Privacy Policy
Effective date: June 1, 2026 · Last updated: June 1, 2026
This Privacy Policy applies specifically to the PO Pilot product operated at popilot.app and describes how we handle your Shopify store data. The AVSaaS company-wide Privacy Policy also applies and governs any areas not specifically addressed here.
1. What Data PO Pilot Accesses from Shopify
PO Pilot connects to your Shopify store via Shopify OAuth with the following read-only scopes: read_inventory, read_products, read_orders, and read_locations. PO Pilot does not request write_inventory or any customer data scopes.
PO Pilot stores: your Shopify store identifier, a local cache of SKU identifiers and product names (used for PO line items), per-SKU inventory levels and velocity metrics (derived from order history), and your configured reorder rules. PO Pilot does not store your customers' personally identifiable information — order data is used only to derive aggregate sales velocity per SKU.
2. Purchase Order Data
PO Pilot stores draft and sent purchase orders you create within the product. This data includes: PO number, line items (SKU, quantity, supplier), PO state (draft, sent, confirmed, received, cancelled), and timestamps for each state transition. This data is retained for the lifetime of your account and deleted within 30 days of account closure.
3. Supplier Data
PO Pilot stores supplier records you create: supplier name, contact email, and any supplier portal tokens generated for portal access. Supplier portal tokens are HMAC-signed and scoped to a single supplier record. They expire and are regenerated on each portal link delivery.
4. Data Residency
Your account data is stored in the region you select at signup: EU-Central (Frankfurt) or US-East (Virginia). Data does not replicate across regions.
5. Shopify OAuth Permissions
PO Pilot requests only the minimum scopes required to evaluate inventory and velocity and to create accurate PO line items. We will never request write scopes for products, orders, or customers. If a future feature requires additional scopes, we will request your explicit re-authorization and explain exactly why each new scope is needed.
6. Retention and Deletion
Inventory snapshots and velocity cache data are retained for 90 days on a rolling basis. PO records are retained for the lifetime of your account. When you disconnect a Shopify store, velocity cache data for that store is deleted within 30 days. When you cancel your PO Pilot subscription, all account data is deleted within 30 days of account closure.
7. Contact
Data privacy questions for PO Pilot: [email protected]