ReceiveFlow

ReceiveFlow

Privacy Policy

How ReceiveFlow handles the information merchants use to manage purchasing, receiving, and reconciliation.

Last updated: August 24, 2026

Information we process

ReceiveFlow stores information that a merchant enters or imports to manage suppliers, purchase orders, receiving, inventory adjustments, invoices, payments, credits, discrepancies, and accounting exports.

We also process the merchant's Shopify store identifier, authorized staff session information, access token, granted scopes, products, variants, inventory locations, and inventory transfers as needed to provide the app.

ReceiveFlow does not request Shopify customer or order access and does not process customer payment-card information.

How we use information

  • Provide purchasing, receiving, reconciliation, and reporting workflows.
  • Apply merchant-initiated Shopify inventory adjustments.
  • Generate documents, barcode labels, and accounting exports.
  • Secure, operate, troubleshoot, and improve the service.
  • Meet legal, security, fraud-prevention, and Shopify platform obligations.

We do not sell or rent merchant data or use it for third-party advertising.

Service providers

ReceiveFlow uses Shopify for app authentication and billing, Render for application hosting, Neon for PostgreSQL database hosting, Sentry for error and performance monitoring, and Resend for transactional purchase-order and supplier-claim email. Those providers process only the information necessary to deliver the requested feature.

Uploaded documents use private Cloudflare R2 storage and a Render-hosted ClamAV malware-scanning worker. Documents remain unavailable while scanning and can be downloaded through short-lived signed links only after a clean result. Infected files and files that cannot be scanned successfully remain unavailable and are queued for deletion.

Security and retention

Data is encrypted in transit. Production providers encrypt stored data at rest. Access is restricted by tenant, and downloadable resources use short-lived, purpose-specific authorization.

ReceiveFlow retains merchant data while the app is installed and as needed to provide the service. After uninstall or a verified deletion request, database data is deleted and stored objects are queued for deletion, subject to limited backup, security, and legal-retention requirements.

Your choices and rights

Merchants may request access, correction, export, or deletion of their ReceiveFlow data. Uninstalling the app initiates account-data deletion. Because ReceiveFlow does not request customer or order data, Shopify customer data requests normally return no stored customer records.

Contact

For privacy questions or requests, email support@receiveflow.app.