← Back to NativeQuote
Compliance & Privacy

Privacy Policy

Last updated: September 8, 2026 • SyntaCraft Studio (nativequote.syntacraft.com)

Summary: NativeQuote collects customer contact information solely to generate B2B wholesale quotation requests and create official draft orders in your Shopify admin. We never sell, broker, or monetize your store or buyer data, and we honor all GDPR/CCPA data deletion requests within 48 hours.

1. Introduction

NativeQuote ("we", "our", or "the App"), operated under the SyntaCraft studio brand, provides B2B wholesale Request-for-Quote (RFQ) tooling and draft order management for Shopify merchants. This Privacy Policy explains what information we collect, how it is used, and how it is protected when merchants and buyers use our service.

2. Information We Collect

To provide automated quotation functionality, NativeQuote accesses data strictly through Shopify’s official APIs and storefront app extensions:

  • Merchant Information: Store name, myshopify domain, merchant email, installed access scopes, and subscription status.
  • Buyer & Quote Information: Name, business email address, phone number, company name, VAT/Tax ID, requested product line items, quantities, and optional custom quotation notes.
  • Draft Order Identifiers: Shopify Draft Order IDs and resulting Order IDs used exclusively for automated status reconciliation and revenue analytics.

3. How We Use Collected Data

Data collected by NativeQuote is used strictly for:

  • Ingesting and displaying wholesale quotation requests in the merchant admin dashboard.
  • Generating official Shopify Draft Orders with negotiated discounts and freight shipping.
  • Dispatching native branded email invoices via Shopify’s official draft order engine.
  • Attributing and displaying converted wholesale revenue in merchant KPI analytics.

4. Data Sharing & Third Parties

We do not sell, rent, or trade merchant or customer data. Data is shared only with:

  • Shopify Inc.: To create draft orders, update inventory, and register completed checkouts via official GraphQL APIs.
  • Infrastructure Providers: Encrypted hosting providers (Cloudflare edge and private VPS infrastructure) operating under strict data processing agreements.

5. Data Retention & GDPR / CCPA Compliance

We adhere strictly to Shopify’s Protected Customer Data (PCD) requirements and international privacy regulations (GDPR, CCPA):

  • Data Retention: We store quote records only for as long as the merchant maintains the app installed.
  • App Uninstallation: When a merchant uninstalls the app, our automated lifecycle webhook triggers and store records are purged within 48 hours.
  • Right to Access & Erasure: We maintain active endpoints for mandatory Shopify privacy webhooks (customers/data_request, customers/redact, and shop/redact). Buyers may request immediate data erasure through their merchant or by emailing us directly.

6. Security & Encryption

All data in transit is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS). Databases are isolated behind private Tailscale mesh networks and Cloudflare edge firewalls with zero open public ingress ports. NativeQuote does not collect or store credit card numbers; all payments are processed securely through Shopify’s PCI-DSS Level 1 certified checkout.

7. Contact Us

If you have questions regarding this Privacy Policy or wish to exercise your data privacy rights, please contact our Data Protection team:

SyntaCraft Privacy Team
Email: [email protected]
Website: https://nativequote.syntacraft.com