orosy Wholesale app privacy policy

Last updated: 8 September 2026

orosy株式会社 (orosy Inc., "we") sets out below what data the Shopify app "orosy Wholesale" ("the app") collects, why it collects it, where it is stored, and how it is deleted. This policy covers the app. Data handling across the wider orosy service is governed by the orosy buyer terms of service and the orosy privacy policy.

1. What the app collects

Once the app is installed and connected to an orosy account, we collect and store the following.

The app does not collect the name, address, e-mail address, or order contents of your store's customers. It does not collect card numbers either: card registration and payment are handled by orosy's payment provider.

2. Why we use it

We do not use this data for advertising or marketing.

3. Where it is stored and for how long

Data is stored in Supabase (PostgreSQL, AWS Tokyo region ap-northeast-1) and the app runs in Vercel's Tokyo region. The database uses a schema dedicated to this app, with row level security enabled.

Data is retained while the app is installed on the store. What happens after uninstall is set out in the next section.

4. Deleting your data

5. Your store's customers

The app neither collects nor stores personal data about your store's customers. When Shopify sends the customer data request (customers/data_request) or customer erasure (customers/redact) notification, we respond that we hold no customer personal data.

6. Sharing with third parties

We do not sell the data we collect, and we do not pass it to third parties.

To make the app work, data is sent to the following services: the orosy wholesale API (sign-in, product search, cart, ordering, orders and invoices), the Shopify Admin API (creating and publishing products, updating inventory), and Amazon Cognito (signing in to the orosy account). Each transfer exists to deliver a feature of the app; none of it is for advertising.

7. Security

The orosy API key and the sign-in refresh token are stored encrypted with AES-256-GCM. The encryption key is held in an environment variable, separately from the database. The orosy API is called only from the server; keys are never handed to the browser.

8. Contact

For questions about this policy or the data we hold, and for deletion requests, contact us here.

orosy株式会社 (orosy Inc.)
E-mail: wholesale_shop_api@orosy.com