Skip to content

Copiara is coming to the Shopify App Store. It is not listed yet.

Copiara

Privacy policy

Last updated: August 27, 2026

This policy explains what Copiara collects, why, who we share it with, how long we keep it, and how to get it back or have it deleted. It covers this website and the Copiara app for Shopify.

Who we are

Copiara is a B2B wholesale app for Shopify stores, operated by Yikes Dude LLC, a Texas limited liability company. In this policy, “Copiara”, “we”, and “us” mean that company.

This policy covers copiara.com and the Copiara application that a merchant installs into their Shopify store from the Shopify App Store, including the admin app embedded in the Shopify admin, the buyer-facing surfaces that run on the merchant’s own storefront, and the APIs behind them.

Our relationship with Shopify

Copiara does not host a store, a checkout, or a buyer account system. The merchant’s store runs on Shopify, and Shopify remains the system of record for products, inventory, companies, orders, and payment state. Copiara reads and writes that data through Shopify’s APIs under the access scopes the merchant grants at install, and it keeps a derived copy so it can serve the features Shopify does not provide.

Shopify’s own handling of merchant and buyer data is governed by the merchant’s agreement with Shopify and by Shopify’s privacy policy, not by this one. Uninstalling the app ends our access.

The two roles we play

Copiara handles personal data in two distinct capacities, and your rights differ depending on which one applies to you.

  • As a controller. For visitors to this website, people who contact us, and the merchant staff who administer a Copiara installation, we decide what is collected and why. This policy governs that data.
  • As a processor. For everything that reaches us from a merchant’s Shopify store or is created in the app, including their buyers, company contacts, catalog, pricing, quotes, and orders, the merchant is the controller and we act on their instructions. If you are a buyer using a merchant’s store, that merchant’s privacy notice governs your relationship, and requests about your data should go to them first. We will support them in answering you.

What we collect on this website

If you submit the contact form, we collect the name, work email, company, and, when you provide them, your role, an indication of catalog size, and whatever you write in the message field. We also record the submission time, the IP address the request came from, and the browser user agent. The IP address and user agent are used for rate limiting and abuse prevention, not for profiling.

The form includes a hidden honeypot field that real visitors never fill in. A submission that fills it is discarded without being stored or forwarded.

We use Google Analytics 4 on this website to understand which pages are read and where visitors arrive from. It is the only analytics tool on the site. We do not run advertising pixels, retargeting tags, or cross-site tracking, and we do not sell or share any of this for behavioral advertising.

What we receive from a merchant’s Shopify store

At install, a merchant grants the app a set of Shopify access scopes. Shopify shows the exact list before the merchant approves it, and the app cannot read or write anything outside it. These are the categories and why each is needed.

Data categoryWhy the app needs it
ProductsProducts, variants, images, base prices, and inventory levels, so the app can build its catalog read model, cross-references, and enrichment layer
CompaniesB2B companies, company locations, and their contacts, so quotes, approvals, and credit apply to the right buying organization
CustomersCustomer records for the people who buy from the store, so a signed-in buyer resolves to their company and their pricing
Orders and draft ordersOrders, draft orders, and payment and fulfillment state, so an accepted quote becomes a draft order and its outcome is read back

The personal data inside those categories is mostly business contact information: the names, work email addresses, phone numbers, and job roles of the people at a merchant’s buying companies, together with company and location addresses. We process it as a processor for the merchant.

What we collect inside the app

  • Identity. A merchant’s staff reach the admin app through Shopify, and Shopify establishes who they are. A buyer using the storefront surfaces signs in through Shopify customer accounts, and we resolve that session to their company and location. We never see or store a Shopify password.
  • Records the app creates. Quotes and their negotiation history, approval chains and spend limits, credit limits and exposure, cross-reference mappings, catalog enrichment, provenance, and change history. These can contain names, work contact details, and free-text notes.
  • Communications. Email the app sends on a merchant’s behalf, such as a quote notification, and the templates behind it.
  • AI concierge conversations. Buyer and staff messages, the responses generated, the tool calls made to answer them, and account facts extracted from the conversation.
  • Uploaded files. Catalog and cross-reference imports, product documents, and attachments.
  • Security and audit telemetry. Every state change writes an audit entry recording the actor, the action, the record touched, a sanitized payload, and request context including IP address and user agent. Denied access attempts are recorded without passwords, tokens, or raw request payloads.

