Privacy Policy
This Privacy Policy explains how Satisfy & I B.V. ("we", "us") processes data in NORTHMAST (the "app"), an embedded Shopify application that turns a merchant's revenue, cost of goods, advertising cost and operating cost data into a single profit view, and that keeps the inventory, purchasing and stock count administration behind it.
It distinguishes throughout between things that are genuinely different: order data relating to a merchant's customers, account data relating to the merchant and their staff, and the supplier and operational records a merchant builds up in the app. The app treats them differently, and this policy describes each separately.
NORTHMAST was formerly developed under the working name Clearboard Analytics. It is the same application, provided by the same legal entity, and this document replaces the corresponding document published under that working name.
Who we are
Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@northmast.app.
We are the provider of the app and the party you contract with. Questions about this policy, and requests relating to your personal data, can be sent to info@northmast.app.
Our roles
Which data protection role we hold depends on the data, and the difference matters for who you should address a request to.
- Processor — for order data relating to the merchant's customers, for the supplier records the merchant enters, and for the contents of any file the merchant uploads as a stock count attachment. The merchant decides why and how that data is processed; we process it only to provide the app to that merchant. Satisfy & I B.V. acts solely as processor here, under the Data Processing Addendum.
- Independent controller — for merchant and staff account data, including the business details a merchant records for use on their own documents, as well as requests submitted through our website, support correspondence, security records, and our own legal and administrative records. We decide the purposes of that processing ourselves, and this Privacy Policy describes it.
Order data relating to your customers
To calculate profit, the app stores financial order data retrieved from Shopify's Admin API. Specifically:
- Orders — the Shopify order identifier, creation date, processing date, cancellation date, test flag, financial status, currency, order totals, discounts, taxes, shipping revenue and the destination country code of the order.
- Order line items — the Shopify line item identifier, variant identifier, SKU, quantity, price, tax amounts and a cost price snapshot.
- Refunds — the Shopify refund identifier, processing date and currency.
- Refund line items — the refunded quantity, subtotal and tax per line.
- Refund transactions — the amount, currency, kind, status, dates and test flag of each refund transaction.
- Refund duties, order adjustments and refund shipping lines belonging to those refunds.
- Shipping method — the delivery option chosen at checkout: its name, and where Shopify provides them its code, its source and a carrier identifier. This describes the service that was chosen, not where the parcel went.
- Payment and refund transactions — per transaction on the order: the payment gateway that processed it, the transaction type and status, whether it was a test transaction, the amount and currency, the amount as charged to the customer where that currency differs, the transaction dates, and a reference to the related transaction where Shopify provides one.
- Transaction fees — only where Shopify makes fee information available for a transaction: the fee amount and currency, the fee type, the percentage rate and any fixed component, and tax charged on the fee. Shopify does not provide this for every payment provider, and where it is absent we have no fee data.
Why we process shipping and payment metadata
We use the shipping and payment metadata described above to calculate and explain your order economics — which costs belong to which order, and what remains as profit — and to support the shipping-cost and transaction-cost settings you configure yourself. It is not used for customer profiling, advertising, personalisation, segmentation or any form of scoring.
NORTHMAST never receives or stores payment credentials. We do not request card numbers — not even masked or truncated ones — card security codes, cardholder names, bank account or bank login details, payment account passwords, or any other payment authentication secret. What we process is transaction economics: which gateway processed a payment, what type and status the transaction had, how much it was and in which currency. That is not the payment instrument itself. We also do not process payout, settlement or bank reconciliation data, and we hold no payout history.
What we do not process about your customers
NORTHMAST does not request and does not store the customer name, customer e-mail address, customer telephone number, street address and house number, address line 2, postal or ZIP code, city, geolocation coordinates of your customers. None of these fields are queried from Shopify, none are stored in our database, and none appear in any export the app generates. We request no billing address at all.
