Privacy · Website and app
Privacy, in two parts: this website, and the app.
What does this website collect?
Nothing beyond the server request logs hosting providers record for any website. There are no forms on this site, no cookies are set by the site, there is no analytics, no advertising or tracking pixels, and fonts are self-hosted rather than loaded from a third-party font CDN. The only way to contact Kaupvik from this site is email.
Part one · This website
This website has nothing to collect, so it collects nothing.
No forms anywhere
Nothing you could type into exists on this site, so nothing can be stored in a form database. Email is the only contact route.
No cookies, no analytics
The site sets no cookies. There is no analytics, no advertising and no tracking pixel, so your visit is not followed.
Self-hosted fonts
Fonts come from this site rather than a third-party font CDN, so reading a page sends no request to a font provider.
Standard request logs
The hosting provider processes ordinary server request logs: IP address, user agent, requested URL and timestamp, for security and operations rather than marketing.
Email you choose to send
If you email Kaupvik, the message and the address you sent it from are held in that mailbox so the question can be answered.
Part two · The app
You are the controller. Kaupvik is the processor.
Merchant (controller)
You decide what is in your Shopify store, which staff use the app, and how long you keep orders and customer records.
Kaupvik (processor)
Kaupvik processes merchant customer data only to run the workflow you asked for: match lines, show the context, create the draft order.
Shopify (platform)
Shopify remains the system of record for your catalog, customers, companies, orders, taxes and payment, under your own agreement with Shopify.
A buyer who wants their data accessed, corrected or deleted should ask the merchant first. If the merchant needs help from Kaupvik, email support@kaupvik.com.
Purpose limitation and minimisation
What is processed, why, and how long it stays.
| Data | Why it is processed | Retention |
|---|---|---|
| Products and variants | To match a SKU line from a list to a real Shopify variant, and to offer candidates when there is no exact match. | Read on demand, then kept only as part of the reviewed list. |
| Companies, company locations and purchasing contacts | To review a list in the buying context you select, because that context decides which catalog and price apply. | Read on demand and referenced by the import record. |
| The minimum customer fields needed to select a purchasing contact | To attach the work to the right person at the right company. No customer profile is built. | Limited to the fields the selection needs. |
| The reviewed list and the draft order it produced | To create the draft order you confirmed, and to answer a question about it later. | Kept so an import can be traced to its list, then deleted on request or on app removal. |
| Import records and diagnostic records | To show what happened in the workspace and to investigate a support issue you raise. | Kept for as long as troubleshooting requires. |
Not processed at all: payment details, storefront browsing behaviour, and any write access to products, customers, companies or orders. Prices and availability are computed by Shopify for the selected company location, and Kaupvik keeps no pricing model of its own.
Sub-processors
The three services involved, and what each one does.
| Service | Role | What it handles |
|---|---|---|
| Shopify | Commerce platform | The app runs inside Shopify Admin. Shopify stores your catalog, customers, companies and orders, decides prices and availability for the selected company location, and owns the draft order once created. |
| Vercel | Web and API hosting | Runs the app's web and API deployment. Standard server request logs are processed here for security and operations. |
| Neon | PostgreSQL database | Stores the app records described above, in a database kept separate from the development environment. |
Development and production run as separate Shopify apps, separate deployments and separate databases, so test work never mixes with live store data.
Retention and deletion
How long data stays, and how it is removed.
Records are kept for as long as the workflow and troubleshooting require, and no longer. Two Shopify privacy webhooks, which every app must implement, are in place:
- Customer data request. Shopify notifies the app that a customer has asked for their data, and the app answers with what it holds for that customer.
- Shop deletion. When the app is removed from a store, Shopify notifies the app so the stored store data can be erased.
The app is not launched, so no production merchant data is processed today. This retention approach is the one that will apply at launch.
Access, correction and deletion
How to ask for access, a correction or deletion.
Merchants: email support@kaupvik.com with the store domain and the request. Access means what the app holds for your store, correction means what should be corrected and why, and deletion means what should be erased.
Buyers: contact the merchant you bought from first. They are the controller of your customer data and can action the request directly.
There is no separate privacy mailbox. General questions go to hello@kaupvik.com, and security concerns go to the same address with the subject "Security".
Changes to this notice
How this notice is kept current.
This notice describes the website and the app as they are today. When the app starts processing live merchant data, or when a sub-processor changes, this page is updated before that change takes effect.
Because the app is pre-release, expect a revision before the Shopify App Store listing opens. The support page and the security page are maintained on the same basis.
Last updated: .
Questions merchants ask
Data, prices and what the app will not do.
What data does Quick Order read?
Products and variants, companies and locations, and the minimum customer fields needed to choose a purchasing contact. It requests draft order write access and does not request write access to products, customers, companies or orders.
The security page lists the access scopes and the retention approach in plain language.
Who decides the price a buyer sees?
Shopify does. Kaupvik asks Shopify for eligibility and price in the context of the selected company location and displays the result. It does not run its own pricing engine and does not override catalog rules.
Does Quick Order use AI to guess my order lines?
No. Matching is deterministic and based on the SKU you already use. Every line that needs a judgement is handed to a person, and every write to Shopify follows an explicit confirmation.
AI Native describes how Kaupvik intends to build products over time: suggestions that explain their basis and can be undone. It is not a claim about features that exist today.
Does Kaupvik replace the Shopify admin experience?
No. The app runs inside Shopify Admin with Shopify's own components and respects Shopify staff permissions. Kaupvik does not imitate Shopify's interface, and Shopify remains the system of record for catalog, pricing, customers, orders and payment.
Next step
Ask about data handling before you install.
Pre-release: the App Store destination is reserved, but the listing is not public yet. The link may be unavailable until Shopify publishes it.