Effective 11 September 2026

Privacy policy

Effective date: 11 September 2026

POClerk (poclerk.com) is an app for Shopify stores that turns emailed purchase orders into draft orders. It is operated by MB Croppick, company code 308104331, registered office Krivių g. 5, LT-01204 Vilnius, Lithuania ("POClerk", "we", "us"). Questions and requests: privacy@poclerk.com.

The short version

  • We store your purchase-order emails and files so you can review them, and we delete the originals automatically after a retention window you control (90 days unless you change it).
  • PO content is sent to one AI provider (Anthropic) to read it. It is not used to train AI models.
  • Everything lives on Cloudflare's platform; the database and file storage are located in Cloudflare's Eastern Europe region.
  • We never sell personal data, never use buyer data for marketing, and show no ads.
  • For your buyers' data we are your processor; the Data processing agreement that applies automatically on install sets out the terms.
  • Uninstall the app and everything is deleted, automatically, on Shopify's standard schedule.

Who this policy covers

  • Merchants — the store that installs POClerk. For your account data, we are the data controller.
  • Buyers — your wholesale customers whose names and email addresses appear on purchase orders. For buyer data, you (the merchant) are the controller and POClerk is your processor: we handle it only to provide the service to you, on your instructions as expressed through the app. The terms of that processing are written down in our Data processing agreement, which applies automatically when you install the app.

Legal basis

Where we are the controller, we rely on these grounds under the GDPR:

  • Your merchant account — store identity, contact email, settings, plan and billing status: necessary to perform our contract with you (Article 6(1)(b)).
  • Usage metrics, security logs and abuse prevention — the counters in Cloudflare Analytics Engine, our audit log, sender authentication, the Turnstile check and rate limits: our legitimate interest in running a reliable, secure service (Article 6(1)(f)).
  • Billing records — the record of what you were charged, which reaches us through Shopify's payouts: our legal obligation to keep accounting records (Article 6(1)(c)).
  • Buyer data is processed on your instructions as your processor, so the legal basis is yours to determine, not ours to state.

What we collect, why, where, and for how long

What Why Where it is stored How long
Merchant account — store domain, store name, contact email, app settings, plan and billing status, encrypted Shopify API tokens To run the app for your store and bill through Shopify Cloudflare D1 database (Eastern Europe region) While the app is installed; deleted after uninstall (see "Uninstalling")
Purchase-order documents — the raw emails your buyers send or you forward, their attachments (PDF, Excel, CSV, images), and files you upload To read the order and show you the original beside what was entered Cloudflare R2 file storage (Eastern Europe region) Purged automatically after your retention window — default 90 days, adjustable 7–365 days in Settings; also deleted on buyer redaction and on uninstall
Extracted order data — buyer name and email, PO number and date, order lines (quantities, item codes, prices), match results and review notes So you can review, fix, and create the draft order; per-customer alias memory Cloudflare D1 (Eastern Europe region) The order's summary (buyer, PO number and date, line counts, order value, draft-order reference) while the app is installed; the line-by-line detail (quantities, item codes, prices, match results, review notes) for 24 months after the PO arrived, then deleted automatically; buyer-identifying fields deleted on a buyer redaction request; everything deleted on uninstall
Product catalog snapshot — your products' SKUs, titles, options, barcodes and prices To match PO lines to your products Cloudflare D1 (Eastern Europe region) Kept in sync while installed; deleted on uninstall
Usage metrics — counts of documents processed, per-line result classes, processing cost and latency, keyed to your store Service quality, plan limits, and our published aggregate accuracy statistics Cloudflare Analytics Engine Retained for about three months (Cloudflare's Analytics Engine retention window), then expires automatically
Feedback — messages you send through the in-app or site feedback form, with an optional email address To read and answer your feedback Cloudflare D1 (Eastern Europe region) Until handled; deleted on uninstall

We do not collect payment card details (Shopify handles all billing) and we place no advertising or cross-site tracking cookies. The embedded app uses Shopify session tokens for sign-in; the website uses no analytics that identify you. The public feedback form is protected by Cloudflare Turnstile, a privacy-preserving check that blocks automated spam.

AI processing (how POClerk reads a PO)

To extract order lines and match uncertain lines to your catalog, POClerk sends the content of each purchase order — the document text or images, plus a shortlist of candidate products from your catalog — to Anthropic (the Claude API), our AI subprocessor. Under Anthropic's commercial API terms, this data is not used to train AI models. POClerk does not train any model of its own on your data either. Anthropic states that it deletes API inputs and outputs from its systems within 30 days of receipt or generation, except where it must keep them longer to enforce its usage policy or to comply with law. We have no custom retention arrangement with Anthropic, so that standard period applies to what POClerk sends it. What the AI produced is always visible: every entered line can be inspected next to the original document, and uncertain lines are held for your review rather than acted on.

Where your data lives

POClerk runs entirely on Cloudflare's platform. The database (Cloudflare D1) and file storage (Cloudflare R2) that hold the data above are located in Cloudflare's Eastern Europe region (verified 21 July 2026). Requests are processed by Cloudflare's global edge network in transit, as with any Cloudflare-hosted service. Inbound PO email is received by Cloudflare Email Routing at your store's dedicated address on in.poclerk.com; confirmation replies are sent through Cloudflare Email Sending from mail.poclerk.com.