From an order's shipping address we request exactly one field: the destination country code, a two-letter country code such as NL, BE or US. NORTHMAST may process and store that country code together with the order, to support the merchant's financial calculations — in particular the merchant-configured shipping-cost rules that can differ per destination country. Detailed shipping-address information such as street, house number, postal code, city or geolocation is not required for that calculation and is not requested. The country code is never used for profiling, marketing, personalisation or advertising, and is not shown per individual customer. It is stored on the order record and follows that record's lifecycle: it is deleted with the order, including when Shopify sends a customers/redact or shop/redact request.
There is one further narrow exception, and it exists only because Shopify requires it. When Shopify sends a customers/data_request or customers/redact webhook, that webhook carries a numeric Shopify customer identifier and a list of order identifiers. We store those identifiers on the resulting privacy request record so that the request can be answered and audited. They are pseudonymous identifiers, not contact details, and they are subject to the retention limits described below.
Special categories of personal data
The app is not designed for, and is not intended to process, special categories of personal data within the meaning of Article 9 GDPR — such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data concerning a person's sex life or sexual orientation. The app queries no field of that kind. Merchants must not knowingly supply such data to the app, including through free-text configuration fields, without a separate written agreement with us first.
Merchant and staff account data
Separately from order data, the app stores the Shopify session records that make the embedded app work. Shopify supplies these; they can include the store domain, a Shopify user identifier, first name, last name, e-mail address, locale, and flags indicating whether the user is the account owner, a collaborator, or has a verified e-mail address, together with the access token and refresh token for the store.
This is merchant and staff data, not customer data. It is used to authenticate the app against Shopify and to run synchronisations on the store's behalf.
Paid access and subscription status
NORTHMAST is a paid app, billed through Shopify. To decide whether your store may open the app, we ask Shopify whether a subscription for NORTHMAST is currently active for your store, using the identifier Shopify uses for it. We store no plan, no price, no invoice and no payment data of any kind, and we receive none: the whole billing relationship runs between you and Shopify.
Your business, supplier and operational records
Beyond the Shopify data above, the app holds the administration you build up in it yourself: what you buy, from whom, at what cost, and what you have in stock. This is your own business data. We process it to provide the app to you and for no other purpose.
You can record your own business details for use on the documents the app produces: your business name, a contact e-mail address, a telephone number and a business address. You enter these yourself, and they appear on the purchase orders and other documents you generate.
You can record the suppliers you buy from. A supplier record holds the company name and your own reference code for it, and optionally the name of a contact person, an e-mail address, a telephone number, an address and your own notes. Where you fill those fields in, they are personal data about that contact person — someone who is neither our customer nor yours — and you decide what to enter. We do not obtain supplier details from any other source, do not enrich or verify them, and do not use them for anything except showing them to you and placing them on the purchase documents you generate. A supplier's details are deleted with the supplier, and with your store when Shopify sends a shop/redact request.
The remaining records are business data rather than personal data, but they are listed here so that you can see everything the app keeps for your store in one place:
- Products and variants read from your Shopify store — identifiers, titles, SKUs, barcodes, options and the status Shopify reports, together with the collections a variant belongs to.
- Cost prices and their history — the cost per item you enter or import, with the date each cost took effect, so that an order from three months ago can be valued at the cost that applied then.
- Inventory quantities per Shopify location, and the locations themselves as Shopify reports them.
- Warehouses you define yourself, including their address, and which of them is your default.
- Supplier records, and the purchasing conditions you set per supplier and product — lead time, minimum order quantity, order multiple, purchase price and currency.
- Purchase orders with their lines, notes, documents and full change history, from draft through ordered to received or cancelled.
- Receipts and supplier returns, including corrections and reversals, and the stock movements they produce.
- Stock counts: the count itself, its description and status, the counted quantities per variant and location, and any file you attach to it.
- Operating costs you record yourself, such as rent, software or salaries, with their amount, currency, period and category.
Files you attach to a stock count
A file you attach to a stock count is your own document, and we do not know what is in it. A scan or photograph of a counted sheet may contain personal data — the name or the handwriting of whoever counted, for example — because you chose to upload it. The app stores the file and shows it back to you; it does not open, read, index, analyse or extract anything from the contents, and nothing in the file is used in any calculation.
Merchant configuration and advertising data
You can connect your own advertising accounts to the app. Two platforms are supported: Meta Ads and Google Ads. Each connection is optional and separate, and what we read and store differs per platform, so they are listed separately below.
