Privacy

Last updated 22 August 2026

APPNOLIO is software a merchant installs on their own store. Almost everything it handles belongs to that merchant, and we handle it on their instructions: they are the controller, we are the processor. This page says what we hold, how long we hold it, and who else can see it - in the same terms the software actually enforces, not in terms we would like to be true.

What we process, and whose it is

Two different things, with different rules. Merchant data is the account itself - the people who sign in, their roles, the store's settings, the credentials that let us talk to Shopify on the store's behalf. Buyer data is what arrives from the store: orders, and the names, e-mail addresses, phone numbers and shipping addresses attached to them.

We are the controller of the first and the processor of the second. A merchant decides why their buyers' data is handled; we only carry out that decision. If a merchant leaves, their buyers' data leaves with them.

How long we keep it

Three clocks, and they are deliberately different lengths because they answer different obligations.

The order record - dates, amounts, line items - is kept for ten years. That is a commercial-record obligation and it is about the transaction, not about the person.

The buyer inside that order - the encrypted e-mail, phone and address columns, the Shopify customer reference and the shortened name - is erased after one year. The record survives the person, which is the point: an obligation to keep a receipt is not an obligation to keep a customer.

Personalisation content a buyer supplied with an order is kept for two years, because a merchant may need to reproduce or dispute what was ordered.

Who else sees it

No e-mail we send to a buyer passes through a mail provider of ours. Store e-mail is sent using the merchant's own mail account and credentials, so the message goes from them to their customer and no e-mail service of ours is in the path.

Our infrastructure providers - hosting, database, object storage and backups - process data on our instructions and nothing else. We do not sell data, and we do not use one merchant's data to build anything for another.

How it is protected

Every third-party credential we hold is encrypted before it is stored, and buyer contact details in an order are stored encrypted rather than in the clear.

Every business record carries the identity of the merchant it belongs to, and every read passes through a layer that will not return a row belonging to somebody else. This is enforced in the data layer rather than remembered by each screen.

When a person in the merchant's own team opens an order and reveals the buyer's contact details, that is recorded - who, which order, and when. Access to personal data leaves a trail even when the person is authorised.

Requests from buyers, and stores that leave

Shopify sends us three requests on a buyer's or a merchant's behalf: a request for a buyer's data, a request to erase a buyer, and a request to erase an entire store. We act on all three rather than merely acknowledging them.

When a store is erased, its data is destroyed here too - including copies held in exports and archives, which are the places this kind of erasure is usually incomplete.

Your rights

If you are a buyer of a store that uses APPNOLIO, the merchant is who decides about your data, and your request is best made to them - they can act on it immediately through the software. If you contact us directly we will pass it to them and help them carry it out.

If you are a merchant, you can ask us for access to, correction of, or erasure of your own account data, and you can ask us to hand back or delete everything we hold for your store.

Contact

Write to us and say which store you are asking about. A request about a buyer should name the merchant, because we cannot act on their data without their instruction.