POinbox by RippleStep

Privacy Policy

Effective 3 September 2026 · Last updated 3 September 2026

This policy describes how RippleStep (“we”, “us”) collects, uses, stores, and shares information when a merchant installs and uses POinbox (listed as “POinbox - PDF to Order”), a Shopify app that turns purchase-order files and inbound email into Shopify draft orders.

This describes our product practices. It is not legal advice. Privacy laws differ by country.

1. Who we are

POinbox is operated by RippleStep. The app runs inside Shopify Admin. We are not established in the European Economic Area. POinbox is a B2B merchant tool and is not directed at children.

Questions: [email protected]. If a law requires a postal address, email us and we will provide it.

2. Information we collect through Shopify’s APIs

After a merchant installs POinbox, Shopify gives us an access token for that shop. We use Shopify’s Admin API only to run the app:

We do not use Shopify data for advertising, remarketing, or sale.

3. Information we collect from merchants

Merchants (and people who email the shop’s POinbox address) provide:

Purchase orders often include buyer business details: company name, buyer name, email, phone if present, billing and shipping addresses, payment terms, line-item descriptions, quantities, and prices. We store those fields so the merchant can review exceptions and create a draft order.

4. Information we collect from merchants’ customers

POinbox is not installed on the storefront. We do not drop cookies, pixels, or other trackers on buyers’ devices, and we do not log how customers browse a merchant’s store.

Buyer personal data reaches us only because it appears in a purchase order the merchant uploads or forwards, or because we look up a matching Shopify customer or company to build a draft order.

5. How we use the information

We use this information only to provide POinbox:

We do not sell personal information. We do not use it to advertise to merchants or their customers. We do not use it to train general-purpose AI models of our own.

To extract data from unstructured files, we may send table headers and sample rows, document text, or page images to a language-model provider (Groq by default, or OpenAI if the merchant environment is configured that way). That content can include names, emails, addresses, and line items from the purchase order. Those providers return structured fields; we do not use that processing for marketing.

6. Service providers

We share data with processors only to run POinbox:

We may also disclose information if required by law, to protect the app or merchants from abuse, or as part of a merger or sale of the business (the buyer would have to honor this policy or give notice of changes).

7. Where data is stored and transferred

We are not established in Europe. The app and database run on Railway in the Netherlands (europe-west4). Purchase-order files sit in S3-compatible object storage. Resend, Groq, OpenAI (if used), and Shopify may process data in the United States or other countries where they operate.

If you are in the EEA, UK, or a similar jurisdiction, some personal data is transferred outside your region when those processors are used. We rely on Shopify’s platform terms, our contracts with processors, and (where used) standard contractual clauses or equivalent transfer tools those processors provide.

8. How long we keep data

Backups, if any, expire on the backup cycle. Cached copies at processors follow their retention settings.

9. Your rights and requests

Merchants and individuals may have rights to access, correct, delete, or restrict processing of personal data, depending on where they live (including GDPR, UK GDPR, and US state laws such as CPRA).

Email [email protected] from the merchant account, or ask the shop owner to contact us on a customer’s behalf. We also handle Shopify’s mandatory compliance webhooks: customers/data_request (we locate matching POinbox records; email us for a copy), customers/redact, and shop/redact.

We do not “sell” or “share” personal information as those terms are used in California law, and we do not use it for cross-context behavioral advertising.

Cookies: we use only what Shopify’s embedded-app session needs for the merchant in Admin. No advertising cookies. No cookies on the storefront.

10. Security

Access to shop data is scoped by Shopify OAuth. Admin screens require an authenticated Shopify session. Inbound email webhooks are verified with the provider’s signature. Files sit in shop-scoped storage. Data is sent over HTTPS. Hosting and storage providers encrypt data at rest. No method is perfect; if we learn of a breach that requires notice, we will notify affected merchants and regulators as the law requires.

11. Changes

We may update this policy. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of POinbox after an update means the revised policy applies to later processing.

12. Contact

RippleStep — POinbox privacy
Email: [email protected]
App: POinbox, served at poinbox.ripplestep.com

If you are a merchant’s customer, contact the merchant first. They can reach us, or Shopify can send us a data-request or redaction webhook.