Your information
Privacy, in plain language.
How Tradefold handles the information behind your wholesale orders.
What we receive
Tradefold is operated by The Dot Dev. Merchants use it to review wholesale purchase orders and prepare Shopify drafts. The merchant decides which orders and buyer information to provide.
- Shopify information: store identifiers, authenticated session information, product variants, SKUs, prices, and app subscription status. Shopify session credentials are stored on the server to maintain the connection.
- Order information: uploaded or pasted purchase orders, emails sent to the assigned order inbox, attachments, sender details, buyer names and contact information, customer references, order lines, quantities, prices, notes, and matching rules.
- Operational records: processing status, errors, review activity, draft identifiers, usage counters, privacy requests, and hosting logs. Support correspondence contains information you choose to send us.
Tradefold does not install a storefront visitor-tracking pixel. It does not collect customer payment-card details. Shopify handles app subscription billing.
Why we use it
We use this information to import and extract order details, match products, display source documents for review, maintain buyer rules, prepare merchant-approved drafts, run the service, prevent misuse, and answer support and privacy requests.
AI-extracted details can be wrong and require merchant review. Extraction does not by itself place an order, send an invoice, collect payment, or fulfill goods. We do not sell order data or use it for targeted advertising.
Who processes information
- Shopify provides installation, authentication, catalog and draft-order APIs, and app billing.
- OpenAI processes the document text or PDF supplied for AI extraction. Tradefold sends extraction requests with response storage disabled. This does not mean zero retention: OpenAI may retain abuse-monitoring data, normally for up to 30 days, with exceptions described in its API data controls.
- Resend receives emails and attachments sent to the order inbox. Provider copies are separate from Tradefold's imported records. See Resend's privacy policy.
- Hostinger hosts the application, database, and operational backups. See Hostinger's privacy policy.
These services may process data outside your country. Tradefold does not currently offer a guaranteed country-specific storage region. Requests concerning provider-held copies require separate review; deleting an app record does not itself delete those copies.
Retention and deletion
Order documents, extracted details, buyer rules, and audit records remain in the workspace to support order review and history until removed through a reviewed deletion request. The development release does not automatically expire those workspace records.
Tradefold's scheduled database-backup script uses a 14-day retention window. Manual recovery exports, hosting-provider backups, provider email copies, and operational logs have separate retention; their final production retention schedule is still being verified. We do not claim that all copies disappear immediately after deletion or uninstall.
Shopify privacy requests are recorded with a 30-day operational deadline. Receipt of a request is not confirmation that access or deletion has been completed. Any required retained records or unresolved provider actions must be reviewed before fulfillment is recorded.
How access is controlled
Merchants sign in through Shopify. Application access is scoped to the authenticated store. Incoming provider webhooks are signature-checked, and operator review exports are written to private files outside the application directory. Operational access is limited to running and supporting the service.
Access, correction, or deletion
If you are a buyer, contact the merchant that received your order first so your identity and request can be verified. Merchants can contact hello@thedotdev.com about information held by Tradefold. Depending on your location, you may have rights to access, correct, erase, or restrict processing of your information and to complain to a relevant privacy authority.
Include your store domain and the type of request. Do not email passwords, API keys, payment-card details, or full customer documents in the initial message. We will arrange an appropriate way to verify the request and handle any necessary information.
Updates and contact
We will update this notice as the service and verified data-handling practices change. The date above identifies this version.
Tradefold · The Dot Dev
hello@thedotdev.com
