Privacy
How BasePO handles merchant, workspace, operational, and Shopify compliance data.
Launch-readiness notice
This policy is prepared for launch readiness. BasePO is not yet publicly launched.
Data BasePO uses
BasePO uses Shopify store identity, product, inventory, location, purchase-order, and app-access data to provide purchasing, receiving, barcode, and workspace features. BasePO does not use Shopify customer or order personal data as part of its core workflow.
Account and operational records
Personal workspace accounts, roles, Shopify staff mappings, security events, and operational activity are stored to authorize access, investigate failures, and protect store data. Operational activity is retained for no more than 90 days and is removed when the app is uninstalled for that store.
Shopify privacy requests
BasePO receives Shopify's required privacy webhooks. Customer requests are completed with a no-data outcome when BasePO holds no matching customer data. Request identifiers and payload details are removed after fulfillment; only minimized, non-identifying outcome evidence may be retained for up to 24 months unless a lawful hold applies.
Security and service providers
Tokens are encrypted at rest and server access is restricted by store and role. BasePO uses service providers including Shopify, Supabase, and Vercel to operate the app.
Contact
Questions and privacy requests can be sent to privacy@basepohq.com. The primary privacy owner is Adrien Lamoureux, with Lindsey Lamoureux as backup.
Last updated
July 31, 2026
