Privacy Policy for BOLShip

Last updated: July 21, 2026

1. Information We Store

BOLShip is designed with data minimization in mind. To provide our core functionality of generating Bills of Lading (BOLs), we permanently store only the following metadata related to your Shopify store:

2. Information We DO NOT Store (Customer Data)

BOLShip explicitly does not permanently store sensitive customer information. When a merchant generates or reprints a Bill of Lading, the app fetches the unfulfilled order data directly from the Shopify API in real-time. This includes the customer's name, shipping address, and phone number (Consignee information).

This data is securely injected into the generated PDF and streamed directly to the merchant's browser. The generated PDF file is never saved to our servers, and the customer's PII is never recorded in our database.

3. Data Retention and Purging

In accordance with data minimization and storage limitation principles, we enforce the following retention schedule:

Because we do not store customer PII, standard customer data redaction requests do not require customer address deletion. When Shopify supplies related order IDs, we scrub generated-BOL order identifiers from the audit log.

4. Service Providers

We use third-party infrastructure providers to host and operate BOLShip, including cloud hosting, managed database services (PostgreSQL, Redis), object storage for your uploaded BOL templates, and error monitoring.

A formal Data Processing Addendum and a named list of our subprocessors are in preparation. To request either, contact us using the details in Section 5.

5. Contact Us & Policy Updates

We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above, and we will notify merchants through the app where the change affects how we handle your data.

If you have any questions about this Privacy Policy or our data practices, please contact our support team through the Shopify App Store.