Last updated 3 August 2026
FulfilFlow is a Shopify app that tracks fulfilment turnaround time against a service-level target you set, flags orders at risk of missing it, and lets your team claim and resolve them. This policy explains what data the app accesses, what it stores, and how it's used.
Through Shopify's API, FulfilFlow reads order data needed to calculate fulfilment timing: order ID and name, created/fulfilled/ cancelled timestamps, fulfilment location, line-item SKUs, and whether an order is a business (B2B) or consumer (DTC) purchase. We do not read or store customer names, emails, phone numbers, or shipping addresses.
We keep a durable copy of the order-timing fields above so the dashboard can chart trends over time, plus your own app settings (SLA target hours, and an alert destination URL if you've turned on Slack, Discord, or webhook alerts). We also store the OAuth access token issued when you install the app, so we can keep talking to your store's API — this token is never shared and is only used to serve your store's own data back to you.
Nobody, except where you've explicitly configured it. If you turn on breach alerts, we send a short summary (shop name and the order(s) affected) to the alert URL you provided — that's a destination you control, not a third party we choose. We don't sell data, and we don't share it with any other outside service.
Data is kept for as long as the app is installed. If you uninstall FulfilFlow, everything we hold for your store — order-timing history, settings, and your access token — is deleted automatically, in line with Shopify's mandatory data-protection requirements for apps.
Access tokens are stored server-side only and never exposed to the browser. Outbound alert requests are validated to stop the alert URL field being used to reach internal or private network addresses.
Because FulfilFlow doesn't store customer-identifiable data, most customer data-access or deletion requests won't find anything held against them here. For questions about your store's own data, or to request deletion outside the normal uninstall flow, contact us below.
If this policy changes in a material way, we'll update the date at the top of this page.
Questions about this policy or your data: aut0m4t1c.support@gmail.com