This Privacy Policy explains how Gold & Jewelry ERP (the “App”, “we”, “us”, or “our”) collects, uses, stores, and deletes information when a merchant installs or uses the App.
1. Information we process
- Shop and installation information: the merchant’s
myshopify.comdomain, installation status, granted permissions, and encrypted Shopify authentication credentials. - Account information: company or workshop name, administrator and user names, email addresses, language, currency, password hashes, roles, and permission levels.
- ERP records entered by users: raw-material lots, metal and fineness information, workshop jobs, products, barcodes, inventory records, sales, returns, refining and production-loss records, account records, and reports.
- Security and technical information: login activity, audit events, request time, request path, response status, IP address, error details, and similar operational logs. Passwords and authentication tokens are redacted from operational logs.
2. How we use information
We use information only to provide and secure the App, authenticate users and Shopify installations, keep each merchant’s records isolated, operate ERP features, provide support, prevent misuse, diagnose errors, comply with legal obligations, and respond to privacy requests.
3. Shopify data
The App uses Shopify authentication to identify and connect the installing store. Shopify access and refresh tokens are encrypted at rest. The App currently requests no protected customer data and does not import Shopify customers, orders, products, or inventory.
4. Sharing and service providers
We do not sell personal information. Information may be processed by hosting, database, security, and infrastructure providers solely as needed to operate the App. We may also disclose information when required by law, to protect rights and security, or as part of a business transfer subject to appropriate safeguards.
5. Data retention and deletion
We retain account and ERP information while the merchant account is active and as reasonably necessary for security, dispute resolution, and legal compliance. When Shopify sends a valid shop-redaction request and no other store remains connected to the company account, the App deletes the connected shop record and the associated company, users, ERP records, and audit records. Encrypted Shopify credentials are disabled and removed when the App is uninstalled or the connection is revoked.
6. Security
We use tenant isolation, encrypted Shopify credentials, password hashing, access controls, signed sessions, audit records, request logging with sensitive-field redaction, and transport encryption. No method of transmission or storage can be guaranteed to be completely secure.
7. International processing
Information may be processed in countries other than the merchant’s country. Where required, we use appropriate safeguards for cross-border processing.
8. Your rights
Depending on applicable law, users may have rights to access, correct, delete, restrict, or object to processing of their personal information. Merchants are responsible for handling privacy rights relating to data they enter into their ERP account. Requests may be sent to the contact address below.
9. Changes to this policy
We may update this policy when the App, legal requirements, or our practices change. The effective date at the top of this page will show the latest revision.
10. Contact
For privacy questions or requests, contact:
Gold & Jewelry ERP
Email: siparishattimv@gmail.com