Privacy Policy

Last updated: August 22, 2026

What POGrid processes

POGrid processes Shopify merchant catalog, inventory, location, supplier, purchasing, automation, purchase-order, and receiving information only to provide purchasing workflows requested by the merchant. POGrid does not request customer names, email addresses, phone numbers, postal addresses, payment data, or other customer profile fields.

Optional automatic sales velocity

If a merchant enables Smart Reorder sales velocity, POGrid reads up to the most recent 30 days of Shopify order line items to calculate a store-wide net units-sold rate for mapped product variants. The request uses order status/test flags, line-item variant IDs, and net current quantities only. Cancelled and Shopify test orders are excluded, and refunded or removed units do not increase the rate. POGrid does not request customer identity fields for this feature. Recent order details and calculated velocity snapshots are used transiently and are not persisted in POGrid’s merchant purchasing metaobjects or a separate POGrid database. Merchants can disable the feature and revoke the optional order-read permission from POGrid settings.

Where purchasing data is stored

Supplier settings, product-to-supplier mappings, purchasing rules, purchase orders, receipts, automation state, and operational settings are stored as app-owned Shopify metaobjects associated with the merchant’s Shopify store. POGrid does not maintain a separate database copy of those merchant purchasing records.

24/7 automation access

If a merchant enables/uses POGrid background automations, POGrid stores an expiring Shopify offline credential on its hosting infrastructure so the selected purchasing rules can run while the merchant is away from the app. The credential is encrypted at rest with AES-256-GCM, is used only for authenticated Shopify Admin API access needed by POGrid, and is removed when the app is uninstalled or the shop-redact privacy request is received.

Email delivery

When a merchant enables POGrid email alerts, the selected alert address is stored with the shop’s POGrid settings in Shopify and purchasing automation notifications are delivered through POGrid’s configured email provider. Separately, when a merchant explicitly chooses to send a purchase order to a supplier, POGrid sends the supplier order email address, message data, and purchase-order PDF through the email provider. Purchasing automations never email suppliers by themselves.

Billing and infrastructure

Subscription billing is handled by Shopify App Pricing. POGrid queries Shopify’s Partner API to verify the merchant’s active POGrid plan. The hosting and email providers process the minimum technical information required to run the service, deliver merchant-requested email, protect the service, and diagnose failures.

Data sharing

POGrid does not sell merchant or customer data. Data is shared only with Shopify and service providers needed to operate requested POGrid functionality, or when required by law.

Retention and deletion

POGrid purchasing records live in Shopify app-owned storage. Shopify controls the lifecycle of those records. POGrid deletes its encrypted background credential on app uninstall and shop-redact. Raw supplier and Stocky CSV files are processed locally in the browser and are not retained by POGrid infrastructure.

Security

POGrid uses Shopify-managed installation, signed Shopify ID tokens, verified webhook signatures, least-privilege access scopes, encrypted expiring background credentials, HTTPS production hosting, and explicit merchant confirmation for sensitive write/send actions.

Questions

For privacy or support questions, use the contact details on the POGrid Support page.

Terms of Service · Support