- Configuration you enter in the app, such as transaction fee settings, named shipping rates and language preference.
- Files you upload yourself. A stock count can carry one attachment — a PDF, JPEG or PNG of at most 5 MB, typically a scan or photograph of a counted sheet. We store the file itself, the name you gave it, its file type and its size. The file is held in private storage: it is never publicly reachable, and it can only be opened through a short-lived link that the app issues to you after checking that the count belongs to your store. We do not read, index or analyse the contents.
- Meta Ads cost data, if you connect Meta: campaign, ad set and ad names and identifiers, date, spend, currency, impressions, clicks and click-through rate.
- Google Ads cost data, if you connect Google Ads: the calendar date in the advertising account's own time zone, the campaign identifier, the campaign name, the cost, the currency, impressions and clicks. The reporting query also returns the campaign status; it is not stored and is discarded together with the rest of the response. We store no ad group, ad, keyword, search term, audience, conversion or click-through-rate data from Google Ads, and no data about the people who saw or clicked your advertisements.
- The Meta connection details: the ad account identifier and name, the account currency, the Meta user identifier of the person who made the connection, the granted permissions, and the access token, which is stored encrypted (AES-256-GCM) and never in plain text.
- The Google Ads connection details: the Google Ads customer identifier of the account you selected, the customer identifier of the manager account through which it is reached where that applies, the account name, currency and time zone, the granted scope, and the access token and refresh token, which are stored encrypted (AES-256-GCM) and never in plain text.
Technical infrastructure data
The app itself does not store IP addresses, device identifiers or browsing behaviour. It contains no cookies for analytics, no tracking pixel and no third-party analytics script, and it does not build a profile of you or of your customers.
Our hosting and database providers do, however, necessarily process connection metadata — such as the IP address a request comes from, timestamps, the requested path and error information — in their own infrastructure logs, because a request cannot be delivered or a database connection established without it. That processing takes place under those providers' own terms and retention periods, which we do not control. We use it only where it reaches us as part of diagnosing an operational fault.
The app writes its own synchronisation logs, described under retention below. Those record which sync ran and whether it succeeded, and are deliberately constructed to carry fixed, safe codes rather than tokens, payloads or personal data.
Requests submitted through our website
Our public website carries a form for merchants who want to hear from us before NORTHMAST is available to install, and we are the controller for what is submitted there. This is separate from everything else in this policy: it concerns people who are not yet using the app, and no Shopify data is involved.
We use it to read and answer the request, to judge whether the product fits the store as it works today, and to contact the sender about getting access. We do not use it for newsletters or any other marketing, and we do not share or sell it.
The legal basis is the taking of steps at the sender's request before entering into a contract. Where a request does not lead to a contract, our basis for keeping the record for the limited period below is our legitimate interest in knowing which stores approached us and what we answered.
A request is delivered to us as e-mail and is not stored in the app's database. We keep it for a maximum of 12 months after submission, unless the sender becomes a customer, or ongoing correspondence or a legal obligation means a different retention period applies to that specific record. A sender can ask us to delete their request earlier at info@northmast.app.
To deliver that e-mail we use Resend, a transactional e-mail provider, which processes the fields the application contains for the purpose of sending that one message to us. Our account with them is configured to use their European (Ireland) region. We do not claim that all processing by this provider takes place exclusively within the EEA. This provider is used only for website application e-mail; it receives no Shopify order data, no data about a merchant's customers, and nothing else the app processes.
- First and last name.
- Work e-mail address.
- The website or store domain of the store the application concerns.
- Monthly order volume, as a range rather than an exact figure.
- An optional message describing what the applicant would like help with.
Why we process this data
- To provide analytics and revenue reporting.
- To read and reply to a request submitted through our website.
- To calculate profit, contribution margin and cost of goods sold.
- To calculate advertising cost and return on ad spend alongside Shopify data.
- To keep your inventory, purchasing and stock count administration, and to work out what to reorder.
- To determine whether your store's paid access to the app is currently active.
