NF / Privacy / Shopify
Bulk Gift Orders — Privacy policy
Scope and product boundary
This policy explains how Bulk Gift Orders handles information when it is installed in a Shopify store. The app turns a merchant-supplied recipient spreadsheet into reviewed Shopify orders or draft orders. It does not ship gifts, deliver packages, provide a customer database, or sell recipient information.
Information processed
Bulk Gift Orders processes the minimum information needed to validate and create a batch:
- Shopify store, installation and session identifiers used to scope access.
- Product and variant identifiers, SKUs, barcodes, prices and availability needed for matching.
- Recipient names, delivery addresses, email addresses and phone numbers when the merchant includes them in an upload.
- Recipient ids, quantities, financial-state instructions, validation issues and the resulting order or draft-order references.
- Batch configuration, mapping choices, usage counters, audit events and technical logs needed to operate and support the service.
Why we process it
We use this information to detect columns, validate rows, show exceptions, create the orders or drafts the merchant explicitly approves, prevent duplicate creation after a retry, produce reconciliation reports and answer support requests. We do not use recipient data for advertising, profiling or sale to third parties.
Merchant responsibility
The merchant decides which recipient information to upload and is responsible for having a lawful basis and the appropriate notices for that use. Upload only information needed for the selected Shopify workflow, keep exported reports confidential and do not use the app to send information to a store or recipient without the required authorisation.
Storage, isolation and retention
Batch records are scoped to the authenticated Shopify store. Uploaded rows and generated reports are kept only for the operational workflow: mapping, preflight, resumable creation, audit and reconciliation. Retention follows the app configuration and the deletion requests available to the merchant; data that is no longer required is removed through the service's retention and deletion paths. We do not build a cross-store recipient directory.
Shopify and service providers
The app uses Shopify's APIs and authentication to access the store you authorise. NarrowForge may use hosting, database and error-monitoring providers needed to run the service. Those providers receive only the information required to perform their role and are expected to protect it under their applicable agreements. Payment details are handled by Shopify App Pricing; NarrowForge does not receive or store card numbers.
Deletion and privacy requests
Uninstalling revokes the app's access. To request deletion of stored batch data or ask a privacy question, use the data deletion page or the support form with the store domain and the relevant batch reference. Do not include passwords, API keys or unnecessary recipient data in a support request.
Your rights and contact
Depending on the applicable law, you may have rights to access, correct, delete, restrict or export personal information. We will route requests to the merchant where the merchant controls the recipient data and will respond to the request using the information needed to verify its scope. Privacy contact: support@narrowforge.com.
Last updated: 2026-09-12.
