Orstrax Orderflow
Privacy Policy
Last updated September 7, 2026
This notice is for Orstrax Orderflow at orderflow.orstrax.io (orders.orstrax.io redirects here). It is the product privacy policy Shopify merchants should use for this app. The company website notice is at orstrax.com/privacy. Product terms are at /terms.
Who we are
Orstrax LLC operates Orderflow. For privacy questions, deletion requests, or security incidents, email hello@orstrax.io.
For Shopify orders, Orstrax acts as a processor on behalf of the merchant (the Shopify store that installed the app). The merchant is responsible for their own customer-facing privacy notices and for the messages they send through Orderflow.
What we process and why
Orstrax Orderflow is an after-checkout order workspace. We read Shopify orders so merchants can assign statuses, send proof and information-request emails, and let customers look up their own order on the storefront. We only import Shopify orders created in the last 60 days, then keep those records updated. We do not request read_all_orders or import older history.
For an authenticated shop we also store shop identity, team account emails you invite, status and proof workflow data, and files you or your customers upload (proofs, information-request photos, logos).
- Name. Customer first and last name appear on the merchant order list, proof and information-request emails the merchant sends, and the customer lookup page so staff and the customer can identify the order. Names are not used for advertising or sold.
- Address. Shipping address from the Shopify order is shown to authenticated merchant staff so they can complete fulfillment workflow (for example handmade or made-to-order shops). Address is not shown on the public lookup page and is not used for marketing.
- Email. Customer email is required to send merchant-configured status, proof, and information-request messages, and so the customer can look up their order. We do not send marketing campaigns. Email is not sold or used to contact customers except as the merchant configures for that store.
- Phone. Phone is shown to authenticated merchant staff when Shopify includes it on the order, so the merchant can reach the customer about that order. It is omitted from public lookup and is not used for SMS marketing.
We do not sell merchant or customer data. We do not use customer data for advertising, profiling with legal or similarly significant effects, or automated decisions that replace merchant judgment. Customer emails go out only when the merchant configures a status, proof, or information-request message. Storefront lookup only shows a customer their own order after they identify it.
Sharing
Access is limited to the authenticated shop’s staff and to service providers that host the app: Google Firebase (Auth, Firestore, Storage), Vercel (hosting), and Resend or the merchant’s own SMTP for mail the merchant sends. Shopify already holds the underlying order. We do not sell personal data or share it for a “data sale” or similar concept. If a customer opts out of sale or sharing under applicable law, we do not sell or share that data in the first place.
Retention
We keep order workflow data while the merchant uses Orderflow. Uninstalling the app from Shopify revokes our API access; stored history is not deleted automatically, so a merchant can reinstall without losing workflow. We remove or redact customer fields when Shopify sends customers/redact or shop/redact. We fulfill customers/data_request by providing stored customer data to the store owner. A merchant can also email hello@orstrax.io to request deletion of their Orderflow workspace. We do not keep personal data longer than needed for those purposes.
Security
The app is served over HTTPS. Data at rest is stored in Google Cloud / Firebase with provider encryption; backups follow the same provider controls. Production merchant data is not copied into local development. Staff passwords for invited teammates must be at least 12 characters and include a letter and a number. Orstrax operator access to production is limited to people who operate the product. We keep application audit logs of merchant-visible and operator actions. Security incidents can be reported to hello@orstrax.io; we investigate, contain, and notify affected merchants when required.
Your choices
Merchants can uninstall the app, disconnect Shopify, and manage team seats. Customers should contact the merchant for order questions; we process customer data for that merchant’s workflow, not as a consumer-facing account. Where a customer asks the merchant to stop emails, the merchant can turn off those templates. We honor Shopify-mandated redaction and data-request webhooks.