Who we share data with (subprocessors)

Subprocessor What they process Why
Cloudflare (hosting, storage, email) All data in the table above, encrypted in transit Runs the entire service
Anthropic (Claude API) PO content and candidate catalog lines, per "AI processing" above Reads and matches purchase orders
Shopify Your store identity, subscription/billing events, draft orders the app creates in your store The platform the app runs on
Google (Gmail) Email you send to support@poclerk.com or privacy@poclerk.com, and our replies Our support and privacy mailboxes are delivered to, and answered from, Gmail

That is the whole list. We do not sell personal data, share it with data brokers or advertisers, or use buyer data for any marketing.

Changes to this list. Before a new subprocessor starts processing merchant or buyer data, we update this table and tell you in the app or by email, giving you the opportunity to object. If you object, you can uninstall before the change takes effect, and the deletion described below applies.

How long we keep data (summary)

  • Raw PO files (emails, attachments, uploads): deleted automatically by a nightly job once older than your retention setting — default 90 days, adjustable 7–365 days. The machine-readable extraction we derived from a file is deleted together with it.
  • Entered order lines: the line-by-line detail of a PO (quantities, item codes, prices, match results, review notes) is deleted automatically 24 months after the PO arrived. The order itself stays reviewable — buyer, PO number, line counts, order value and the draft-order reference remain — so your order history keeps its summary while the line-level detail ages out.
  • Buyer redaction: on a customer data-erasure request relayed by Shopify, we delete that buyer's identity records, learned aliases, their documents' identifying fields, and all their raw files.
  • Uninstalling: uninstalling revokes our access token immediately. Shopify sends the shop-deletion signal about 48 hours later, and on it we delete everything — all files and every database record for the store. Draft orders already created live in your Shopify store and are yours.
  • Restore history: our database (Cloudflare D1) keeps an automatic restore history of the whole database for 30 days. A record we delete — on uninstall, on a buyer redaction, or when its retention period ends — leaves the live database at once and drops out of that history within 30 days. We use it only to recover the service from a failure, never to look up individual records, and if we ever restore it, we repeat every erasure and scheduled deletion made since the restore point.

Your rights

Merchants can access and change their data in the app (settings, aliases, buyers, documents) or write to privacy@poclerk.com to access, correct, export, or delete anything, or to object to or restrict processing. If you are in the EU/EEA or UK, you also have the right to complain to a supervisory authority. Our lead supervisory authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos g. 17, LT-10312 Vilnius, vdai.lrv.lt — or you can complain to the authority in your own EU/EEA/UK country.

Buyers should direct requests to the merchant they ordered from — the merchant is the controller of buyer data. POClerk supports the merchant's obligations automatically through Shopify's mandatory privacy webhooks:

  • customers/data_request — logged and surfaced so the merchant can provide the buyer's data; we assist on request.
  • customers/redact — the buyer's personal data is erased as described above.
  • shop/redact — the store's complete data is erased after uninstall.

Security

  • Shopify access tokens are stored encrypted (AES-GCM) and never leave the server side.
  • All traffic is TLS; webhooks are verified with Shopify's HMAC signatures before anything is processed.
  • Inbound email is checked against sender authentication (DMARC); by default, mail that fails authentication for your address is rejected.
  • Files are stored under per-store keys and served only through authenticated, signed URLs.
  • The app requests only the Shopify permissions it needs, and holds Shopify's protected customer data approval for the customer fields it uses (name and email) — used solely to enter and review orders.

International transfers

Primary storage is in Cloudflare's Eastern Europe region. Anthropic is a US provider; transfers to it are covered by a data-processing agreement that incorporates the EU standard contractual clauses. Cloudflare processing is covered by Cloudflare's data-processing addendum. Our support and privacy mailboxes are hosted by Google (Gmail), a US provider; Google LLC is certified under the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. DPF.

Children

POClerk is a business tool for merchants and is not directed at children.

Changes to this policy

If this policy changes materially, we will note it here with a new effective date and flag it in the app.

  • 11 September 2026 — effective date moved together with the terms of service, which now state what counts as an order and how long the one-time grace lasts. Nothing in this policy changed.
  • 10 September 2026 — deletion: records deleted from our database drop out of its automatic 30-day restore history, which is used only to recover the service from a failure, and a restore repeats every erasure and scheduled deletion made since its restore point. Subprocessors: a new one is announced to you beforehand, with the opportunity to object; the fixed minimum of 14 days' notice is removed. Nothing about what is collected, where it is stored, or how long the live service keeps it has changed.
  • 5 September 2026 — retention: the line-by-line detail of a PO is now deleted automatically 24 months after the PO arrived, while the order's summary stays; the machine-readable extraction derived from a raw file is deleted together with that file; and the catalog snapshot no longer lists inventory levels, which POClerk does not store. Nothing else changed.
  • 28 August 2026 — completeness: the registered office is stated; a legal-basis section, Google (Gmail) as the subprocessor for email correspondence with a notice procedure for future changes, our lead supervisory authority, and Anthropic's published retention period were added; and the new Data processing agreement writes down the processor terms for buyer data. Nothing about what is collected, where it is stored, or how long it is kept has changed.
  • 17 August 2026 — the operator is now named: POClerk is operated by MB Croppick, the company registered for it. Nothing about what is collected, where it is stored, or how it is handled has changed.

Contact

privacy@poclerk.com — or support@poclerk.com for anything else.

See also the terms of service. Questions about anything on this page: privacy@poclerk.com.