify’s mandatory compliance webhooks: customers/data_request (we locate matching POinbox records; email us for a copy), customers/redact, and shop/redact.
We do not “sell” or “share” personal information as those terms are used in California law, and we do not use it for cross-context behavioral advertising.
Cookies: we use only what Shopify’s embedded-app session needs for the merchant in Admin. No advertising cookies. No cookies on the storefront.
10. Security
Access to shop data is scoped by Shopify OAuth. Admin screens require an authenticated Shopify session. Inbound email webhooks are verified with the provider’s signature. Files sit in shop-scoped storage. Data is sent over HTTPS. Hosting and storage providers encrypt data at rest. No method is perfect; if we learn of a breach that requires notice, we will notify affected merchants and regulators as the law requires.
11. Changes
We may update this policy. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of POinbox after an update means the revised policy applies to later processing.
12. Contact
RippleStep — POinbox privacy
Email:
[email protected]
App: POinbox, served at
poinbox.ripplestep.com
If you are a merchant’s customer, contact the merchant first. They can reach us, or Shopify can send us a data-request or redaction webhook.