Privacy

How BasePO handles merchant, workspace, operational, and Shopify compliance data.

Launch-readiness notice

This policy is prepared for launch readiness. BasePO is not yet publicly launched.

Data BasePO uses

BasePO uses Shopify store identity, product, inventory, location, purchase-order, and app-access data to provide purchasing, receiving, barcode, and workspace features. BasePO does not use Shopify customer or order personal data as part of its core workflow.

Account and operational records

Personal workspace accounts, roles, Shopify staff mappings, security events, and operational activity are stored to authorize access, investigate failures, and protect store data. Operational activity is retained for no more than 90 days and is removed when the app is uninstalled for that store.

Shopify privacy requests

BasePO receives Shopify's required privacy webhooks. Customer requests are completed with a no-data outcome when BasePO holds no matching customer data. Request identifiers and payload details are removed after fulfillment; only minimized, non-identifying outcome evidence may be retained for up to 24 months unless a lawful hold applies.

Security and service providers

Tokens are encrypted at rest and server access is restricted by store and role. BasePO uses service providers including Shopify, Supabase, and Vercel to operate the app.

Contact

Questions and privacy requests can be sent to privacy@basepohq.com. The primary privacy owner is Adrien Lamoureux, with Lindsey Lamoureux as backup.

Last updated

July 31, 2026