SAAS: Pickup + Store Finder Privacy Policy

SAAS: Pickup + Store Finder (“the App”), installed as “SAAS Integrator CNC” and developed and operated by SAAS Integrator (“we”, “us”, “our”), including its optional add-on SAAS Order Management. This Privacy Policy explains how we collect, use, store, and protect information when merchants install and use the App on Shopify.

For the base App (store pickup, store finder and store hours), SAAS Integrator acts as a data processor of merchant data accessed through Shopify. When a merchant enables SAAS Order Management, the App also stores a limited set of customer data to prepare, notify, hand over and dispatch orders, and creates accounts for the merchant’s store staff, as described below.

Effective date: 31 July 2026

 

1. Information We Access and Process

When you install and use the App, we access and process the minimum data required to provide its functionality.

a) Shopify Store Data

  • Store name and store URL
  • Shopify location data
  • Product and inventory information
  • Order information (including line items and fulfillment status)
  • Customer information associated with orders (name, phone number, and shipping address)
  • Order tags, notes, and attributes related to pickup and fulfillment

We access this data through Shopify’s secure APIs. The App does not use or store customer email addresses.

b) Inventory and Location Data

We access inventory levels and location data to:

  • Validate pickup availability by store location
  • Ensure accurate stock status prior to checkout
  • Support multi-location store selection

We do not access or process payment information.

c) SAAS Order Management (opt-in)

When a merchant enables SAAS Order Management, the App stores a limited set of customer data for the orders it is preparing, so that store staff can pick, pack, notify, hand over and dispatch them:

  • Customer name — shown on pick lists, picking slips and packing slips, and on the staff screens, so staff prepare and hand over the correct order to the correct person
  • Customer phone number — used to send order notifications by SMS through the merchant’s own SMS account
  • Customer shipping address — shown on the packing slip for delivery orders only. It is not stored for store pickup orders

SMS notifications are transactional messages about the customer’s own order. They are sent when an order is ready for collection, when an order is dispatched, when part of an order is ready or dispatched, and when a refund is processed. They are never used for marketing.

Where a merchant enables collection verification, the App generates a short collection code and sends it to the customer by SMS. Staff confirm that code at handover. The code is generated by the App and is not personal information.

A merchant may also require staff to sight photo identification before releasing certain orders. The App records only that a check was performed and by which staff member. It does not capture, photograph or store any identity document, document number, or any details from it.

This data is read from the Shopify Orders API and only the minimum necessary is stored. It is not used for marketing or profiling.

 

2. How We Use Information

We use accessed and stored data solely to:

  • Enable store pickup, store finder and store hours functionality
  • Validate inventory availability by location
  • Add pickup-related order tags, notes, or attributes
  • Facilitate store-level order fulfillment
  • With SAAS Order Management enabled: prepare, pick, pack, notify, hand over and dispatch pickup and delivery orders, verify collection where the merchant requires it, and allow head office to review and resolve orders a store cannot fulfil
  • Monitor plan usage (location count and order volume)
  • Provide merchant support

We do not sell, rent, trade, or use merchant or customer data for advertising or marketing purposes. We do not use personal data for automated decision-making or profiling.

 

3. Data Sharing

We do not share merchant or customer data with third-party marketing providers.

Data may be processed by:

  • Shopify (as the platform provider)
  • Infrastructure providers used to securely host the App

For merchants who enable SAAS Order Management, and using the merchant’s own third-party accounts:

  • The customer’s phone number, and the order reference contained in the message, are sent to the merchant’s SMS provider (for example Twilio) to deliver order notifications. The merchant supplies and controls that account

We only share data where required to provide core app functionality or to comply with legal obligations.

 

4. Data Retention

We retain data only as long as necessary to:

  • Provide the App’s functionality
  • Maintain billing records
  • Comply with legal obligations

SAAS Order Management data (opt-in add-on). When a merchant enables SAAS Order Management, the App stores the customer’s name, phone number and, for delivery orders, shipping address. Once an order is complete — collected, dispatched or refunded — those customer details are automatically removed after the retention window the merchant sets in the App settings, up to a maximum of 60 days. The order record itself (order number, totals and line items) is kept for the merchant’s own history; the customer’s personal details are erased from it.

Orders that are still open keep their customer details for as long as they remain open, because staff cannot otherwise complete them. This covers orders being prepared, orders waiting to be collected or dispatched, and orders a store has flagged as unable to fulfil, including those under review by head office. Those details are removed once the order is completed and ages past the window.

Staff activity records are kept for a separate period the merchant sets, up to a maximum of 60 days, after which they are automatically deleted.

Data is never retained longer than the merchant’s setting, except where billing or law requires it.

Upon uninstalling the App:

  • API access is revoked immediately
  • Stored order and staff records for that store, including all customer details held by SAAS Order Management, are deleted

The App implements Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). On a customer redaction request, that customer’s name, phone number and address are erased from the App’s order records. Merchants may contact us to request confirmation of data deletion.

 

5. Store Staff and User Data

SAAS Order Management gives a merchant’s store staff their own accounts, so they can work without access to the Shopify admin. For those users the App stores:

  • Staff name and, where the merchant provides it, an email address
  • A mobile number, where the staff member or merchant provides one, used only to send that staff member a reset code when they need to recover their PIN or password
  • Credentials, stored only as one-way cryptographic hashes. Passwords and PINs are never stored in a readable form and cannot be retrieved by us
  • An activity record of actions taken in the App — such as picking, collecting, dispatching, refunding and signing in — together with the staff member and store location

This information is used only to operate the App for that merchant: to authenticate staff, to apply the permissions the merchant has assigned, to allow credential recovery, and to give the merchant an accountable record of who did what. Staff mobile numbers are never used for marketing and are not shared other than with the merchant’s own SMS provider to deliver the reset message.

The merchant is the employer and controls these accounts. Merchants can add, amend and remove staff at any time within the App, and removing a staff member removes their credentials.

 

6. Merchant Responsibilities

Merchants remain the data controller of customer information processed through Shopify, and of the staff accounts they create in SAAS Order Management.

If a customer requests deletion or access to their personal data, merchants should manage these requests through Shopify. We will assist where required.

Merchants are responsible for informing their own staff how the App records their activity, and for setting retention periods appropriate to their obligations.

 

7. Data Security

We implement industry-standard safeguards including:

  • Encrypted data transmission (HTTPS/TLS)
  • Encryption of stored data at rest, including backups
  • Separation of test and production data
  • Restricted internal access controls, limited to authorised personnel
  • Role-based staff permissions and a per-action PIN within SAAS Order Management
  • An access and activity log recording actions taken on order data
  • Secure hosting environments
  • A documented process for responding to any security incident

 

8. International Data Transfers

Data may be processed in jurisdictions where our infrastructure providers operate. We take reasonable steps to ensure data is protected in accordance with applicable privacy laws.

 

9. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be reflected on this page with a revised effective date. Continued use of the App constitutes acceptance of updates.

 

10. Contact Information

If you have privacy-related questions, please contact:

Email: ecommerceapps@saasintegrator.com
Website: https://www.saasintegrator.com