Privacy Policy
Resale Certificate Manager ("the app", "we") is a Shopify app that helps US merchants collect, review, and keep records of resale and tax-exemption certificates. This policy describes what data the app handles, why, and for how long. We collect the minimum needed to run the service, we do not sell or rent any data, and we never use it for advertising.
Data we process for merchants
- Store information received from Shopify when you install the app: your store domain, store contact email, and an API access token that lets the app act on your store (for example, marking a customer tax-exempt).
- Settings you enter in the app: notification email, review interval, customer tag, and upload-page text.
- Subscription status from Shopify's Billing API, to know which plan your store is on. We never see payment card details — billing is handled entirely by Shopify.
Data we process about your buyers
When a buyer submits a certificate on your storefront (or you file one in the admin), the app stores what was submitted: business name, business email, issuing US state, certificate or tax-registration number, optional issue and expiry dates, and the uploaded certificate document (PDF or image). On approval, the app writes to the matching customer record in your Shopify store: the tax-exempt flag, a tag, and two metafields (certificate reference and review-due date). Certificate documents are stored privately and are only accessible to the store's staff through the app's authenticated admin — they are never publicly addressable.
Emails
The app sends transactional emails only: certificate renewal and review reminders to the merchant's notification address and to the buyer email on file. Emails are delivered through our email provider acting as a data processor. We send no marketing email.
What we do not collect
- No payment or card data (Shopify handles all billing).
- No analytics, tracking pixels, or advertising identifiers — on the storefront upload page or anywhere else.
- No sale or sharing of data with third parties, other than the service providers needed to run the app (Shopify, our hosting provider, and our email delivery provider), each bound to process data only on our instructions.
Storage and security
Data is stored on our production infrastructure in the United States. Access tokens are stored server-side and are never exposed to browsers. Certificate documents are served only through authenticated, store-scoped requests. All traffic uses HTTPS.
Retention and deletion
- While the app is installed, certificate records are retained so the merchant can meet their record-keeping obligations.
- If you uninstall the app, your data is retained briefly so nothing is lost if you reinstall, and is then permanently deleted — including all certificate documents — when Shopify issues its shop data-erasure request (approximately 48 hours after uninstall).
- Buyer-level erasure requests received from Shopify (customers/redact) permanently delete that buyer's certificates and documents.
- Data-access requests (customers/data_request) are surfaced to the merchant, who responds to their customer as the data controller.
Roles
For buyer data, the merchant is the data controller and the app is a data processor acting on the merchant's instructions. Buyers should direct privacy requests to the store they submitted their certificate to; we support the merchant in fulfilling them.
Your rights
Depending on where you live (including under GDPR and US state privacy laws such as the CCPA), you may have rights to access, correct, or delete personal data. Merchants can exercise these directly in the app or by contacting us; buyers should contact the merchant they submitted to.
Changes
If this policy changes materially, we will update this page and the effective date above.
Contact
Questions or requests: devhubr@gmail.com