1. Scope
This Privacy Policy describes how B2B POS ("the App"), developed and operated by Molsoft Inc. ("Molsoft," "we," "us," "our"), a company headquartered in Montreal, Quebec, Canada, handles data when a merchant installs the App from the Shopify App Store and uses it in connection with their Shopify store.
This policy covers the B2B POS app only.
2. Roles: Who Controls What
For the limited data described in Section 3, Molsoft acts as a data processor on behalf of the merchant (the data controller), who remains responsible for their own end customers' and staff's personal data as processed through Shopify itself. The App does not independently collect or process personal data belonging to the merchant's staff, customers, or trade partners.
3. Information We Collect and Store
B2B POS is architected to minimize data persistence. The App does not maintain its own database of orders, customers, staff records, or transaction history — that data remains in Shopify and is accessed by the App in real time via the Shopify Admin API, without being written to Molsoft's infrastructure. The only data the App persists is a single session record per installed store, consisting of:
Authentication credentials (secrets):
- OAuth access token
- OAuth refresh token
- Storefront access token
These are offline access tokens issued by Shopify at install time, used solely to authenticate the App's API calls to the merchant's store. They are encrypted at rest using a managed key management service (KMS) and are never exposed in logs or support tooling.
Shop and billing metadata:
- The store's
.myshopify.comdomain - App owner identifier
- Subscription plan and Shopify plan tier
- Development-store flag
The App does not store merchant staff personal data, end-customer personal data, or order- or customer-level commercial data. Any personal data the App displays in the course of rendering the point-of-sale interface (for example, a customer name on an order screen) is retrieved live via the Shopify API and is not written to Molsoft's systems.
4. How We Use This Information
The data described in Section 3 is used exclusively to:
- Authenticate API requests between the App and the merchant's Shopify store;
- Maintain the App's connection to the store between sessions;
- Determine plan and billing tier for feature access and reconciliation with Shopify Billing;
- Provide support when a merchant contacts us regarding their store.
We do not sell this data, and we do not use it for advertising or profiling.
5. Legal Basis for Processing (GDPR / UK GDPR)
Where a merchant or their end customers are located in the EEA or UK, our processing of the limited data described in Section 3 relies on:
- Performance of a contract (Art. 6(1)(b)) — the credentials in Section 3 are necessary to provide the App the merchant installed;
- Legitimate interests (Art. 6(1)(f)) — billing and plan metadata, for account administration.
A Data Processing Addendum is available to merchants on request by contacting us using the details in Section 13.
6. Data Storage and Security
- Storage location: Data is hosted on cloud infrastructure located in North America.
- Encryption: Access and refresh tokens are encrypted at rest using KMS. All API traffic between the App and Shopify is encrypted in transit (TLS).
- Access control: Access to production credential stores is restricted to authorized Molsoft personnel on a need-to-know basis.
7. Data Retention
Session records described in Section 3 are retained for as long as the App remains installed on the merchant's store. Upon uninstall, Shopify sends Molsoft a shop/redact webhook 48 hours after the uninstall event; in accordance with Shopify's Partner Program requirements, Molsoft completes deletion of the corresponding session record within 30 days of receiving that webhook, unless we are legally required to retain it. Billing metadata may be retained longer where required for financial recordkeeping.
8. Subprocessors and Third-Party Sharing
We do not sell or rent data. We share the limited data described in Section 3 only with the following categories of subprocessor:
| Subprocessor | Purpose |
|---|---|
| Cloud infrastructure provider (North America) | Hosting and KMS encryption of session data |
| Shopify Inc. | Platform on which the App operates; OAuth token issuance and billing |
Molsoft does not share B2B POS data with any additional third-party analytics, marketing, or support subprocessors beyond those listed above.
9. Your Rights
Merchants, and where applicable their end users under GDPR or CCPA, may have the right to request access to, correction of, or deletion of data we hold; to object to or restrict certain processing; to data portability where applicable; and to lodge a complaint with a supervisory authority. Because the App stores no end-customer personal data, most such requests are satisfied by confirming the contents of the shop's session record, or by directing the request to Shopify directly for data the merchant controls within their store.
Requests can be made to hello@molsoft.io.
10. Shopify Compliance Webhooks
In accordance with Shopify App Store requirements, Molsoft honors the mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. Because B2B POS does not independently store customer personal data, customers/data_request and customers/redact requests will typically confirm that no App-held data exists beyond what is described in Section 3. shop/redact triggers deletion of the shop's session record as described in Section 7.
11. International Data Transfers
Where data is transferred outside a merchant's or end user's jurisdiction, Molsoft relies on Standard Contractual Clauses or other lawful transfer mechanisms as applicable to ensure an adequate level of protection.
12. Children's Privacy
The App is intended for use by business merchants and their authorized staff only. It is not directed at, and we do not knowingly collect data from, individuals under the age of 16.
13. Contact Us
Molsoft Inc.
Montreal, Quebec, Canada
Email: hello@molsoft.io
14. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by an updated "Last Updated" date at the top of this page.
How can we help?
We're here to help! Feel free to reach out with any questions or feedback you may have.
Contact Us
How can we help?
We're here to help! Feel free to reach out with any questions or feedback you may have.