Summary: NativeQuote collects customer contact information solely to generate B2B wholesale quotation requests and create official draft orders in your Shopify admin. We never sell, broker, or monetize your store or buyer data, and we honor all GDPR/CCPA data deletion requests within 48 hours.
1. Introduction
NativeQuote ("we", "our", or "the App"), operated under the SyntaCraft studio brand, provides B2B wholesale Request-for-Quote (RFQ) tooling and draft order management for Shopify merchants. This Privacy Policy explains what information we collect, how it is used, and how it is protected when merchants and buyers use our service.
2. Information We Collect
To provide automated quotation functionality, NativeQuote accesses data strictly through Shopify’s official APIs and storefront app extensions:
- Merchant Information: Store name, myshopify domain, merchant email, installed access scopes, and subscription status.
- Buyer & Quote Information: Name, business email address, phone number, company name, VAT/Tax ID, requested product line items, quantities, and optional custom quotation notes.
- Draft Order Identifiers: Shopify Draft Order IDs and resulting Order IDs used exclusively for automated status reconciliation and revenue analytics.
3. How We Use Collected Data
Data collected by NativeQuote is used strictly for:
- Ingesting and displaying wholesale quotation requests in the merchant admin dashboard.
- Generating official Shopify Draft Orders with negotiated discounts and freight shipping.
- Dispatching native branded email invoices via Shopify’s official draft order engine.
- Attributing and displaying converted wholesale revenue in merchant KPI analytics.
4. Data Sharing & Third Parties
We do not sell, rent, or trade merchant or customer data. Data is shared only with:
- Shopify Inc.: To create draft orders, update inventory, and register completed checkouts via official GraphQL APIs.
- Infrastructure Providers: Encrypted hosting providers (Cloudflare edge and private VPS infrastructure) operating under strict data processing agreements.
5. Data Retention & GDPR / CCPA Compliance
We adhere strictly to Shopify’s Protected Customer Data (PCD) requirements and international privacy regulations (GDPR, CCPA):
- Data Retention: We store quote records only for as long as the merchant maintains the app installed.
- App Uninstallation: When a merchant uninstalls the app, our automated lifecycle webhook triggers and store records are purged within 48 hours.
- Right to Access & Erasure: We maintain active endpoints for mandatory Shopify privacy webhooks (
customers/data_request,customers/redact, andshop/redact). Buyers may request immediate data erasure through their merchant or by emailing us directly.
6. Security & Encryption
All data in transit is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS). Databases are isolated behind private Tailscale mesh networks and Cloudflare edge firewalls with zero open public ingress ports. NativeQuote does not collect or store credit card numbers; all payments are processed securely through Shopify’s PCI-DSS Level 1 certified checkout.
7. Contact Us
If you have questions regarding this Privacy Policy or wish to exercise your data privacy rights, please contact our Data Protection team:
SyntaCraft Privacy Team
Email: [email protected]
Website: https://nativequote.syntacraft.com