FolioPO

Privacy policy

Effective September 8, 2026 ยท Revision 2

FolioPO provides purchase-order document processing for merchants. Contact the FolioPO operator at [email protected] about privacy or this service.

Information we process

We process your shop domain, installation credentials, subscription and usage records, product and variant identifiers, SKUs, titles and prices. Uploaded purchase orders may contain customer names, email addresses, shipping addresses, phone numbers, product lines, quantities and prices. We store original documents, extracted order details, matches, draft-order references, saved aliases, parsing templates and operational audit records.

Purpose and sharing

We use this information to extract purchase orders, match products, let you review details, create the draft orders you request, track plan allowance, provide support, and handle security and deletion requests. We do not sell customer data or use it for advertising.

Shopify receives the draft-order information you approve. DigitalOcean hosts the application and database in the United States. GitHub Actions provides encrypted recovery-backup storage and recovery automation on GitHub-hosted infrastructure, which may process data in the United States. Backup artifacts are private and retained for up to seven days. When AI extraction or OCR is used, document content is sent to Volcengine Ark (Doubao) for processing through its China-region service. Uploaded documents may contain personal information; only upload information you are authorized to process. These service providers process information under their applicable service and privacy terms. Processing may occur outside your country.

Retention and deletion

Original files expire after the configured retention period, up to 7 days on Starter, 30 days on Growth and 90 days on Pro. Audit history is retained for up to 30, 180 and 365 days respectively. Extracted order records and reusable settings remain available until deleted or the shop is redacted. Deleting an original file does not by itself delete its extracted order history.

You can export shop data and delete eligible order data in Settings. Shopify customer-data requests and shop-redaction webhooks are supported. Unresolved draft creation may need reconciliation before deletion to avoid duplicate orders. Uninstalling stops access; the subsequent Shopify shop-redaction request triggers removal of stored shop data. Draft orders already created in Shopify must be managed in Shopify.

Security and choices

Connections use HTTPS. App access uses Shopify authentication, and data access is scoped to the installed shop. No system can guarantee absolute security. Contact us to request access, correction or deletion; we may verify your authority to act for the shop. Customers should contact the merchant that collected their information.

Personal content and original files are encrypted by the application. Encrypted recovery backups are retained for up to seven days. Security access records use pseudonymous user identifiers and expire after 90 days. Recovery includes reapplying deletion requests before service resumes.

Our Data Processing Agreement describes processing instructions, service providers, responsibilities and incident handling.

Updates

We may update this policy as the service changes. The effective date above identifies the latest revision.

Support and usage guide