1. Who we are
OrderQuorum is operated by Guangzhou Zhengjian Information Technology Co., Ltd. (“we”, “us”, or “our”), Room 2001, Panlong Xinjie, Haizhu District, Guangzhou, Guangdong 51000, China. Privacy requests can be sent to cartquilt@gmail.com.
2. Our role
When a Shopify merchant installs OrderQuorum, we generally process buyer, approver, company, cart, and order information as the merchant’s service provider or processor. The merchant determines why that information is used. We act as an independent controller for our own account administration, billing, support, fraud prevention, and legal compliance records.
3. Information we process
- Shop identity, shop domain, installation scopes, locale, timezone, and subscription status.
- Shopify company, company-location, company-contact, and customer identifiers.
- Contact names and email addresses only when needed to identify buyers and approvers.
- Cart line items, variant and product identifiers, product and variant titles, SKU, submitted quantities and prices, currencies, totals, and a cart fingerprint.
- Purchase order references, approval rules, buyer notes, approver comments, decisions, and timestamps.
- Order identifiers used to mark an approved request as checked out.
- Support messages, limited diagnostic logs, and security events.
We do not sell personal information, use it for behavioral advertising, or use purchase data to build unrelated profiles.
4. How we use information
We use information to authenticate users; run purchase approval workflows; confirm that submitted variant identifiers exist and read product and variant titles, SKU, and product ID; validate PO numbers; check approval expiry, company location, variant identifiers and quantities, subtotal and currency, and the approved PO number at checkout; restore approved variant IDs and quantities; provide audit exports; prevent abuse; troubleshoot incidents; answer support requests; administer Shopify billing; and comply with law. Product access is not used to modify products or retrieve or recalculate Shopify prices.
5. Shopify and lawful instructions
We receive information through Shopify APIs, webhooks, app proxies, customer account session tokens, and data entered directly by merchants and their company users. Merchants are responsible for giving their users appropriate notices and selecting lawful approval policies. We process merchant-controlled data according to the merchant’s instructions, our agreement, and Shopify’s requirements.
6. Service providers and international processing
Shopify provides platform authentication, APIs, extensions, and app billing. Our intended production deployment uses Amazon Web Services for application hosting and MySQL infrastructure. Before live customer data is processed, the actual host, storage, backup destinations, and transfer safeguards must be verified and recorded. Optional backup services are not treated as active until they are enabled and verified. Providers used in the verified deployment may process information outside the user’s country, subject to safeguards appropriate to the transfer and data.
7. Retention
- Open approval requests are kept while needed to provide the service. Rejected, expired, withdrawn, and checked-out requests and their full audit chains are normally deleted 180 days after their last update, or after the merchant’s configured retention window. A valid legal hold or pending customer access request can pause scheduled deletion.
- App session and configuration records remain while the app is installed.
- If production backups are enabled, their retention follows the verified deployment configuration. The local encrypted-backup design targets a rolling 14-day window; replicated copies, if used, follow their separately configured and verified lifecycle.
- Fulfilled Shopify customer-data request receipts are deleted 30 days after fulfillment. The generated report is delivered as a download and is not stored by OrderQuorum.
- Support and security records may be kept for up to 24 months when needed to resolve disputes or protect the service.
- We may keep a minimal record longer when law requires it, without retaining unnecessary customer content.
8. Deletion and Shopify privacy requests
We process Shopify’s mandatory customer data request, customer redaction, and shop redaction webhooks. Customer redaction clears the mapped Shopify customer ID, display name, email, and buyer note; replaces the Shopify company-contact ID with a salted pseudonymous value; and disables the local member. It clears all event comments on that customer’s submitted requests and comments or labels on events attributed to that member, then rebuilds the affected event hash chains. The pseudonymous member record and its role and location relationships remain until shop deletion; retained request relationships follow request retention. Free text on unrelated requests is not semantically searched for indirect mentions and may remain until the request aggregate is deleted under the applicable retention rule, or longer when retention is legally required; retained free text is not presumed anonymous. Uninstalling stops new collection, and Shopify’s shop redaction request triggers deletion of remaining merchant-controlled tenant data according to Shopify’s required timeline.
9. Security
Our production design requires HTTPS in transit, private network access for MySQL, least-privilege credentials, protected secret files, encryption at rest for production volumes and backups when enabled, access controls, timestamped approval events with no merchant-facing edit action, dependency monitoring, and limited logs designed to exclude signed query strings and authorization headers. These controls are release gates and must be verified in the actual deployment before live protected customer data is processed; repository configuration alone is not proof that a runtime control is active. No security measure is perfect; we investigate suspected incidents and notify affected parties when required.
10. Cookies and tokens
OrderQuorum uses essential Shopify authentication and session mechanisms. Customer account extensions use short-lived Shopify session tokens. We do not place advertising cookies. Server logs record limited operational metadata and are designed not to store access tokens, PO numbers, email addresses, or signed URL parameters.
11. Your choices and rights
Depending on local law, individuals may request access, correction, deletion, restriction, objection, or a portable copy of personal information. Company users should normally contact the Shopify merchant that controls their account. Requests may also be sent to cartquilt@gmail.com; we may refer the request to the relevant merchant and verify identity before acting.
12. Children
OrderQuorum is a business purchasing service and is not directed to children. We do not knowingly collect children’s personal information for this service.
13. Legal disclosure
We may disclose information when required by valid legal process, to protect users or the service, in connection with a corporate transaction subject to appropriate safeguards, or to service providers bound to use it only for authorized purposes.
14. Changes and contact
We may update this policy as the service or law changes. We will publish the new effective date and provide additional notice when a material change requires it. Questions can be sent to cartquilt@gmail.com.