How we use it

  • To provide the app: catalog search, cross-referencing, quoting, approvals, credit visibility, catalog enrichment, and the AI concierge.
  • To keep it secure and accountable: access control, rate limiting, abuse prevention, and the audit trail a merchant needs to answer who did what.
  • To support you: answering questions, diagnosing problems, and reaching you about service and security matters.
  • To run our own business: billing records, and responding to enquiries from this website.
  • To improve the app in aggregate, using operational and usage measures. We do not read a merchant’s commercial data to build features for someone else.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

Where the GDPR or UK GDPR applies, we rely on the following bases.

  • Performance of a contract for installation, app delivery, and support.
  • Legitimate interests for security, abuse prevention, audit logging, service communications, and responding to a business enquiry you sent us.
  • Consent for website analytics where consent is required in your jurisdiction, and for optional marketing email. You can withdraw it at any time.
  • Legal obligation for tax, accounting, and lawful requests.

For data we process on a merchant’s instruction, the merchant establishes the legal basis and we act under a data processing agreement.

The AI concierge and your data

The concierge runs on Vertex AI Gemini models and Vertex AI text embeddings inside our own Google Cloud project. When a buyer or a staff member uses it, their message, the catalog and account context needed to answer, and the generated response are sent to that project.

Under the Google Cloud terms applicable to that project, customer data sent to Vertex AI is not used to train Google’s foundation models. We do not use one merchant’s catalog, pricing, conversations, or orders to train models for another merchant, and we do not train models on customer data for general product improvement.

Conversations are stored against the merchant’s installation and pruned on the retention schedule below. Merchant and buyer content is treated as data, never as instructions to the model: a message cannot grant access to another merchant’s store, change a role, or bypass an approval path.

Cookies and similar technologies

  • This website. Google Analytics 4 sets analytics cookies. Nothing else on copiara.com sets a cookie. You can block them with your browser settings or the Google Analytics opt-out add-on, and the site works normally without them.
  • The app. Only strictly necessary storage: the short-lived session tokens that keep an admin or a buyer authenticated for the current session, and the preferences you set in the interface. There is no analytics or advertising instrumentation inside the app or on the surfaces it adds to a merchant’s storefront.

Sub-processors

These are the vendors that process personal data to run the site and the app. Each is engaged under terms that require confidentiality and appropriate security. Shopify is not listed here: it is the merchant’s own platform and the source of the data, not a vendor we introduce.

VendorWhat they do for usProcessing location
Google LLC (Google Cloud Platform)Application hosting, the production PostgreSQL database, object storage, secret management, and the Pub/Sub pipeline that carries Shopify webhooksUnited States (us-central1)
Google LLC (Vertex AI)Gemini model calls and text embeddings for the AI concierge and catalog searchUnited States
Vercel Inc.Hosting and delivery for copiara.com and the Copiara admin app embedded in the Shopify adminUnited States
ResendTransactional and notification email sent by the app and by this websiteUnited States
HubSpot, Inc.Customer relationship records for enquiries submitted on this websiteUnited States
Slack Technologies (Salesforce, Inc.)Internal notification to our team when an enquiry arrivesUnited States
Google LLC (Google Analytics 4)Aggregate traffic measurement on copiara.com only. Not used inside the appUnited States

Copiara does not use a payment processor. Subscriptions are billed by Shopify through Shopify’s app billing, so no card or bank details ever reach us, and buyer purchases settle at the merchant’s Shopify checkout rather than through us.

Merchants can ask to be notified in advance of a new sub-processor by writing to hello@copiara.com. We give notice before a new one starts processing customer data, and a merchant may object.

When we share information

  • With the sub-processors above, for the purposes listed.
  • Back to the merchant’s own Shopify store, which is where the data came from and where the order settles.
  • Within a merchant’s installation, according to the roles and permissions their administrators configure.
  • When the law requires it, in response to a valid legal demand. Where we are permitted to tell the affected merchant, we will.
  • In a corporate transaction, such as a merger or acquisition, in which case this policy continues to apply to the transferred data until it is replaced by a notice at least as protective.

International transfers

Copiara is operated from the United States and the production database and object storage are in Google Cloud’s us-central1 region. If you are outside the United States, using the app means your data is transferred there. For transfers from the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, incorporated through our data processing agreement and through our vendors’ terms.

Copiara runs in a single region today. That is a current residency boundary, not a global residency promise. A merchant that needs data held in another region should raise it before installing so it can be scoped properly.

