BuyerPrism Privacy Policy

Effective date: 28 September 2026.

Operator: Mykhailo Ihnatiev, Komuny Paryskiej 58, lok. 40, 30-389 Kraków, Poland. NIP 8971938345; REGON 528714015.

Privacy contact: privacy@buyerprism.com

What BuyerPrism does

BuyerPrism is a read-only Shopify application. It reads selected Shopify B2B configuration and contextual buyer outcomes to explain catalog visibility, prices, quantity rules, volume breaks, assignment paths, and changes over time. It does not change Shopify products, prices, catalogs, Markets, companies, carts, orders, or checkout configuration. A contextual catalog price is not a final checkout quote.

Data processed

The service processes the merchant shop domain, Shopify resource identifiers, minimized catalog/Market/company-location relationships, product and variant identifiers, product titles and SKUs used for navigation, verified prices and ordering rules, app-owned policies and tiers, findings, audit metadata, schedule settings, and encrypted Shopify access/refresh tokens.

BuyerPrism is designed not to request or retain customer or order data, company contacts, email addresses, phone numbers, street addresses, customer notes, arbitrary metafields, or complete Shopify API responses. Operational logs contain bounded identifiers, operation names, status codes, counts, durations, and safe error codes. They do not contain tokens, full request headers, complete API responses, or personal contact fields.

When someone contacts us, we process their email address, message, and related support history to answer and secure the service. Avoid sending customer records, credentials, or other unnecessary personal data in support messages.

Purposes and roles

We process app data to authenticate the Shopify installation, answer merchant-requested simulator queries, run read-only audits, show and compare findings, operate merchant-enabled monitoring, provide CSV downloads, secure the service, diagnose failures, and comply with deletion or privacy requests. The merchant controls its Shopify business data and instructions for the app; BuyerPrism handles support correspondence and its own operational records.

For our own support correspondence and operational records, the legal bases are performance of the service requested by the merchant (GDPR Article 6(1)(b)), compliance with applicable legal duties (Article 6(1)(c)), and our legitimate interests in answering requests, preventing abuse, and securing the service (Article 6(1)(f)), as applicable. The merchant determines the legal basis for personal data in its Shopify store. Where we process that data on the merchant's behalf, we act on the merchant's documented instructions and assist with applicable data-subject requests.

Retention and deletion

Audit observations, findings, notifications, and outcome history are retained for up to 90 days while installed. App-owned policies and tier mappings remain until the merchant deletes them, uses the in-app Delete all BuyerPrism data control, or uninstalls the app. Webhook idempotency receipts are retained for up to 30 days.

On uninstall, Shopify-derived data, policies, notifications, schedules, and encrypted tokens are deleted immediately. A minimal inactive installation tombstone containing the shop domain, installation state, timestamps, generation counter, and webhook receipt can remain for up to 30 days to reject duplicate or stale work. It is deleted earlier when Shopify sends shop/redact. CSV exports are streamed to the merchant and are not stored by BuyerPrism.

Backups and point-in-time recovery history follow the configured Neon retention window, which is at most six hours on the initial production plan. A deletion can remain in provider recovery history until that window expires; restored data must be subjected to the same deletion record and retention controls before service is resumed. Support correspondence is normally deleted within 12 months after a request closes. We may retain specific messages longer where reasonably needed for an unresolved dispute, security investigation, or legal duty, then delete them when that reason ends.

Service providers and transfers

Our providers and their roles are listed in Subprocessors. Application compute, queue, and PostgreSQL are located in Frankfurt, Germany. Providers may access or process information outside the European Economic Area for support or platform operations. Where a restricted transfer occurs, it is governed by the provider's applicable data-processing terms and transfer safeguards, such as Standard Contractual Clauses or an adequacy decision. Contact privacy@buyerprism.com for information about the safeguards relevant to a request.

Security

BuyerPrism uses least-privilege read scopes, server-side encrypted token storage, TLS, private application/cache networking, authenticated webhooks, shop-scoped database access, generation-fenced background jobs, dependency scanning, security headers, and monitored release infrastructure. No system can guarantee absolute security.

Rights and requests

Merchants can erase application data from the Privacy page while installed and can uninstall through Shopify. Privacy, access, correction, objection, restriction, portability, or deletion requests can be sent to privacy@buyerprism.com. We may need to verify identity and authority before fulfilling a request. Applicable rights and response rules depend on the relevant law and our role in the processing. Individuals may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent supervisory authority.

Changes and contact

Material changes will be reflected by a new effective date and communicated where required. Questions or security reports can be sent to privacy@buyerprism.com or security@buyerprism.com. Postal contact: Mykhailo Ihnatiev, Komuny Paryskiej 58, lok. 40, 30-389 Kraków, Poland.