Privacy Policy for BOLShip
Last updated: July 21, 2026
1. Information We Store
BOLShip is designed with data minimization in mind. To provide our core functionality of generating Bills of Lading (BOLs), we permanently store only the following metadata related to your Shopify store:
- Product and variant freight metadata (e.g., freight classes, weights, pallet counts).
- Your custom LTL Carrier Address Book (carrier names, SCAC codes, contact info).
- Your custom BOL PDF templates and their form field mappings.
- Your store's default shipper settings (e.g., your warehouse address).
- Billing and subscription status.
- Staff session data required to keep you signed in securely to the app within Shopify Admin.
- A historical audit log of generated BOLs, which includes the carrier, order number, and timestamp, but excludes direct customer identifiers such as name, shipping address, and phone number.
2. Information We DO NOT Store (Customer Data)
BOLShip explicitly does not permanently store sensitive customer information. When a merchant generates or reprints a Bill of Lading, the app fetches the unfulfilled order data directly from the Shopify API in real-time. This includes the customer's name, shipping address, and phone number (Consignee information).
This data is securely injected into the generated PDF and streamed directly to the merchant's browser. The generated PDF file is never saved to our servers, and the customer's PII is never recorded in our database.
3. Data Retention and Purging
In accordance with data minimization and storage limitation principles, we enforce the following retention schedule:
- Order/Consignee Data: Never stored. Fetched live from Shopify during BOL generation/reprint.
- Generated BOLs Audit Log: Retained while the shop is installed; order identifiers are scrubbed upon receiving a
customers/redactrequest. Purged entirely onshop/redact. - Staff Sessions: Retained while active; deleted on app uninstall and on
shop/redact. Expired sessions are cleaned up periodically. - Tenant Settings (Templates, Carriers, Products): Retained while the app is installed. Purged entirely on
shop/redact(which fires ~48 hours after uninstall).
Because we do not store customer PII, standard customer data redaction requests do not require customer address deletion. When Shopify supplies related order IDs, we scrub generated-BOL order identifiers from the audit log.
4. Service Providers
We use third-party infrastructure providers to host and operate BOLShip, including cloud hosting, managed database services (PostgreSQL, Redis), object storage for your uploaded BOL templates, and error monitoring.
A formal Data Processing Addendum and a named list of our subprocessors are in preparation. To request either, contact us using the details in Section 5.
5. Contact Us & Policy Updates
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above, and we will notify merchants through the app where the change affects how we handle your data.
If you have any questions about this Privacy Policy or our data practices, please contact our support team through the Shopify App Store.