Legal
Privacy policy
What Purser and Purser Downloads collect, why, where it is stored, how long it is kept, and how to get it deleted.
Last updated 18 July 2026
This policy explains what Purser ("we", "us") does with data when you install one of our apps into your Shopify store. We publish two: Purser, the purchase-order and accounts-payable app, and Purser Downloads, which delivers digital files to your customers after a paid order. Most of this page describes Purser; because Purser Downloads is the app that handles your customers' personal data, it has a section of its own further down. This policy is written to be read, not to be survived. If anything here is unclear, email support@gopurser.com and we will explain it in plainer words and then fix the wording.
What we collect through Shopify's APIs
- Shop details: your myshopify.com domain, shop name, currency, and the locations you hold stock at.
- Products and variants: titles, SKUs, barcodes, unit cost and price.
- Inventory levels: how much of each variant is on hand, per location.
- Your app subscription status, so we know which plan you are on.
We request no access to your orders, your customers, your marketing data, your themes or your storefront, and we cannot read them.
What we collect directly from you
- Suppliers you create: business name, and optionally a contact name, email address, phone number, lead time and payment terms.
- Purchase orders, receipts, bills, payments, credit notes and the costs you enter against them.
- Any CSV file you upload to the importer, and its contents.
- Anything you write to us in a support email.
A supplier contact is personal data about a real person at your supplier. We hold it only so we can put it on a purchase order and, if you ask us to, email that purchase order to them. We never contact your suppliers for our own purposes.
What we collect from your customers
Purser, the purchase-order and accounts-payable app, collects nothing about your customers. It has no access to your customer records, your orders or your storefront, and it holds no personal data about the people who shop with you. Purser Downloads is different: to deliver a file after a sale it receives the buyer's name and email address from the order. That is set out in full in the Purser Downloads section below. We answer this question explicitly because Shopify requires us to.
How we use it
- To run the app you installed: build purchase orders, receive stock, calculate weighted-average cost, and track what you owe.
- To write inventory quantities, unit cost and retail price back to Shopify when you receive stock. That is the whole point of the app.
- To email a purchase order to a supplier, when you ask it to.
- To answer your support emails.
- To keep the app working: error logs, which may incidentally contain a shop domain or an order number.
We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models. We do not build a profile of your business to sell to anybody, including your competitors.
Where it is stored, and who else touches it
Purser is operated from the United States, and your data is stored and processed there. We are not established in Europe. If you are in the UK or the European Economic Area, installing Purser means your data is transferred to and processed in the United States.
We use three subprocessors, and only three:
- Shopify: the platform the app runs inside, and the source of the product and inventory data. Shopify also handles all billing.
- Fly.io: hosts the application and its PostgreSQL database, in their Ashburn, Virginia region in the United States.
- Resend: sends purchase-order emails to the suppliers you choose to email. They receive the supplier's email address and the purchase order itself.
When Purser emails a purchase order, it is sent from our domain but the reply-to address is yours, so your supplier's reply reaches you and not us. We do not read or store your correspondence with your suppliers.
Payment information
Purser never sees a card number. Your subscription is charged by Shopify and appears on your Shopify invoice. We are told only which plan you are on, and whether the subscription is active.
How long we keep it
For as long as the app is installed. Your ledger is the reason you installed a ledger, and we are not going to quietly expire it.
When you uninstall Purser, Shopify notifies us and we delete your shop's data. We also honour Shopify's mandatory data-deletion requests. If you want your data deleted sooner, or want written confirmation that it is gone, email us and ask.
Your rights
Depending on where you are, you may have the right to access the personal data we hold, to have it corrected, to have it erased, and to object to or restrict how we process it. Purser implements Shopify's three mandatory compliance webhooks, so a data request or deletion request made through Shopify reaches us and is acted on rather than merely acknowledged.
You can also just email us at support@gopurser.com. That is not a worse route than the formal one; it is usually a faster one.
Purser Downloads (digital delivery)
Everything below applies to Purser Downloads specifically. Where it differs from Purser, the app above, it is because Purser Downloads works with your orders and your customers and Purser does not.
What Purser Downloads collects through Shopify's APIs
- Shop details: your myshopify.com domain, shop name and currency.
- Products and variants: titles and SKUs, so it can attach the right file to the right product.
- Paid orders: the order and its line items, and the buyer's name and email address, so it knows what to deliver and where to send it.
- Your app subscription status, so we know which plan you are on.
What Purser Downloads collects directly from you
- The digital files you upload for delivery, and their filenames.
- Your delivery-email settings: the from-name, and the reply-to name and address you choose.
- Anything you write to us in a support email.
What Purser Downloads collects from your customers
Two things, both tied to an order the customer placed with you. First, their name and email address, taken from the Shopify order, used to send them their download and to address it to them. Second, delivery activity: when the email was delivered, opened or clicked, and when a file was downloaded. That activity is what the per-order delivery ledger is made of, and it is how you can see that a delivery failed and re-send it.
Purser Downloads never sees a card number, sets no advertising cookies on your customers, and builds no profile of them. A customer does not create an account with us; the download links we email are signed and expire on their own.
How Purser Downloads uses it
- To deliver the purchased files: by email, on the order's thank-you page, and in the customer's Shopify account.
- To keep the per-order delivery ledger, so you can see what reached each customer and recover the ones that did not.
- To re-send a delivery, automatically or when you click resend.
- To keep the app working: error logs, which may incidentally contain a shop domain or an order number.
We do not sell this data, share it with advertisers, or use it to train machine-learning models.
Where Purser Downloads stores it, and who else touches it
Purser Downloads is operated from the United States, and your data is stored and processed there. We are not established in Europe. If you are in the UK or the European Economic Area, installing it means your data is transferred to and processed in the United States.
Purser Downloads uses these subprocessors:
- Shopify: the platform the app runs inside, the source of the order and product data, and the handler of all billing.
- Fly.io: hosts the application, in their Ashburn, Virginia region in the United States.
- Neon: hosts the PostgreSQL database that holds the delivery ledger, in the United States.
- Cloudflare R2: stores the digital files you upload, which are served to your customers over signed, expiring links.
- Resend: sends the delivery emails. It receives the customer's email address and the download email itself.
How long Purser Downloads keeps it, and how to delete it
For as long as the app is installed. When you uninstall it, Shopify notifies us and we delete the shop's data, including the files stored in Cloudflare R2.
Purser Downloads implements Shopify's three mandatory compliance webhooks. A customer-redaction request erases that customer's name and email from the order, leaving the delivery record without personal data; a shop-redaction request removes the shop entirely. Download links are signed and expire, so a link that leaks stops working on its own. If you want data deleted sooner, or written confirmation that it is gone, email support@gopurser.com.
Cookies and tracking on this website
This marketing website sets no advertising cookies and runs no third-party trackers. The app itself sets only the session cookie Shopify requires to keep you logged in. If we ever add analytics or advertising tags, this section will be updated before they go live, not after.
Changes to this policy
If we change how we handle your data in any way that matters, we will update this page and the date at the top of it. If the change is significant, we will email the shop's contact address rather than hoping you re-read a web page.
Contact
Email support@gopurser.com. A person reads it.
