Supplier Bridge · Privacy

Supplier Bridge Privacy Policy

Supplier Bridge · provided by zFinia · effective 30 September 2026

This policy explains how Supplier Bridge, an app for Shopify stores provided by zFinia through the Shopify App Store, handles data. It applies to the app. The zFinia website is covered by the zFinia Privacy Policy.

Summary

Supplier Bridge reads the purchase orders you create in Shopify and turns each one into a CSV file laid out the way your supplier needs. It has read-only access to purchase orders and inventory, and no access to your orders or your customers.

zFinia does not sell your data, use it for advertising, or share it with anyone except the service providers listed below.

What the app can read

When you install Supplier Bridge, Shopify asks you to grant these read-only permissions: purchase orders, inventory transfers, inventory shipments and inventory. The app uses them to read:

  • Purchase orders: number, status, currency, dates, the supplier name and destination location name recorded on the order, and each line's supplier SKU, product and variant title, quantity and unit cost.
  • The SKU of each line's inventory item.
  • Shipments linked to a purchase order, only for the carrier's estimated arrival date.

Supplier Bridge does not request access to orders, customers or any other protected customer data.

What we store

  • Your store's myshopify.com domain and the access credentials Shopify issues to the app for your store, used to call Shopify on your behalf.
  • The supplier templates you create: template names, the supplier names you enter, column names and order, the Shopify fields or fixed values you choose, delimiter and header settings.
  • A count of your successful CSV exports and the time of the last one, used for the free plan's export limit.
  • Your plan status (paid or not, and the plan's handle), cached for a few minutes after Supplier Bridge asks Shopify which plan you're on.
  • Technical logs: requests to the app and error messages, which can include your store's domain.

What we don't store

Purchase order contents and the CSV files you download are not stored. Each file is built when you ask for it and sent straight to your browser.

Billing

Plans are billed by Shopify through Shopify App Pricing. Supplier Bridge never sees or stores payment details. To apply your plan, the app asks Shopify's Partner API which plan your store has chosen.

Service providers and location

  • Shopify: the platform the app runs in, and billing.
  • Render: hosts the app's web service (United States, Virginia).
  • Neon: hosts the app's database (United States, AWS us-east-1).

Your data is therefore processed and stored in the United States.

Retention and deletion

  • When you uninstall, the app's access credentials for your store are deleted straight away and its cached plan status is cleared.
  • Your templates and export count are kept until Shopify sends the shop data deletion request (Shopify sends it 48 hours after you uninstall). All data for your store is then deleted. If you reinstall before then, your templates are still there.
  • Supplier Bridge holds no customer personal data. It still answers Shopify's customer data request and customer deletion webhooks.

To ask for deletion sooner, or for a copy of what we hold for your store, email support@zfinia.com from an address you use for your store.

Security

  • All traffic uses HTTPS.
  • Every request is authenticated with Shopify session tokens, and every data query is limited to the store making the request.
  • Webhooks from Shopify are verified with HMAC signatures; requests that fail verification are rejected.
  • Credentials and secrets are kept in the hosting provider's environment settings, never in source code.

Changes and contact

If this policy changes, we update this page and the effective date above.

Questions: support@zfinia.com.