Privacy Policy
Last updated: September 8, 2026
This Privacy Policy explains how ShopTrade Pte Ltd ("ShopTrade", "we", "us"), a company registered in Singapore with its registered office at 160 Robinson Road, #14-04 SBF Center, Singapore 068914, collects, uses, and protects information in connection with the ShopQuotes application and related websites and services (the "Service"). By installing or using the Service, you agree to this Policy.
1. Who this policy is for
The Service is used by Shopify merchants and their staff. We process two broad categories of data: information about the merchant and their store, and information about the merchant's own customers that flows through the quoting workflow. The merchant is the controller of their customers' personal data; we act as a processor on the merchant's behalf.
2. Information we collect
- Store and account data from Shopify: store name, domain, contact email, plan, locale, currency, and staff identities, used to operate the app.
- Quote and order data: draft orders, line items, prices, customer name, email, phone, and addresses associated with quotes the merchant creates or receives.
- Connected email account data: when a merchant connects a sending account (for example Gmail, Outlook, or an email service), we store the credentials or tokens required to send on the merchant's behalf (see Section 4).
- Usage and diagnostic data: logs, error reports, and basic analytics used to operate and improve the Service.
3. How we use information
- To provide the quoting features merchants install the app for.
- To send quote and notification emails that the merchant configures or initiates.
- To provide support, maintain security, prevent abuse, and meet legal obligations.
- To improve the Service in aggregate. We do not sell personal data, and we do not use it for advertising.
4. Google user data (Gmail) and Microsoft (Outlook)
If a merchant chooses to connect a Google account to send quote emails, the Service requests the following OAuth scopes: https://www.googleapis.com/auth/gmail.send (to send email the merchant initiates), https://www.googleapis.com/auth/gmail.settings.basic (to read the list of "Send mail as" addresses on the connected mailbox so the merchant can choose a verified alias to send from), userinfo.email (to identify the connected mailbox address), and userinfo.profile (to pre-fill the sender display name). We request offline access so we can refresh the connection without asking the merchant to sign in repeatedly.
We use Google user data only to send emails that the merchant configures or triggers from within ShopQuotes, and to read the mailbox's "Send mail as" address list so the merchant can pick which verified address quotes are sent from. We do not create, change, or delete any Gmail setting, filter, forwarding rule, or send-as entry. We do not read, search, or store the contents of the mailbox, we do not access incoming mail, and we never use Google user data for advertising or to train generalized artificial intelligence or machine learning models. Access tokens and refresh tokens are stored encrypted at rest and are used solely to perform the sending action on the merchant's behalf.
Limited Use disclosure. ShopQuotes' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why
https://www.googleapis.com/auth/gmail.send: used to send the quote and notification emails that the merchant composes or triggers in ShopQuotes, from the merchant's own mailbox. This scope only sends mail; it does not grant read access.https://www.googleapis.com/auth/gmail.settings.basic: used only to call the Gmail send-as list endpoint (users.settings.sendAs.list) and show the merchant a dropdown of the verified "Send mail as" addresses on the connected mailbox, so quotes can be sent from an alias such as quotes@ or sales@. We store only the alias address, display name, and verification status, solely to populate that dropdown and to set the From address on emails the merchant sends. We never create, modify, or delete send-as entries or any other Gmail setting, and this scope is never used to read messages.https://www.googleapis.com/auth/userinfo.email: used to identify and display the email address of the connected mailbox so the merchant knows which account is sending.https://www.googleapis.com/auth/userinfo.profile: used to pre-fill the sender display name (the "From" name) when a mailbox is first connected. The merchant can change it at any time.
Our Limited Use commitments
Consistent with the Google API Services User Data Policy, ShopQuotes commits that its access to and use of Google user data will:
- be limited to providing and improving the email sending features that are user facing and prominent in ShopQuotes;
- not be transferred or sold to third parties, except as necessary to provide or improve those features, to comply with applicable law, or in connection with a merger or acquisition with appropriate notice;
- not be used for serving advertisements;
- not be used to develop, train, or improve generalized or non personalized artificial intelligence or machine learning models; and
- not be read by any human, except (a) with the user's explicit consent for specific messages, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized and is used for internal operations.
Revoking access
A merchant can disconnect a connected account at any time inside ShopQuotes, which deletes the stored tokens and any stored send-as alias data for that account. A merchant may also revoke ShopQuotes' access directly from their Google Account at myaccount.google.com/permissions (or from their Microsoft Account security settings). Revoking access immediately ends our ability to send on the merchant's behalf.
If a merchant connects a Microsoft account instead, we request Mail.Send, User.Read, and offline_access for the same purpose and under the same limitations described above.
5. How we share information
We share data only as needed to run the Service:
- Shopify, the platform the app runs on.
- Email and infrastructure providers used to deliver messages and host the Service (for example email delivery services, cloud hosting, and error monitoring), acting as our subprocessors.
- Legal and safety: where required by law or to protect rights, safety, and the integrity of the Service.
We do not sell personal data.
6. Data retention and deletion
We retain data for as long as the merchant uses the Service, and for a limited period afterward as required for legitimate business or legal purposes. When a merchant uninstalls the app, we stop sending and remove stored sending credentials and send-as alias data. We honor Shopify's mandatory data deletion requests (shop/redact, customers/redact, customers/data_request) within the required windows, and propagate applicable deletions to our subprocessors. A merchant may request deletion of their data by contacting us.
7. Security
We use industry standard measures including encryption in transit, encryption at rest for sensitive credentials and tokens, access controls, and per-store isolation. No method of transmission or storage is completely secure, but we work to protect your information.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, including under the Singapore Personal Data Protection Act (PDPA), the EU and UK GDPR, and similar laws. Merchants act as the controller for their customers' data and should direct end customers accordingly. To exercise a request relating to data we hold, contact us at the address below.
9. International transfers
We and our subprocessors may process data in countries other than where you are located. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We may update this Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice.
11. Contact
ShopTrade Pte Ltd (operator of ShopQuotes)
160 Robinson Road, #14-04 SBF Center, Singapore 068914
Email: support@shopquotes.com
© 2026 ShopTrade Pte Ltd. All rights reserved. ShopQuotes is a product of ShopTrade Pte Ltd.