Legal · PO Pilot

Privacy Policy

Effective date: June 1, 2026 · Last updated: June 1, 2026

This Privacy Policy applies specifically to the PO Pilot product operated at popilot.app and describes how we handle your Shopify store data. The AVSaaS company-wide Privacy Policy also applies and governs any areas not specifically addressed here.

1. What Data PO Pilot Accesses from Shopify

PO Pilot connects to your Shopify store via Shopify OAuth with the following read-only scopes: read_inventory, read_products, read_orders, and read_locations. PO Pilot does not request write_inventory or any customer data scopes.

PO Pilot stores: your Shopify store identifier, a local cache of SKU identifiers and product names (used for PO line items), per-SKU inventory levels and velocity metrics (derived from order history), and your configured reorder rules. PO Pilot does not store your customers' personally identifiable information — order data is used only to derive aggregate sales velocity per SKU.

2. Purchase Order Data

PO Pilot stores draft and sent purchase orders you create within the product. This data includes: PO number, line items (SKU, quantity, supplier), PO state (draft, sent, confirmed, received, cancelled), and timestamps for each state transition. This data is retained for the lifetime of your account and deleted within 30 days of account closure.

3. Supplier Data

PO Pilot stores supplier records you create: supplier name, contact email, and any supplier portal tokens generated for portal access. Supplier portal tokens are HMAC-signed and scoped to a single supplier record. They expire and are regenerated on each portal link delivery.

4. Data Residency

Your account data is stored in the region you select at signup: EU-Central (Frankfurt) or US-East (Virginia). Data does not replicate across regions.

5. Shopify OAuth Permissions

PO Pilot requests only the minimum scopes required to evaluate inventory and velocity and to create accurate PO line items. We will never request write scopes for products, orders, or customers. If a future feature requires additional scopes, we will request your explicit re-authorization and explain exactly why each new scope is needed.

6. Retention and Deletion

Inventory snapshots and velocity cache data are retained for 90 days on a rolling basis. PO records are retained for the lifetime of your account. When you disconnect a Shopify store, velocity cache data for that store is deleted within 30 days. When you cancel your PO Pilot subscription, all account data is deleted within 30 days of account closure.

7. Contact

Data privacy questions for PO Pilot: [email protected]