Privacy Policy
B2B Rebate Manager ("the app") is operated by Nsawa Enterprises LLC. This policy explains what data the app processes when a merchant installs it on their Shopify store, why, and what happens to that data. Last updated 30 August 2026.
What the app does
The app calculates volume rebates for business customers from a store's existing order history. It is read only: it does not change anything in the store, move money, or write to orders, products, or customers.
Data processed, and why
- Order data: line amounts, discounts, taxes, dates, and currency. This is the basis every rebate is calculated from.
- Buyer identity: the Shopify identifier of the company, company location, or customer an order belongs to, and their display name. This is how spend is attributed to the correct rebate agreement, and how buyer names appear on rebate statements.
- Store settings: currency and timezone, because rebate periods and amounts depend on them.
The app does not read or store customer email addresses, phone numbers, or postal addresses from the store. It processes the minimum personal data needed to provide the service, and uses it for no other purpose. No data is sold. Data is shared only with the service providers listed below, and only to do the specific job described.
Service providers the app relies on
- Oracle Cloud hosts the app and its database. All stored data lives there.
- OpenAI processes two things when a merchant chooses to use them: the text of an agreement document the merchant uploads for extraction, and the questions the merchant types to the in app assistant, together with summary setup information (counts and statuses, not buyer identities). These requests are sent with storage disabled and are not used to train models. Merchants who do not upload documents or use the assistant send nothing to OpenAI.
- Resend delivers rebate statement emails when a merchant sends one. It receives the recipient address the merchant enters and the statement itself.
Where data lives
Data is stored in the app's own database on Oracle Cloud infrastructure. Storage volumes are encrypted at rest, connections use TLS in transit, the database is not reachable from the public internet, and backups are kept on the same encrypted storage. Test and production data are kept in separate databases. Access is limited to the operator of the app.
Retention and deletion
- Data is kept only while the app is installed and serving the merchant.
- When a customer asks their merchant for erasure, Shopify notifies the app and the app removes that customer's identifiers. The financial records a merchant is legally required to keep (order values and rebates already calculated) are retained, but can no longer be linked to a person.
- 48 hours after a merchant uninstalls the app, Shopify sends a deletion request and the app deletes all of that store's data.
- When a customer asks what data is held about them, the app can produce that answer for the merchant, who remains the data controller.
Roles
The merchant is the data controller for their customers' data. The app acts as a processor on the merchant's instructions. Subprocessor: Oracle Cloud (hosting). Shopify remains the source of all data the app reads.
Contact
Questions about this policy or about data held by the app: contact Nsawa Enterprises LLC at etechflow0@gmail.com.