Lisa Abercrombie, Inc.
Draft Deputy Privacy Policy
Plain-language summary. Draft Deputy accesses Shopify merchant, customer, product, inventory, and draft-order data only to provide and secure the app. We do not keep a separate customer, order, or payment database, and we do not sell data, use it for advertising, or send it to an artificial-intelligence provider.
This Privacy Policy explains how Lisa Abercrombie, Inc. (“we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when a Shopify merchant installs or uses Draft Deputy (the “App”). It also explains the privacy choices available to merchants and their customers.
By installing or using the App, the merchant acknowledges the practices described in this Privacy Policy. This policy applies only to Draft Deputy. Shopify and each merchant operate under their own privacy notices and practices.
1. Our role and scope
For merchant account and App-usage information, Lisa Abercrombie, Inc. generally determines why and how that information is processed. When Draft Deputy processes a merchant’s customer information to create or manage draft orders, the merchant generally determines the purposes of that processing and we act as the merchant’s service provider or processor, as applicable.
Merchants are responsible for providing their own customers with appropriate privacy notices and for ensuring they have a lawful basis to direct the App to process customer information.
2. Information we collect
Information received from Shopify
Depending on the features used and permissions granted, Draft Deputy may receive or access:
- Merchant and store information, such as shop name, shop domain, Shopify store identifier, installation status, and App authorization information.
- Customer information, such as customer identifiers, names, email addresses, phone numbers, billing or shipping addresses, notes, tags, and other customer fields available through the permissions granted by the merchant.
- Draft-order information, such as draft-order identifiers and status, line items, quantities, prices, discounts, taxes, notes, customer associations, and billing or shipping details.
- Product and variant information, such as product titles, images, variants, SKUs, barcodes, prices, status, and Shopify identifiers.
- Inventory information, such as inventory-item identifiers, inventory levels, availability, and location-related inventory information.
- Webhook and compliance-request information sent by Shopify, including requests to access or delete customer or shop data.
Draft Deputy uses customer, product, inventory, and draft-order information through Shopify as needed to perform requested actions. We do not store a separate copy of complete Shopify customer records, complete draft orders, Shopify orders, or payment details. Customer and draft-order records remain in the merchant’s Shopify store, except for the limited scan-history references described below.
Information provided directly through the App
Merchants and their authorized staff may enter, scan, select, or submit information through Draft Deputy. We store the following limited information:
- Merchant account credentials: username and a hashed password.
- Shop connection information: store URL and encrypted Shopify access tokens.
- Billing and usage information: subscription plan and counts of “Add to Order” actions.
- Scan history: SKU, quantity, timestamp, and the related Shopify draft-order identifier or name (for example, #D100).
We do not store phone numbers, street addresses, payment-card or other payment details, complete Shopify orders, complete customer profiles, chat content, or AI data in the Draft Deputy database.
Technical and usage information
We may collect technical information needed to operate, secure, and troubleshoot the App, including timestamps, shop domain, request and response status, feature activity, device or browser information, IP address, and diagnostic or error-log information. Error logs may contain identifiers or limited transaction context associated with the action that produced the error. We seek to avoid placing unnecessary personal information in logs and do not use logs to create a customer database.
3. Shopify permissions
Draft Deputy currently requests the following Shopify API scopes. A scope permits access; the App should use only the information necessary for its features and operations.
| Scope | Purpose |
|---|---|
read_customers |
Find and display customers so authorized staff can select the correct customer for a draft order. |
write_customers |
Create or update customer information when an authorized merchant user directs the App to do so. |
read_draft_orders |
Find and display draft orders and their contents. |
write_draft_orders |
Create or update draft orders, including adding scanned or selected products. |
read_inventory |
Display inventory availability and levels for selected products or variants. |
read_products |
Find products and variants and display details such as title, image, SKU, barcode, and price. |
4. How we use information
We use information for the following business purposes:
- Provide the App’s product lookup, SKU or barcode scanning, inventory display, customer selection, and draft-order creation and editing features.
- Authenticate installations, maintain merchant sessions, and communicate with Shopify’s APIs.
- Store and synchronize information needed for App functionality and performance.
- Respond to support requests and communicate about the App.
- Monitor reliability, diagnose errors, prevent fraud or misuse, and protect the App, merchants, customers, and Shopify.
- Comply with applicable law, enforce our agreements, and respond to lawful requests.