- To secure the service, including authenticating requests and verifying webhooks.
- To provide support when you contact us, and to meet our legal obligations.
Legal bases for the processing we control
This section concerns only the processing for which we are an independent controller — merchant and staff account data, requests submitted through our website, support, security and administration. For customer order data, supplier records and attachment contents we act as processor, and the merchant is responsible for establishing the legal basis.
- Performance of a contract, including steps taken at your request before entering into one — to give you access to the app, authenticate your store against Shopify, establish whether your paid access is active, run synchronisations on your behalf, answer your support requests, and read and reply to a request submitted through our website. Without this processing we cannot provide the service you installed.
- Compliance with a legal obligation — to meet our obligations under tax, accounting and data protection law, including responding to a supervisory authority.
- Legitimate interests — to keep the service secure and operable, to detect and resolve faults, to prevent misuse and unauthorised access to another merchant's data, and to keep records of what happened when something goes wrong. We have weighed these interests against your rights and limited the processing to what the service actually requires.
What we never do
- We do not sell personal data.
- We do not use your data, or your customers' data, for personalised advertising.
- We do not carry out automated decision-making that produces legal effects or similarly significant effects on any individual.
- We do not use your data for purposes unrelated to providing the service.
How long we keep data
Detailed order data — orders, order line items, refunds, refund line items and refund transactions, together with the related refund duties, order adjustments, refund shipping lines, shipping method metadata, payment and refund transaction metadata and any Shopify-provided transaction fee information — is retained for a maximum of 24 calendar months, measured from the date the order was placed — the commercial order date Shopify records for the sale, not the date the order was imported into Shopify and not the date it was shipped. Records past that limit are deleted automatically by a daily retention job, and orders older than the limit can no longer be imported or re-created.
Advertising cost records (ad spend) and the related synchronisation provenance — which days were fetched for which advertising account, and which account was the reporting source in which period — are retained for a maximum of 24 calendar months, the same reporting horizon as detailed order data. Records past that limit are deleted or truncated automatically by the same daily retention job. Disconnecting an advertising platform stops future synchronisation but does not delete this history early; a shop/redact request always deletes it in full.
Synchronisation logs, which record when a sync ran and whether it succeeded, are retained for a maximum of 90 days.
Completed customers/data_request records, including the generated export payload, are retained for a maximum of 30 days after completion and are then deleted in full.
Files you upload as a stock count attachment carry no separate time limit: they are business records of your own, and they are kept for as long as the stock count they belong to. They are removed from private storage when you remove or replace the attachment, when you delete the draft count it belongs to, and when Shopify sends a shop/redact request for your store.
Merchant settings and shipping rates are kept for as long as the app is installed for your store, because the app needs them to calculate profit. They are deleted on shop/redact.
Your business details, supplier records and operational records — products, cost prices and their history, inventory quantities, locations, warehouses, purchase orders, receipts, supplier returns, stock counts and operating costs — carry no separate time limit. They are your own administration, and the app keeps them for as long as it is installed for your store, or until you delete the record yourself. They are deleted in full when Shopify sends a shop/redact request.
A request submitted through the form on our website is kept for a maximum of 12 months after it was submitted, unless the sender becomes a customer or another retention period applies as described in the section on those requests.
Deletion requests from Shopify
When Shopify sends a customers/redact request, the affected order data is deleted immediately and a minimal technical marker is kept for as long as the app remains installed for that store. That marker exists for one purpose only: to stop a later synchronisation from re-importing the deleted order. It contains the store key, a fixed topic, the order identifier and a status — no name, e-mail address, telephone number, address, customer identifier, amount or payload fragment.
When Shopify sends a shop/redact request, all stored data for that store is deleted, including orders, line items, refunds and refund components, ad spend, products and variants, cost prices and their history, inventory quantities and locations, warehouses, suppliers and their contact details, purchase orders, receipts, supplier returns, stock counts, recorded operating costs, your own business details, settings, shipping rates, synchronisation logs, privacy request records and any advertising platform connection. Files you uploaded — the attachments on your stock counts — are removed from private storage in the same request, and not only from our records of them.
