Privacy policy
Last updated: August 9, 2026
Wholesale Studio provides a business-to-business ordering portal and order-management workflow for Shopify merchants. This policy explains the information we process when a merchant installs the app or a merchant's authorized wholesale buyer uses it.
Information we process
- Store information, app permissions, and encrypted Shopify access credentials needed to operate the installed app.
- Buyer identifiers, name, email address, company and company-location membership, and saved shipping-address details requested from Shopify.
- Wholesale order requests, purchase-order numbers, notes, line items, prices, invoice state, payment state, and Shopify order identifiers.
- Order details, shipping contact details, and selected inventory and origin-location identifiers sent to GoodDay when the merchant enables that integration and releases an order to its ERP.
- Limited security and diagnostic logs used to protect and operate the service. We do not sell personal information or use it for advertising.
How we use information
We process information only to authenticate users, enforce store and company access, display the merchant's catalog, create and manage wholesale order requests, send Shopify invoices, synchronize configured ERP orders, provide support, prevent abuse, and comply with law.
Sharing and subprocessors
Information is shared with Shopify as necessary to provide the app and with infrastructure providers that host the application and database. When a merchant connects GoodDay, the order, shipping, and origin-location information required to create that merchant's ERP sales order is sent to GoodDay. We do not disclose data to unrelated third parties except when legally required or to protect the service.
Retention and deletion
We retain merchant data while the app is installed and only as long as needed to provide the service or meet legal obligations. Shopify privacy webhooks trigger customer-data exports and erasure workflows. Customer identifiers and locally retained shipping snapshots are removed when a valid erasure request is processed. Store data is deleted after Shopify sends the shop-redaction request following uninstall. Merchants are responsible for applying their lawful retention policy to records in systems they control, including a connected ERP.
Security
Data is encrypted in transit. Shopify and GoodDay credentials are also encrypted at the application layer before storage. Production data is tenant-scoped, access is limited to service operations and authorized personnel, and access or security incidents are investigated under our incident-response process.
Your choices and requests
Buyers should normally contact the Shopify merchant that invited them. Merchants can contact us to request access, correction, or deletion of information processed by the app. We respond to verified privacy requests within the time required by applicable law.
Contact
Email us at beamer@working.studio. You can also visit our support page.