Privacy Policy
Last updated: June 17, 2026
This Privacy Policy explains how ShopTrade Pte Ltd ("ShopTrade", "we", "us"), a company registered in Singapore with its registered office at 160 Robinson Road, #14-04 SBF Center, Singapore 068914, collects, uses, and protects information in connection with the ShopQuotes application and related websites and services (the "Service"). By installing or using the Service, you agree to this Policy.
1. Who this policy is for
The Service is used by Shopify merchants and their staff. We process two broad categories of data: information about the merchant and their store, and information about the merchant's own customers that flows through the quoting workflow. The merchant is the controller of their customers' personal data; we act as a processor on the merchant's behalf.
2. Information we collect
- Store and account data from Shopify: store name, domain, contact email, plan, locale, currency, and staff identities, used to operate the app.
- Quote and order data: draft orders, line items, prices, customer name, email, phone, and addresses associated with quotes the merchant creates or receives.
- Connected email account data: when a merchant connects a sending account (for example Gmail, Outlook, or an email service), we store the credentials or tokens required to send on the merchant's behalf (see Section 4).
- Usage and diagnostic data: logs, error reports, and basic analytics used to operate and improve the Service.
3. How we use information
- To provide the quoting features merchants install the app for.
- To send quote and notification emails that the merchant configures or initiates.
- To provide support, maintain security, prevent abuse, and meet legal obligations.
- To improve the Service in aggregate. We do not sell personal data, and we do not use it for advertising.
4. Google user data (Gmail) and Microsoft (Outlook)
If a merchant chooses to connect a Google account to send quote emails, the Service requests the following OAuth scopes: https://www.googleapis.com/auth/gmail.send (to send email the merchant initiates) and userinfo.email (to identify the connected mailbox address). We request offline access so we can refresh the connection without asking the merchant to sign in repeatedly.
We use Google user data only to send emails that the merchant configures or triggers from within ShopQuotes. We do not read, search, or store the contents of the mailbox, we do not access incoming mail, and we never use Google user data for advertising or to train generalized artificial intelligence or machine learning models. Access tokens and refresh tokens are stored encrypted at rest and are used solely to perform the sending action on the merchant's behalf.
Limited Use disclosure. ShopQuotes' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why
https://www.googleapis.com/auth/gmail.send: used to send the quote and notification emails that the merchant composes or triggers in ShopQuotes, from the merchant's own mailbox. This scope only sends mail; it does not grant read access.https://www.googleapis.com/auth/userinfo.email: used to identify and display the email address of the connected mailbox so the merchant knows which account is sending.
Our Limited Use commitments
Consistent with the Google API Services User Data Policy, ShopQuotes commits that its access to and use of Google user data will:
- be limited to providing and improving the email sending features that are user facing and prominent in ShopQuotes;
- not be transferred or sold to third parties, except as necessary to provide or improve those features, to comply with applicable law, or in connection with a merger or acquisition with appropriate notice;
- not be used for serving advertisements;
- not be used to develop, train, or improve generalized or non personalized artificial intelligence or machine learning models; and
- not be read by any human, except (a) with the user's explicit consent for specific messages, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized and is used for internal operations.
Revoking access
A merchant can disconnect a connected account at any time inside ShopQuotes, which deletes the stored tokens. A merchant may also revoke ShopQuotes' access directly from their Google Account at myaccount.google.com/permissions (or from their Microsoft Account security settings). Revoking access immediately ends our ability to send on the merchant's behalf.
If a merchant connects a Microsoft account instead, we request Mail.Send, User.Read, and offline_access for the same purpose and under the same limitations described above.
5. How we share information
We share data only as needed to run the Service:
- Shopify, the platform the app runs on.
- Email and infrastructure providers used to deliver messages and host the Service (for example email delivery services, cloud hosting, and error monitoring), acting as our subprocessors.
- Legal and safety: where required by law or to protect rights, safety, and the integrity of the Service.
We do not sell personal data.
6. Data retention and deletion
We retain data for as long as the merchant uses the Service, and for a limited period afterward as required for legitimate business or legal purposes. When a merchant uninstalls the app, we stop sending and remove stored sending credentials. We honor Shopify's mandatory data deletion requests (shop/redact, customers/redact, customers/data_request) within the required windows, and propagate applicable deletions to our subprocessors. A merchant may request deletion of their data by contacting us.
7. Security
We use industry standard measures including encryption in transit, encryption at rest for sensitive credentials and tokens, access controls, and per-store isolation. No method of transmission or storage is completely secure, but we work to protect your information.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, including under the Singapore Personal Data Protection Act (PDPA), the EU and UK GDPR, and similar laws. Merchants act as the controller for their customers' data and should direct end customers accordingly. To exercise a request relating to data we hold, contact us at the address below.
9. International transfers
We and our subprocessors may process data in countries other than where you are located. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We may update this Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice.
11. Contact
ShopTrade Pte Ltd (operator of ShopQuotes)
160 Robinson Road, #14-04 SBF Center, Singapore 068914
Email: support@shopquotes.com
© 2026 ShopTrade Pte Ltd. All rights reserved. ShopQuotes is a product of ShopTrade Pte Ltd.