QuoteFlow Privacy Policy

Effective date: 28 August 2026

QuoteFlow is provided by StoreForge Labs ("QuoteFlow", "we", "us"). This policy explains how QuoteFlow processes information when a Shopify merchant installs or uses the app and when a customer submits a quote request through a merchant's storefront.

Information we process

Merchant information may include the Shopify shop domain, app settings, notification email address and technical information required to operate the service.

Quote-request information may include customer name, email, optional phone number, company, postcode and message; product and variant identifiers; requested quantity; quoted prices, shipping, discounts and tax; Shopify Draft Order identifiers; and quote/payment status.

How we use information

We use this information only to provide QuoteFlow functionality: receiving quote requests, allowing merchants to prepare quotes, creating Shopify Draft Orders and invoices, synchronizing payment status, sending merchant notifications, providing support, securing the service and meeting privacy/legal obligations.

Service providers

QuoteFlow relies on Shopify for commerce and authentication, Railway for application/database infrastructure, and Resend for transactional merchant email notifications. We do not sell personal information or use customer quote data for third-party advertising.

Data minimization and security

QuoteFlow is designed to process only data needed for quoting and related merchant workflows. Transactional notification emails avoid copying customer phone numbers, postal details or full customer messages. Security audit records do not contain customer PII, session tokens, API secrets or payment-card data.

Retention and deletion

Quote records are retained for the merchant-selected period of 90, 180, 365 or 730 days, with 730 days as the default maximum. Privacy-request export payloads are retained for up to 30 days and QuoteFlow security audit records for up to 365 days.

Shopify privacy requests are supported through mandatory compliance webhooks. Customer-redaction requests anonymize matching personal fields. Shopify shop-redaction requests erase that shop's QuoteFlow records, settings and sessions, unless retention is legally required.

Privacy requests

Customers should normally submit access or deletion requests through the Shopify merchant with whom they interacted. Shopify then sends the appropriate privacy request to installed apps where applicable.

International processing

Infrastructure providers may process information in countries other than the country where a merchant or customer is located. Where required, applicable contractual and platform safeguards are used.

Changes

We may update this policy as QuoteFlow changes or legal/platform requirements evolve. The effective date above identifies the current version.

Contact

Privacy or support enquiries can be submitted through QuoteFlow's support channel shown in Shopify Admin or the Shopify App Store.

This policy describes QuoteFlow's product practices and is not legal advice. StoreForge Labs should review it with appropriate professional advice where required.