Employee Suite
Home CSV Exports Scheduled Reports Sales
Upgrade to Pro Settings
Settings Upgrade to Pro Logout

Privacy Policy

What Employee Suite accesses, why, and how to make us delete it.

Last updated: 17 August 2026

Employee Suite ("Employee Suite", "we", "our", "us") provides a Shopify application that reports on a merchant's store and schedules price changes on their behalf. This policy explains exactly what we access, why, how long we keep it, and how to make us delete it.

We have written this to be specific rather than broad. If something is not listed here, we do not collect it.

1. WHAT WE ACCESS FROM YOUR SHOPIFY STORE

When you install Employee Suite, Shopify grants us a limited set of permissions. We hold these and no others:

read_orders Order totals, dates, financial and fulfilment status. Used to count what is awaiting fulfilment, total revenue over a period, and how old the oldest unfulfilled order is.

read_products Product and variant titles, prices and SKUs. Used for stock reporting and to record a variant's price before a scheduled sale changes it.

read_inventory Stock levels per variant. Used to report what is low or out of stock, and to name those items so you know what to reorder.

write_products Used only to change variant prices at the start of a sale you have scheduled, and to restore the original prices at the end. Nothing else is written.

We do NOT request or hold customer names, email addresses, shipping addresses, phone numbers, or payment details.

Shopify classes order access as protected customer data, so we hold Level 1 access, which read_orders requires. We have not requested, and do not hold, Level 2 access, which is what covers customer names, email addresses, phone numbers and addresses. Our order queries do not ask for those fields at all, so they are never sent to us. Where an order in our reports would otherwise show a customer, it shows no identifying information.

We do not access your theme, your files, your discounts, your Shopify Payments account, or your customer accounts.

2. WHAT WE COLLECT DIRECTLY FROM YOU

- The email address you nominate to receive scheduled reports. - Your store domain and, if Shopify provides it, your store's display name. - Anything you write to us in a support request.

We do not use tracking pixels or advertising cookies. A session cookie is used to keep you signed in while the app is open.

3. WHAT WE STORE, AND FOR HOW LONG

Shopify access token Encrypted at rest using Fernet with a key derived via PBKDF2. Deleted when you uninstall.

Store domain and name Kept while the app is installed.

Report schedules The report type, frequency, delivery time and delivery email you configured. Deleted when you uninstall.

Scheduled sales The sale you configured, and for each product the price it had before we changed it. This record is what allows us to put your prices back. Retained for 90 days after a sale ends so a mistake can be traced, then deleted.

Aggregate counts Order counts, revenue totals and stock counts, held so a report can be produced. Overwritten on each refresh. Not retained as history.

We do not store the contents of your orders, your customer records, or your product catalogue beyond the fields listed above.

4. WHAT WE SEND, AND TO WHOM

Scheduled reports are emailed to the address you nominate. If you nominate an address that is not your own, you are responsible for having the right to send that person your store's figures.

We share data with these processors, and only as needed to run the service:

Render Application hosting. United States. Mailjet Email delivery. European Union. Neon / PostgreSQL Database hosting.

We do not sell your data. We do not share it for advertising. We do not use it to train machine learning models.

5. WHEN YOU UNINSTALL

Shopify notifies us. We then:

- Restore the original prices of any sale that is still running. - Delete your access token. - Delete your report schedules and sale records.

Shopify's compliance webhooks are implemented and verified by HMAC signature: customers/data_request, customers/redact, and shop/redact. Because we hold no customer data, a customer redaction request has nothing to erase, and we respond confirming that.

6. YOUR RIGHTS

Wherever you are, you may ask us to tell you what we hold about you, correct it, or delete it. Under the GDPR you additionally have the right to object to processing, to restrict it, and to receive your data in a portable format. Under the CCPA you have the right to know, to delete, and to opt out of sale - we do not sell data, so there is nothing to opt out of.

Write to the address in section 8. We will respond within 30 days.

In relation to your store's data, you are the controller and we are the processor. We act on your instructions and do not process your store's data for our own purposes.

7. SECURITY

- All traffic is over HTTPS with HSTS. - Access tokens are encrypted at rest. - Every Shopify webhook is verified by HMAC signature before it is accepted. - Access is scoped per store; you can only ever see stores you connected.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify you without undue delay and within 72 hours where the GDPR requires it.

8. CONTACT

Email: support@employeesuite.site Address: Hammond Park, Western Australia, Australia

If you are in the EU or UK and are not satisfied with our response, you may lodge a complaint with your local supervisory authority.

9. CHANGES

We will post any change here and update the date at the top. If a change materially affects what we collect or how we use it, we will tell you by email before it takes effect.

Terms of Service  ·  FAQ
FAQ | Privacy Policy | Terms of Service
© 2026 Employee Suite. All rights reserved.