How long we keep things

DataRetention
Website enquiry records (form submissions)While the conversation is active and for up to 24 months after the last contact, then deleted
Shopify connection data for a merchant's store (access tokens, the links to Shopify customers and products, queued work, and any parked data-request package)Deleted when we receive the shop/redact webhook, which Shopify sends about 48 hours after the app is uninstalled
A specific buyer's personal dataRedacted when we receive the customers/redact webhook for that person, within 30 days of the request
Audit log entriesMerchant configurable. 730 days by default, pruned automatically
AI concierge conversations and messagesMerchant configurable. 365 days by default, pruned automatically
Generated data exports30 days. Download links expire after 24 hours
A merchant's Copiara workspace and the commercial records created in it (quotes, approvals, credit records, cross-references, enrichment)Retained and flagged when a store is redacted, so reinstalling returns to the same workspace. Deleted on the merchant's request
Erased buyer and contact recordsIdentifying fields are replaced with a tombstone immediately. The record itself remains so audit and quote history still resolve

Deleting live data and expiring a backup are different things. Cloud SQL automated backups and point-in-time recovery hold historical copies for the configured window, so a record deleted in the app can persist in a recovery snapshot until that window rolls past.

Shopify privacy webhooks

Every app distributed through the Shopify App Store must implement three mandatory compliance webhooks, and Copiara does. They are how a privacy request reaches us from the platform.

  • customers/data_request. A buyer has asked the merchant for the data we hold about them. We assemble it and provide it to the merchant, who responds to their buyer. We complete this within 30 days.
  • customers/redact. A buyer has asked to be erased. We redact their personal data on the schedule in the retention table above, within 30 days.
  • shop/redact. Shopify sends this about 48 hours after a merchant uninstalls the app. We delete the Shopify connection data we hold for that store: the stored access tokens, the links between Shopify customers and Copiara buyer records, the links between Shopify products and Copiara catalog records, queued work for that shop, and any buyer data-request package still waiting to be collected. The store is marked uninstalled. The merchant’s Copiara workspace and the records the app created in it are retained and flagged rather than destroyed, because a workspace can predate a store, outlive it, and be reconnected by reinstalling. Deleting a workspace is a separate step, and a merchant can ask us for it.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, and be free from discrimination for exercising any of these. California residents may also ask what categories we collected, used, disclosed, and, if we did, sold or shared in the preceding twelve months. We do not sell or share personal data.

To exercise a right, write to hello@copiara.com. We respond within 30 days and will tell you if we need longer. We may need to verify your identity, and we will not ask for more information than the verification needs. You may use an authorized agent.

If your data sits inside a merchant’s Shopify store, send your request to that merchant. They can raise it with us through Shopify’s privacy webhooks or directly. We will not unilaterally change or delete their records, and we will help them respond.

If you are in the EEA or the UK you may also complain to your supervisory authority. We would rather hear from you first.

Export and deletion mechanics

  • Export. A merchant can ask us for a full export of the data Copiara holds for their store, at hello@copiara.com. A generated export is kept for 30 days, its download link expires after 24 hours, and the link can be reissued while the export file still exists.
  • Erasing a person. Erasing a buyer or contact replaces their name, email, and phone number with a tombstone and severs the link to their Shopify customer record. The record itself stays so that audit entries and quote history still resolve to something rather than breaking.
  • Uninstalling. Uninstalling the app from the Shopify admin ends our access immediately. Shopify sends shop/redact about 48 hours later, and we delete the Shopify connection data for that store. Your Shopify store keeps everything in it, and the records Copiara created for you stay in your Copiara workspace, retained and flagged, so reinstalling returns you to the same workspace. Ask us if you would rather have those records exported, deleted, or both.

Security

Our current security posture, including how one merchant’s data is separated from another’s, access controls, the audit trail, object storage handling, and what we do not claim, is written out on the security page. Security questionnaires are welcome before a contract.

Children

Copiara is a business product. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to us and we will delete it.

Changes to this policy

We update this policy as the app changes. The date at the top always reflects the current version. For a change that materially affects how we handle personal data, we notify merchant administrators by email before it takes effect.

Contact

Privacy questions, rights requests, a data processing agreement, or a sub-processor notification request all go to hello@copiara.com. Postal mail can be sent to Yikes Dude LLC, Texas, United States, and we will reply by email.