When the app is uninstalled, the Shopify session records for that store — which hold the staff account details and access tokens — are deleted immediately. The remaining store data is kept only until Shopify's shop/redact request arrives, so that Shopify's mandatory compliance flow can be completed correctly, and is deleted at that point.
Shopify
Shopify is the platform the app runs on and the source of the order data described above. Shopify is not a subprocessor engaged by us: the merchant has their own direct relationship with Shopify, and Shopify determines its own processing under its own terms. We access store data through Shopify's official Admin API using the permissions the merchant granted at install.
Advertising platforms
A merchant may voluntarily connect their own Meta Ads account, their own Google Ads account, both, or neither. Every connection is started by the merchant through that platform's own official OAuth authorisation screen and never by us; it covers only accounts the merchant already has access to; and the app works without any advertising connection at all.
For Meta, the app reads advertising cost and performance data for the selected ad account using the read-only ads_read permission.
For Google Ads, the app requests a single scope, https://www.googleapis.com/auth/adwords. That is the only scope the Google Ads API offers, and it is not itself limited to reading, so what matters is what we actually do with it: we use it exclusively for read-only reporting. The app makes only search (reporting) requests — one to list the advertising accounts you can select, and one to retrieve daily cost, impressions and clicks per campaign for the account you selected. The account listing returns, for each account you already have access to, its customer identifier, name, currency, time zone, status and whether it is a manager or a test account; we keep only the details of the one account you then select, as listed above, and discard the rest. It issues no write request of any kind, and therefore does not create, change, pause or delete campaigns, advertisements, ad groups, budgets, bids, keywords, audiences, conversions or account settings.
No Shopify order data and no data about your customers is ever sent to Meta or to Google. The only thing the app sends to Google Ads is the reporting query itself, which contains an account identifier and a date range and nothing else.
A merchant can disconnect either platform at any time from the app's settings, and disconnecting one platform never touches the other. Disconnecting Google Ads asks Google to revoke the token, and then deletes the stored access and refresh tokens, the selected account details, any pending authorisation state and all Google Ads cost data imported for that store. Disconnecting Meta likewise deletes the stored token and account details, any pending authorisation state and all Meta cost data imported for that store. In both cases this ends all further access, and disconnected advertising data never keeps counting as current. Uninstalling the app, and the shop/redact request that follows it, deletes every advertising platform connection and all imported advertising cost data for the store, as described above.
An advertising platform connected this way is not a subprocessor engaged by us either. We read data from it on the merchant's instruction; we do not send it data to process on our behalf.
Subprocessors
A subprocessor is a provider we engage to process data on our behalf. This is a different category from Shopify, which the merchant has their own relationship with, and from an advertising platform the merchant chooses to connect. We engage the following providers:
- Vercel — Application hosting and the serverless runtime that executes the app, including the daily scheduled job. Data categories: All data processed in transit by the application: Shopify order and refund data, advertising cost data, merchant configuration, and Shopify session data. Processing context: Serverless execution and hosting infrastructure operated by Vercel, processing the application traffic and the data required to serve a request. We have not established that execution is limited to a single region.
- Supabase — Managed PostgreSQL database where all application data is stored, and the private object storage that holds the files merchants attach to a stock count. Data categories: Orders, order line items, refunds and refund components, order shipping method and payment transaction metadata, advertising cost records, product and variant data, cost prices and cost history, inventory quantities and locations, warehouses, supplier records including any supplier contact details the merchant enters, purchase orders, receipts, supplier returns, stock counts, operating cost records, merchant settings and shipping rates, synchronisation logs, privacy request records, Shopify session records, encrypted advertising platform tokens, and the stock count attachment files themselves. Processing context: The primary database is hosted in a European Supabase project region. Supabase may carry out supporting processing, such as operations and support, outside that region; we do not claim that all Supabase processing takes place exclusively within the EEA. Contract: We have concluded a Data Processing Addendum with Supabase. Transfers: That Data Processing Addendum incorporates the EU Standard Contractual Clauses where these are required for a transfer.
