Privacy policy
Last updated September 19, 2026
1. Who this policy covers
DraftFlow is operated by CLYDE. For support or legal inquiries, contact support@draftflows.com.
This policy covers merchants using DraftFlow, their authorized users, people whose information appears in submitted purchase orders, and visitors to the DraftFlow website. For buyer data submitted by a merchant, the merchant determines the purposes of order processing, while DraftFlow processes that data to provide the requested service.
2. Information involved in the workflow
Depending on what you submit and the app permissions enabled, the service workflow can involve:
- Store and account details, such as store identifiers and authorized contact information.
- Forwarded emails and PO attachments, including buyer names, email addresses, shipping or billing details, PO references, products, quantities, and prices.
- Catalog data, including product descriptions, SKUs, variants, and pricing needed for matching.
- Extracted order details, product mappings, review decisions, processing status, and Shopify draft-order references.
- Subscription and usage records needed to calculate charges, together with support correspondence and technical diagnostic information.
Only forward information appropriate for purchase-order processing. Do not include payment-card details, passwords, or unrelated sensitive personal information.
3. Why information is processed
We process information to receive and extract POs, match products to the connected catalog, show exceptions for merchant review, create Shopify draft orders, measure billable usage, maintain purchased credit entitlements, provide support, and maintain the service.
4. Automated processing
DraftFlow uses the Google Gemini API paid tier for automated document extraction and product matching. Purchase-order content is transmitted over HTTPS for processing. Under Google’s paid-service terms, submitted prompts, files, and responses are not used to improve its products or train its models. Google may log prompts and responses for a limited period for safety, security, and legal purposes, as described in those terms. Merchants should check extracted details and product matches before syncing or acting on an order.
5. Information sharing
Reviewed order information is sent to the merchant’s connected Shopify store. Purchase-order content is sent to Google Gemini for extraction and product matching. Providers supporting email intake, hosting, monitoring, and support may process information needed to operate the service. We may also disclose information if legally required.
6. Retention and deletion
We minimize the information we keep. Emailed PO files, such as PDFs and images, are processed in memory for the order workflow and deleted from our active processing system immediately after successful creation of the Shopify draft order. We do not permanently store raw email messages or attachments. During exception review or unsuccessful processing, PO content may remain available only as needed to complete or troubleshoot the processing workflow.
We retain limited records needed for billing and merchant support, such as the Shopify draft-order ID, PO processing timestamp, and line-item count. Purchased add-on credit balances may be retained separately as billing entitlements so they can be restored after a verified reinstall.
When Shopify sends a shop/redact privacy webhook after uninstall, we delete associated store and order-processing metadata, subject to information we must retain for applicable legal or billing obligations. We also respond to Shopify’s customers/data_request and customers/redact privacy webhooks as applicable. Data retained by our service providers is subject to their own retention terms; Google may keep limited safety logs as described in Section 4.
7. Your choices and requests
Merchants can choose what to forward and manage the app’s installation through Shopify. To ask about access, correction, export, or deletion, contact support@draftflows.com. Verification may be needed before responding.
If your information appears in a merchant’s PO, contacting that merchant can help route the request. Depending on applicable law, additional privacy rights may apply, including the right to complain to a relevant data-protection authority. We process personal data in accordance with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) where applicable.
8. Security and international processing
We use HTTPS when transmitting purchase-order content to Google Gemini. Our hosting and processing providers may handle information in different countries, according to their service terms and applicable law. Contact us to ask about our safeguards or data-processing arrangements.
9. This website
This version of the landing page does not include advertising pixels, analytics scripts, or a data-collection form. It loads typography from Google Fonts, which involves requests to that provider. Hosting infrastructure may process technical request information. Contact buttons open your email application; information you send is then part of your support correspondence.
The interactive PO example uses fictional data in your browser. It does not process a real PO or connect to a Shopify account.
10. Changes and contact
We may update this policy as our practices change. We will update the date above and communicate material changes where required. For privacy questions, contact support@draftflows.com.
