Privacy policy — Assisty Dropship POs
Last updated 17 September 2026.
Who we are
Assisty Dropship POs is made by Assisty Technology Company Limited, Hanoi, Vietnam ("we"). Write to customer.services@assisty.ai about anything on this page. The merchant who installs the app is the controller of their customers' data; we process it on their behalf, for the one purpose below.
What the app does
When a customer pays for an order in your Shopify store, the app creates one purchase order per supplier for the items on that order, carrying the customer's ship-to, so the supplier can ship straight to the customer. You send that purchase order as a PDF, or the app emails it for you; when the supplier ships, the tracking number goes back into Shopify, which fulfills the order and notifies the customer.
What we hold, and why
| Data | Where it comes from | Why we hold it | Who sees it |
|---|---|---|---|
| The customer's name, address and phone number (the ship-to on the order) | The Shopify order | So the supplier knows where to ship | You, and the supplier on the purchase order and its tracking page |
| The customer's note on the order | The Shopify order | Printed on the purchase order when it concerns delivery | You and the supplier |
| The order's line items: product title, SKU, quantity, unit price | The Shopify order | So the purchase order lists what to ship | You and the supplier |
| Product images, cached from your catalog | Shopify | Shown beside each line in the app and on the PDF | You and the supplier |
| Product costs, in the supplier's currency | Shopify inventory items, or what you type | Printed on the purchase order as the supplier's price | You and the supplier |
| Supplier name, email address, currency, blind-ship setting, promised ship days | The vendor field on your products, and what you type | To address and send each purchase order | You; the email address is printed on the purchase order |
| The email address a purchase order was sent to, and its delivery events (delivered, bounced, complained) | Amazon Web Services, when the app emails for you | So the timeline shows what happened to each send | You |
| The carrier, tracking number and tracking URL the supplier or you enter | The supplier's tracking page, or you | To fulfill the order in Shopify with tracking | You, and the customer through Shopify's shipping notification |
| Your store's domain, name, currency, time zone and your email | Shopify, at install | To run the app for your store and to reach you about it | Us |
| An access token for your store | Shopify, at install | So the app can read orders and write fulfillments for your store | Nobody; it is stored encrypted and never shown |
We hold nothing about your customers beyond the order and its ship-to. We do not read customer accounts, browsing, marketing preferences or payment details.
Protected customer data
The app asks Shopify for the customer's name, address and phone number. It holds them only to print them on the purchase order and its tracking page, so the supplier can ship to your customer. They are shown to the supplier you chose for that order and to nobody else. They are erased when Shopify asks for that customer's data to be redacted, and with everything else when the store is redacted after an uninstall, as described under "How long".
Where it is held
The app runs on Amazon Web Services in the United States. Data is encrypted in transit and at rest. Every store's rows are separated from every other store's at the database level, so a request from one store can never read another's. Shopify remains the source of the order; the app keeps a copy for the life of the purchase order.
How long
- For the life of the install. When you uninstall (Shopify's
app/uninstalledwebhook) the app destroys its access token and stops processing your store at once; your purchase orders and suppliers are kept for a short while so a reinstall restores them. - About 48 hours after an uninstall Shopify sends
shop/redact, and every row of your store is deleted: orders, purchase orders, suppliers, cached images, events, everything. - When Shopify sends
customers/redactfor a customer, the ship-to and the note on that customer's orders are erased, and so is the copy of the ship-to on every purchase order made from them. - When Shopify sends
customers/data_request, the app records which of that customer's orders it holds a ship-to for; you answer the customer from Shopify's own request, and no data leaves the app. - Emails sent for you are kept by Amazon Web Services only as long as delivery takes; we keep the delivery events, not the message.
Sub-processors
- Amazon Web Services — hosting, the database, the PDFs and cached images (S3), the email sending (SES) and the queues that carry your store's events.
- Shopify — the source of every order, product and fulfillment, and the channel through which the customer is notified.
Nobody else receives your customers' or your suppliers' data.
What we do not do
We do not sell, rent or share data with anyone for their own purposes. We run no advertising and no analytics on customer data. We do not use your data to find suppliers for other merchants, or other merchants' data to find suppliers for you. We do not contact your customers.
Your rights
You can see, edit and delete everything the app holds for your store from inside the app and by uninstalling it. Your customers exercise their rights through you and through Shopify's redaction webhooks, which the app honours. If you are a customer of a store that uses the app, contact that store.
Changes
We will post changes to this page and update the date at the top.
Contact
customer.services@assisty.ai — Assisty Technology Company Limited, Hanoi, Vietnam.
This policy covers the Assisty Dropship POs app only. The Assisty inventory app has its own privacy policy. Install Assisty Dropship POs on the Shopify App Store, or the Assisty inventory app.