orosy Wholesale app privacy policy
Last updated: 8 September 2026
orosy株式会社 (orosy Inc., "we") sets out below what data the Shopify app "orosy Wholesale" ("the app") collects, why it collects it, where it is stored, and how it is deleted. This policy covers the app. Data handling across the wider orosy service is governed by the orosy buyer terms of service and the orosy privacy policy.
1. What the app collects
Once the app is installed and connected to an orosy account, we collect and store the following.
- Store identifiers: the myshopify domain, display language, default destination country, import defaults, and the ID of the location whose inventory the app adjusts
- A Shopify access token: stored so that the app's server can call the Shopify Admin API
- The e-mail address of the orosy account: stored to identify the connected account and to check the account's review status
- The orosy API key and the sign-in refresh token: stored encrypted (AES-256-GCM). They are never stored in plain text and are never shown on screen
- The mapping of imported products: Shopify product and variant IDs against orosy product and variant IDs, barcode (JAN), order unit, delivery group, the wholesale price at import, and the import timestamp
- A record of received stock applied to inventory: the orosy order ID, line number, quantity applied, and timestamp (stored so that the same delivery is not applied twice)
The app does not collect the name, address, e-mail address, or order contents of your store's customers. It does not collect card numbers either: card registration and payment are handled by orosy's payment provider.
2. Why we use it
- To render the app's screens and to run product search, import, ordering, and order tracking
- To check the review status of the orosy account and to keep the screens locked until the account is approved
- To map imported products back to orosy products, add received quantities to inventory, and show changes in wholesale price and stock
- To investigate a support request or a defect when you contact us
We do not use this data for advertising or marketing.
3. Where it is stored and for how long
Data is stored in Supabase (PostgreSQL, AWS Tokyo region ap-northeast-1) and the app runs in Vercel's Tokyo region. The database uses a schema dedicated to this app, with row level security enabled.
Data is retained while the app is installed on the store. What happens after uninstall is set out in the next section.
4. Deleting your data
- Uninstall: when Shopify notifies us that the app was uninstalled, we delete everything we hold for that store (store identifiers, the access token, the orosy account e-mail address, the encrypted API key, the imported-product mapping, and the inventory records). We perform the same deletion when Shopify sends the shop erasure notification (shop/redact), which arrives 48 hours after uninstall.
- Disconnecting: pressing "Disconnect" on the settings page immediately deletes the orosy account e-mail address and the encrypted API key, and revokes the API key the app issued. The Shopify products you imported, and their mapping, stay on the store.
- Individual requests: to have data deleted in any other case, contact us at the address below.
5. Your store's customers
The app neither collects nor stores personal data about your store's customers. When Shopify sends the customer data request (customers/data_request) or customer erasure (customers/redact) notification, we respond that we hold no customer personal data.
6. Sharing with third parties
We do not sell the data we collect, and we do not pass it to third parties.
To make the app work, data is sent to the following services: the orosy wholesale API (sign-in, product search, cart, ordering, orders and invoices), the Shopify Admin API (creating and publishing products, updating inventory), and Amazon Cognito (signing in to the orosy account). Each transfer exists to deliver a feature of the app; none of it is for advertising.
7. Security
The orosy API key and the sign-in refresh token are stored encrypted with AES-256-GCM. The encryption key is held in an environment variable, separately from the database. The orosy API is called only from the server; keys are never handed to the browser.
8. Contact
For questions about this policy or the data we hold, and for deletion requests, contact us here.
orosy株式会社 (orosy Inc.)
E-mail: wholesale_shop_api@orosy.com