Pareto B2B QuotesRequest a quote for ShopifySupport
← Back

Privacy Policy — Pareto B2B Quotes

Last updated: 2026-08-19

1. Who we are

Pareto B2B Quotes ("the App", "we", "us") is a Shopify application that lets merchants receive and manage quote requests from their customers.

Data controller / operator: Nikola Posarac, France

Contact: nikola@pareto-labs.com

This policy explains what personal data the App processes, why, and the rights of the people concerned.

2. Our two roles

  • For merchant account data (the store owner who installs the App), we act as a data controller.
  • For the personal data of the merchant's own customers that flows through the App (quote requests), we act as a data processor on behalf of the merchant. The merchant is the controller of that data. See our Terms of Service & Data Processing Agreement.

3. What data we process

From the merchant (via Shopify): store name, store domain, contact email, and the Shopify access token needed to operate the App.

From the merchant's customers (via quote requests): name, email address, phone number (optional), company name (optional), shipping address, and the products / cart details attached to the request.

We process the minimum data required to deliver the quote functionality. We do not sell personal data and do not use it for advertising.

4. Why we process it (purpose & legal basis)

PurposeLegal basis (GDPR Art. 6)
Deliver quote requests to the merchantPerformance of a contract / legitimate interest
Notify merchant and customer by emailPerformance of a contract
Create draft orders in the merchant's storeLegitimate interest of the merchant
Prevent spam and abuseLegitimate interest
Understand how merchants use the App (product analytics)Legitimate interest

We use personal data only for these purposes.

5. Sub-processors

We share data only with the infrastructure providers required to run the App:

Sub-processorPurposeData location
ShopifyPlatform, store data, draft ordersGlobal
RenderApplication hostingUnited States
NeonManaged PostgreSQL databaseUnited States
ResendTransactional email deliveryUnited States
PostHogProduct analytics (merchant usage of the App)United States

Each provider is bound by its own data-protection commitments. We will inform merchants of any intended change to this list.

PostHog receives no personal data of store customers. The only identifier sent is the merchant's store domain (e.g. example.myshopify.com), together with technical counters and store attributes (page opened, number of quote lines, quote totals and their currency, Shopify plan, country, store currency, whether a notification email is configured). Names, email addresses, phone numbers, postal addresses, messages and attachments are never transmitted, and no analytics code runs in the merchant's admin or in the storefront — events are sent from our server only.

6. Data retention

Quote request data is retained for 24 months after the last activity, then deleted automatically. Data is also deleted on request and when a merchant uninstalls the App. See our Data Retention Policy.

7. Security

Personal data is encrypted at rest and in transit (TLS). Database backups are encrypted. Access to production data is restricted, and we maintain an Incident Response Policy.

8. Data subject rights

Individuals may request access, correction, deletion, restriction, or portability of their data, and may object to processing. Requests concerning a merchant's customers should normally be addressed to that merchant; we support them via Shopify's mandatory customers/data_request and customers/redact webhooks and by acting on the merchant's instructions.

To exercise a right directly, contact nikola@pareto-labs.com.

9. International transfers

Data may be processed in the United States. Where required, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) provided by our sub-processors.

10. Cookies

The App uses only functional cookies/sessions required to operate (e.g. keeping a merchant logged in). It does not use tracking or advertising cookies. Product analytics (section 5) is collected server-side and sets no cookie or browser storage on any visitor's device.

11. Changes

We may update this policy. Material changes will be communicated to merchants.

12. Contact

Questions or requests: nikola@pareto-labs.com