- Process Shopify’s mandatory privacy and compliance requests.
We do not use merchant or customer information for targeted advertising. We do not sell merchant or customer personal information. Draft Deputy does not currently use artificial intelligence or send App data to an AI provider.
5. How we disclose information
We disclose information only as needed for the purposes described in this policy:
- Shopify. We exchange information with Shopify to authenticate the App, retrieve permitted store data, update customers and draft orders as directed, and process platform events and compliance requests.
- Hosting provider. Draft Deputy is hosted by DigitalOcean, which may process or store App databases, application files, server logs, network information, and backups on our behalf.
- Professional advisers and authorities. We may disclose information when reasonably necessary to comply with law, protect legal rights or safety, investigate misuse, or obtain legal, accounting, security, or insurance services.
- Business transaction. Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality and legal requirements.
We do not allow a service provider to use merchant or customer information for its own advertising purposes merely because it processes information for Draft Deputy.
6. Data storage, retention, and deletion
Draft Deputy stores the limited merchant-account, shop-connection, billing/usage, and scan-history information described above in an SQLite database hosted in the App’s DigitalOcean environment.
While the App is installed, Draft Deputy retains the current scan session and up to the 50 most recently saved scan sessions. Each session contains no more than 1,500 scan actions. Older saved sessions and scan actions beyond these limits are removed from active App storage.
When a merchant uninstalls Draft Deputy, the App deletes its scan history, revokes or invalidates the stored Shopify access tokens, and resets its billing and usage counters. Complete Shopify customer and draft-order records are not deleted because they remain in and belong to the merchant’s Shopify store.
After Shopify delivers a valid shop-redaction request, we delete the shop’s remaining Draft Deputy account and App-stored shop information within 30 days, unless a longer period is required by law. If the merchant later reinstalls Draft Deputy, the installation starts clean and old scan history is not restored. Residual copies may remain in restricted backups for up to 90 days and will not be restored except for disaster-recovery or security purposes.
Diagnostic and security logs are retained for up to 12 months unless they are needed longer to investigate a security incident, prevent abuse, establish or defend legal claims, or comply with law. A merchant may request deletion sooner by contacting us, subject to legal and operational exceptions.
7. Privacy requests
Merchant requests
A merchant may request access to, correction of, or deletion of personal information controlled by Lisa Abercrombie, Inc. by emailing lisa.abercrombie@gmail.com. We may need to verify the request and the requester’s authority over the relevant Shopify store.
Customer requests
A Shopify customer should normally submit a privacy request directly to the merchant from whom the customer purchased or interacted. The merchant can then submit the request through Shopify or contact us. We will assist the merchant and respond to valid Shopify compliance webhooks, including customer data-access and redaction requests, as required by Shopify and applicable law.
Depending on location and applicable law, individuals may have rights to know, access, correct, delete, restrict, or obtain a copy of their personal information, or to object to certain processing. We will not discriminate against a person for exercising an applicable privacy right.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, loss, misuse, or disclosure. These measures include hashing App passwords, encrypting stored Shopify access tokens, limiting access to people and systems that need it, using secure connections where appropriate, maintaining authentication controls, and monitoring and addressing application errors.
No internet transmission or storage system is completely secure. Merchants are responsible for protecting their Shopify credentials, controlling staff access, and promptly notifying us of suspected unauthorized App activity.
9. International processing
Draft Deputy and its service providers may process information in the United States or other countries where they operate. Those countries may have privacy laws that differ from the laws where a merchant or customer lives. Where required, we use appropriate safeguards for cross-border transfers.
10. Children’s privacy
Draft Deputy is a business application intended for Shopify merchants and their authorized staff. It is not directed to children, and we do not knowingly collect personal information directly from children through the App. Customer information received from a merchant is processed only to provide services to that merchant.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to Draft Deputy, our practices, or applicable requirements. We will post the revised policy and update the “Last updated” date. If required by law, we will provide additional notice of material changes.
12. Contact us
Questions or requests concerning this Privacy Policy or Draft Deputy’s privacy practices may be directed to:
Lisa Abercrombie, Inc.Attn: Privacy — Draft Deputy
1252 South 2430 West
Syracuse, Utah 84075
United States
Email:
lisa.abercrombie@gmail.com
Website:
https://mom-boutique-api.robustapps.net/