Order Intake

Privacy policy

Order Intake turns purchase orders your buyers email you into Shopify draft orders. Those emails contain other people's business details, so this page states exactly what we touch and — more importantly — what we deliberately do not keep.

What we read from your store

After you install the app we hold access tokens for your shop, encrypted at rest with AES-GCM. We use them to:

We never complete an order, charge a card, or change inventory. The app has no code path that does any of those things.

What happens to an order email

Mail sent to your intake address at cardiworkshop.com is read once, in memory, and then discarded. We do not store the original email or its attachments. What we keep is the order table we extracted from it:

Anything else in the document — addresses, contact names, contract terms, logos, other sheets — is never written to storage.

What we store about you

Who else sees it

We do not sell, rent or share your data with anyone else, we do not use it for advertising, and we do not use it to train models.

Retention and deletion

Extracted documents are deleted automatically 90 days after they arrive, and we keep at most the 200 most recent per shop. When you uninstall, Shopify sends an app/uninstalled webhook and we delete your tokens, settings and every stored document. You can also request deletion at any time at cardi.workshop@gmail.com.

We implement Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Shop redaction deletes everything listed above.

Contact

Questions about this policy, or about data we hold: cardi.workshop@gmail.com.

Last updated 2026-08-21 · Home · Support · Privacy