Security
We apply technical and organisational measures appropriate to the data we process. In practice this includes: every database read and write is scoped to a single store, so one merchant's data cannot be reached from another's context; advertising platform tokens are encrypted at rest with AES-256-GCM and are never logged; incoming Shopify webhooks are verified by HMAC before any action is taken; OAuth state values are stored hashed and can be used only once; and logs and error messages are constructed to carry fixed, safe codes rather than tokens, payloads or personal data.
We hold no security certifications, and we make no absolute guarantee. No method of transmission or storage is completely secure.
Your rights
Depending on where you are located, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to it. Where we act as a processor on a merchant's behalf — which is the case for all customer order data — requests from a customer should be directed to the merchant, and we will assist the merchant in answering them. To exercise rights in relation to data for which we are the controller, such as merchant account and support data, contact us using the details below.
To make a request, e-mail info@northmast.app and describe what you want. We may need to ask you for information to confirm who you are, so that we do not disclose or delete data on the basis of a request from someone else. We answer without undue delay and in any event within the period applicable data protection law allows. Exercising these rights is free of charge.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with your local supervisory authority. For us that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Contact
Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@northmast.app.
Changes to this policy
Each document carries its own version number and effective date. A material change results in a new version number and a new effective date shown at the top of the page. Minor corrections that do not change your rights or our obligations — such as a typographical fix — do not.
Version 1.7 (8 September 2026) replaces version 1.6 (8 September 2026). Material change: this policy now names categories of data the app has stored for some time but that earlier versions did not list. It describes your own business and contact details, your supplier records — including the name, e-mail address, telephone number and address of a supplier's contact person, which is personal data about someone who is not our customer — and the product, cost, inventory, warehouse, purchasing, receiving, supplier return and stock count records the app keeps. It also states that we use subscription information Shopify provides to determine whether your paid access is active, and corrects the description of our database provider, which also holds the private storage your stock count attachments live in. No new data is collected and nothing about Shopify order data, customer data, advertising data, retention or deletion has changed: this version closes a gap in the description, not in the processing. Version 1.6 (8 September 2026) replaced version 1.5 (31 August 2026). Material change: that version described a category of data it did not name before — the files you upload yourself as a stock count attachment. It states what is stored about such a file, that it is held in private storage and reachable only through a short-lived link issued after a check that the count belongs to your store, how long it is kept, and when it is removed. The deletion description has also been made precise: a shop/redact request now removes those files from storage itself, not only our records of them. No new data is collected: the attachment feature already existed and is unchanged, and nothing about Shopify, customer or advertising data has changed. Version 1.5 (31 August 2026) replaced version 1.4 (31 August 2026). Material change: the application form now asks for a last name as well as a first name, and the field for the store is presented as the applicant's website rather than specifically a Shopify store URL. The list of data categories in the controlled release section reflects both. Nothing else about that processing changed: same purpose, same legal basis, same 12-month retention, same provider. Version 1.4 (31 August 2026) replaced version 1.3 (10 August 2026). Material change: our public website now carries an application form for the controlled release, so this policy describes a category of data it did not cover before — the details someone submits when applying for access, before they are a merchant. That section states what is collected, why, on what legal basis, how long it is kept, and which provider delivers the resulting notification e-mail. Nothing changed about the data the app processes for merchants or their customers: no new Shopify or advertising data category, no new purpose, and no change to the existing retention or deletion rules. Version 1.3 (10 August 2026) replaced version 1.2 (28 July 2026). Material change: advertising cost records and the related synchronisation provenance are now retained for a fixed maximum of 24 calendar months — the same reporting horizon as detailed order data — and are deleted automatically past that limit. Disconnecting an advertising platform stops future synchronisation but no longer deletes the advertising history that was already imported; that history remains subject to the same 24-month limit and to shop/redact. Version 1.2 (28 July 2026) replaced version 1.1 (25 July 2026). Material change: the advertising sections previously described Meta as the only advertising platform that can be connected. Google Ads is now available as well, so those sections describe both platforms, list separately which Google Ads data categories are read and stored, and state that our Google Ads access is used for read-only reporting. No new data category is collected from Shopify, no processing purpose was added or widened, and the retention and deletion rules are unchanged.