Privacy policy — Assisty Dropship POs

Last updated 17 September 2026.

Who we are

Assisty Dropship POs is made by Assisty Technology Company Limited, Hanoi, Vietnam ("we"). Write to customer.services@assisty.ai about anything on this page. The merchant who installs the app is the controller of their customers' data; we process it on their behalf, for the one purpose below.

What the app does

When a customer pays for an order in your Shopify store, the app creates one purchase order per supplier for the items on that order, carrying the customer's ship-to, so the supplier can ship straight to the customer. You send that purchase order as a PDF, or the app emails it for you; when the supplier ships, the tracking number goes back into Shopify, which fulfills the order and notifies the customer.

What we hold, and why

DataWhere it comes fromWhy we hold itWho sees it
The customer's name, address and phone number (the ship-to on the order)The Shopify orderSo the supplier knows where to shipYou, and the supplier on the purchase order and its tracking page
The customer's note on the orderThe Shopify orderPrinted on the purchase order when it concerns deliveryYou and the supplier
The order's line items: product title, SKU, quantity, unit priceThe Shopify orderSo the purchase order lists what to shipYou and the supplier
Product images, cached from your catalogShopifyShown beside each line in the app and on the PDFYou and the supplier
Product costs, in the supplier's currencyShopify inventory items, or what you typePrinted on the purchase order as the supplier's priceYou and the supplier
Supplier name, email address, currency, blind-ship setting, promised ship daysThe vendor field on your products, and what you typeTo address and send each purchase orderYou; the email address is printed on the purchase order
The email address a purchase order was sent to, and its delivery events (delivered, bounced, complained)Amazon Web Services, when the app emails for youSo the timeline shows what happened to each sendYou
The carrier, tracking number and tracking URL the supplier or you enterThe supplier's tracking page, or youTo fulfill the order in Shopify with trackingYou, and the customer through Shopify's shipping notification
Your store's domain, name, currency, time zone and your emailShopify, at installTo run the app for your store and to reach you about itUs
An access token for your storeShopify, at installSo the app can read orders and write fulfillments for your storeNobody; it is stored encrypted and never shown

We hold nothing about your customers beyond the order and its ship-to. We do not read customer accounts, browsing, marketing preferences or payment details.

Protected customer data

The app asks Shopify for the customer's name, address and phone number. It holds them only to print them on the purchase order and its tracking page, so the supplier can ship to your customer. They are shown to the supplier you chose for that order and to nobody else. They are erased when Shopify asks for that customer's data to be redacted, and with everything else when the store is redacted after an uninstall, as described under "How long".

Where it is held

The app runs on Amazon Web Services in the United States. Data is encrypted in transit and at rest. Every store's rows are separated from every other store's at the database level, so a request from one store can never read another's. Shopify remains the source of the order; the app keeps a copy for the life of the purchase order.

How long

  • For the life of the install. When you uninstall (Shopify's app/uninstalled webhook) the app destroys its access token and stops processing your store at once; your purchase orders and suppliers are kept for a short while so a reinstall restores them.
  • About 48 hours after an uninstall Shopify sends shop/redact, and every row of your store is deleted: orders, purchase orders, suppliers, cached images, events, everything.
  • When Shopify sends customers/redact for a customer, the ship-to and the note on that customer's orders are erased, and so is the copy of the ship-to on every purchase order made from them.
  • When Shopify sends customers/data_request, the app records which of that customer's orders it holds a ship-to for; you answer the customer from Shopify's own request, and no data leaves the app.
  • Emails sent for you are kept by Amazon Web Services only as long as delivery takes; we keep the delivery events, not the message.

Sub-processors

  • Amazon Web Services — hosting, the database, the PDFs and cached images (S3), the email sending (SES) and the queues that carry your store's events.
  • Shopify — the source of every order, product and fulfillment, and the channel through which the customer is notified.

Nobody else receives your customers' or your suppliers' data.

What we do not do

We do not sell, rent or share data with anyone for their own purposes. We run no advertising and no analytics on customer data. We do not use your data to find suppliers for other merchants, or other merchants' data to find suppliers for you. We do not contact your customers.

Your rights

You can see, edit and delete everything the app holds for your store from inside the app and by uninstalling it. Your customers exercise their rights through you and through Shopify's redaction webhooks, which the app honours. If you are a customer of a store that uses the app, contact that store.

Changes

We will post changes to this page and update the date at the top.

Contact

customer.services@assisty.ai — Assisty Technology Company Limited, Hanoi, Vietnam.

This policy covers the Assisty Dropship POs app only. The Assisty inventory app has its own privacy policy. Install Assisty Dropship POs on the Shopify App Store, or the Assisty inventory app.