Skip to content

Privacy policy

Flowtopus Privacy Policy

Effective date: June 21, 2026

Overview

Flowtopus helps Shopify merchants run supply-chain routines across inventory, supplier documents, purchase orders, reminders and operational alerts.

This policy explains what data Flowtopus processes, why it is needed, and how merchants can request access, correction, export or deletion.

Merchant store data

Flowtopus processes Shopify shop identity, product, variant, inventory location, inventory level, order line, cancellation and refund signals needed to calculate stock risk, reorder points and replenishment routines.

When a merchant records a purchase order receipt, Flowtopus may write the approved received quantity to the mapped Shopify inventory location and then rely on Shopify inventory webhooks as confirmation.

Flowtopus does not use Shopify customer contact data to run its core supply-chain workflow and does not sell merchant or customer data.

Supplier operations data

Merchants may store suppliers, contact e-mails, commercial terms, purchase orders, payment milestones, landed costs, receipt exceptions and supplier document attachments.

Supplier invoices, packing slips or images may be processed by the configured extraction model so Flowtopus can propose structured lines for human review before stock impact.

How data is used

Flowtopus uses operational data to show inventory risk, draft purchase orders, route merchant approvals, reconcile supplier documents, send merchant action digests and alert admins when the supply pipeline is stale or blocked.

AI-assisted extraction is used only to prepare reviewable supplier document data; Flowtopus keeps the merchant approval step before supplier documents update incoming stock.

Processors

Flowtopus relies on infrastructure and service providers including Convex for application data, Clerk for authentication, Resend for e-mail delivery and inbound documents, OpenRouter or the configured model provider for document extraction, and the production hosting provider used for the web and worker services.

Processors are used only to operate the product, secure access, deliver messages, process documents, monitor reliability and support merchant workflows.

Shopify privacy requests

Flowtopus handles Shopify mandatory privacy webhooks for customers/data_request, customers/redact, shop/redact on the shared Shopify webhook endpoint.

A shop redaction request removes Shopify-specific integration credentials and Shopify-derived operational rows for that shop. Customer redaction and data request webhooks are acknowledged without persisting unnecessary customer contact fields.

Retention and deletion

Flowtopus retains operational records while the merchant account is active so purchase orders, supplier documents, stock decisions and audit trails remain explainable.

Merchants can request deletion or export of account data. Some records may be retained where required for security, billing, audit, dispute resolution or legal obligations.

Security

Flowtopus uses organization-scoped access controls, role checks for sensitive actions, encrypted Shopify access tokens, signed webhook validation and tenant checks on dashboard and agent operations.

No public dashboard query exposes raw Shopify access tokens, agent tokens or private webhook secrets.

Contact

For privacy questions, data requests or deletion requests, contact [email protected].

Merchants should include their store domain and organization name so Flowtopus can locate the relevant account safely.