Steady Orders (the “app”) is operated by Sons of Adonis Ltd (Registered in England and Wales, company number 12202136), whose registered office is Clavering House, Clavering Place, Newcastle upon Tyne, NE1 3NG, United Kingdom (“we”). The app lets a Shopify merchant’s wholesale (B2B) customers set up standing orders that the app turns into Shopify draft orders or orders on a schedule. This policy explains what personal data the app handles for merchants and for their customers, why, and for how long.
Who is responsible
For data about a merchant’s customers, the merchant is the controller and we process that data on the merchant’s behalf to provide the app. For a merchant’s own account details and billing, we are the controller.
Information we receive through Shopify’s APIs
| Data | Why |
|---|---|
| Store name, domain, timezone, currency and the store’s contact email | Run schedules in the store’s local time and send merchant alerts |
| Company, company location and company contact names and ids; payment terms and the location’s shipping address | Create each draft order for the right buyer with the right terms and delivery address |
| The signed-in customer’s id, name and email, and their company memberships | Decide which company locations a buyer may order for; send the buyer their reminders |
| Product, variant and price information for a company location | Show the buyer their catalog and prices; create the order lines |
| Draft order and order ids, names, totals and payment status; order webhooks for orders the app created | Record what was created, show history and the dashboard, bill the merchant once per order |
| Recent orders of a company location (ids, dates, tags) | Suggest a standing order to buyers who re-order by hand, and list candidates for merchant invitations |
| Webhooks for app installation, subscription status, deleted companies, locations, contacts and products | Keep schedules consistent with the store and pause what can no longer run |
The app requests only the access scopes needed for the above; the full list and the reason for each is published in the app’s documentation.
Information merchants give us directly
App settings (ordering rules, reminder timing, an optional alert email address), standing orders a merchant sets up on a buyer’s behalf and the merchant’s attestation note, and invitations a merchant chooses to send. We do not ask merchants for information about their customers beyond what Shopify already holds.
Information customers give us directly
The standing orders a buyer creates and manages in their customer account: products, quantities, cadence and dates. The app’s customer account pages do not set cookies, do not use third-party tracking and do not record how customers browse the store. Requests from those pages carry a short-lived session token issued by Shopify so that the app can verify who is asking.
How we use the information
- To create draft orders and orders on the buyer’s schedule, with the merchant’s catalog pricing and payment terms.
- To email buyers about the standing orders they (or their merchant) set up: an advance reminder before each order, a notice when a total changes materially, and an acceptance request for a schedule the merchant set up. These are transactional messages about an arrangement the buyer is part of; they carry no unsubscribe link and stop when the schedule is paused or cancelled, when the buyer’s data is deleted, or when the merchant uninstalls the app.
- To email a merchant’s invitation to buyers who re-order by hand. Invitations carry an unsubscribe link; an address that uses it is recorded for that store and receives no further invitations from it. The unsubscribe applies to invitations only, not to the transactional messages above.
- To email merchants about schedules that need attention and about billing.
- To show merchants a dashboard and history of what the app created, and to bill merchants through Shopify.
- To keep operational logs and internal product events (for example “standing order created”) for troubleshooting. These contain ids, not message bodies.
We do not sell personal data, use it for advertising, or use it for any purpose other than providing and supporting the app.
Legal basis
- Merchant account and billing data: to perform our contract with the merchant (these terms and Shopify’s billing), and our legitimate interest in supporting, securing and troubleshooting the app.
- Data about a merchant’s customers: we process it on the merchant’s instructions to provide the app. The merchant, as controller, decides the legal basis for it, including for invitation emails sent on the merchant’s behalf.
- Records we must keep, such as billing records: to comply with our legal obligations.
Who else processes the data
- Shopify, which hosts the store and the customer account pages.
- Our hosting provider, which runs the app’s servers and database in the European Union (Railway, EU West).
- Our email provider, Resend, which delivers the emails described above and receives the recipient address, subject and body.
These providers process data only on our instructions, under data processing terms. We do not transfer data to anyone else.
Some of these providers are based in, or may access data from, the United States. Where personal data leaves the UK or the European Economic Area, it is protected by the safeguards in the provider’s data processing terms, such as the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses.
How long we keep it
- While the app is installed: for as long as the merchant uses it.
- After uninstall: the app stops all processing for the store at once. Queued emails are cancelled and no further emails are sent; the buyer email addresses stored on standing orders are removed immediately. Records of emails already sent, invitations, unsubscribe entries and earlier data-request exports still contain addresses at this point. Shopify sends the app a shop data erasure request 48 hours after uninstall, and on receipt the app deletes everything it holds for that store, those records included.
- Customer requests: when a customer asks a merchant for their data or its deletion, Shopify forwards the request to the app. For a deletion the app stops the customer’s standing orders, then removes their customer id, name, email, agreement details, one-off change authorship, invitations, unsubscribe entries, the addresses and content of emails sent to them, and their details from alerts, activity records and earlier data-request exports. Order history (dates, products, totals) is kept without any link to the person. For a data request the app prepares the records it holds for the merchant to pass on.
- Operational logs are kept for a limited period by our hosting provider and then discarded.
Security
Data moves over HTTPS only. Access tokens for Shopify are stored server-side and never sent to the customer account pages. Requests from Shopify are verified with signed tokens and webhook signatures.
Your rights and how to contact us
Under data protection law, including the UK GDPR and the EU GDPR, you may have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format.
Customers should contact the merchant they buy from; merchants can raise the request with Shopify, which forwards it to the app, or email us directly. Merchants can see, change and delete what the app holds about their standing orders inside the app, and can remove everything by uninstalling it.
If you are unhappy with how your data is handled, please contact us first. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data protection authority where you live.
Questions about this policy: support@steadyorders.com. Postal address: Clavering House, Clavering Place, Newcastle upon Tyne, NE1 3NG, United Kingdom.
Changes
We will update this page when our data practices change and show the date above.