ReceiveFlow
Privacy Policy
How ReceiveFlow handles the information merchants use to manage purchasing, receiving, and reconciliation.
Last updated: August 24, 2026
Information we process
ReceiveFlow stores information that a merchant enters or imports to manage suppliers, purchase orders, receiving, inventory adjustments, invoices, payments, credits, discrepancies, and accounting exports.
We also process the merchant's Shopify store identifier, authorized staff session information, access token, granted scopes, products, variants, inventory locations, and inventory transfers as needed to provide the app.
ReceiveFlow does not request Shopify customer or order access and does not process customer payment-card information.
How we use information
- Provide purchasing, receiving, reconciliation, and reporting workflows.
- Apply merchant-initiated Shopify inventory adjustments.
- Generate documents, barcode labels, and accounting exports.
- Secure, operate, troubleshoot, and improve the service.
- Meet legal, security, fraud-prevention, and Shopify platform obligations.
We do not sell or rent merchant data or use it for third-party advertising.
Service providers
ReceiveFlow uses Shopify for app authentication and billing, Render for application hosting, Neon for PostgreSQL database hosting, Sentry for error and performance monitoring, and Resend for transactional purchase-order and supplier-claim email. Those providers process only the information necessary to deliver the requested feature.
Uploaded documents use private Cloudflare R2 storage and a Render-hosted ClamAV malware-scanning worker. Documents remain unavailable while scanning and can be downloaded through short-lived signed links only after a clean result. Infected files and files that cannot be scanned successfully remain unavailable and are queued for deletion.
Security and retention
Data is encrypted in transit. Production providers encrypt stored data at rest. Access is restricted by tenant, and downloadable resources use short-lived, purpose-specific authorization.
ReceiveFlow retains merchant data while the app is installed and as needed to provide the service. After uninstall or a verified deletion request, database data is deleted and stored objects are queued for deletion, subject to limited backup, security, and legal-retention requirements.
Your choices and rights
Merchants may request access, correction, export, or deletion of their ReceiveFlow data. Uninstalling the app initiates account-data deletion. Because ReceiveFlow does not request customer or order data, Shopify customer data requests normally return no stored customer records.
Contact
For privacy questions or requests, email support@receiveflow.app.