InventoryPath Order Exports privacy notice
Last updated: October 6, 2026
InventoryPath is a brand of AvanSaber Inc., which operates InventoryPath Order Exports. This notice explains the app’s processing of Shopify merchant, supplier and order information. Read it alongside the AvanSaber company privacy policy. This notice describes the app-specific processing; the InventoryPath website privacy supplement covers website analytics and newsletter subscriptions.
For privacy questions or requests, contact [email protected]. Merchants are responsible for their customer notices and for choosing suppliers authorised to receive the selected information.
Information the app uses
The app reads the order and line-item information needed for configured exports: Shopify order and line identifiers, dates, order statuses and tags, product and vendor details, SKUs, quantities, amounts, currencies, line-item customisation values, order attributes and selected supported order metafields.
It also uses shop identifiers, workflow settings, supplier email addresses, verification records and Shopify subscription eligibility. Raw Shopify order responses are processed transiently rather than stored as complete order records.
This version does not request Shopify buyer name, email, phone or address fields. Customer-entered customisation values and merchant-selected attributes can still contain personal information. Include only the fields your authorised supplier needs.
How information is used and shared
We use this information to preview and generate exports, run schedules, authenticate merchant staff and suppliers, check billing eligibility, troubleshoot the app and respond to privacy requests.
Exports are accessible to authorised app users and the verified supplier configured for the workflow. Supplier notifications contain a private access link rather than a spreadsheet attachment. The approved supplier inbox must verify access before downloading, including when a link has been forwarded.
We do not use exported order data to enrol customers in marketing lists or send it to an advertising service. Installing the app or verifying a supplier inbox does not subscribe anyone to a newsletter.
Service providers
The app runs on AvanSaber’s AWS infrastructure, managed through RunCloud, with Cloudflare serving its HTTPS hostname. PostgreSQL stores app records. Zoho ZeptoMail sends transactional verification and notification emails. Shopify provides authorisation and app subscription billing.
Brevo is used for optional website newsletter subscriptions, separately from app processing. It is not connected to order exports. Export files are stored privately on the app server; S3 and R2 are not used for this deployment.
Data protection
HTTPS protects transmission. Authenticated access and supplier inbox verification control downloads. Export objects, Shopify tokens and privacy-report bodies use application-level authenticated encryption. Export files are held outside public webroots, and database backups are separately encrypted. The app’s database disk is encrypted at rest.
Supplier verification codes expire after ten minutes, are single-use, have attempt and rate limits, and are stored as hashes.
Retention
| Information | Retention |
|---|---|
| Export files | Access expires after seven days; the worker removes the encrypted file. |
| Export manifests, source identifiers and diagnostic export records | Up to 65 days after processing, with privacy deletion taking precedence. |
| Data-access reports | Up to 30 days after preparation. |
| Expired supplier verification challenges | Cleaned after one additional day. |
| Shop, workflow and supplier settings | While needed to provide the installation, subject to deletion requests and uninstall cleanup. |
| Database backups, including recovery-test copies | Encrypted, with a maximum 14-day retention. |
Minimal hashed event receipts may be retained to prevent replaying privacy events; older receipts remove the raw shop value. The 14-day backup retention rule also applies to encrypted recovery-test copies held on operator-controlled storage.
Access, deletion and uninstall
The app authenticates Shopify customer-data request and redaction webhooks. For a data request, it prepares a private report of retained rows requested by Shopify. An authorised merchant can download the report and provide it through the merchant’s verified customer-request process.
When relevant data is redacted, affected files are revoked and deleted. Files containing more than one customer’s data are removed in full. Affected schedules pause, and a future-only recovery boundary prevents erased historical rows from being fetched again.
Uninstalling stops app access and schedules and begins deletion of live app data, with a 24-hour operational target. Failed deletion jobs are retried. Before restoring a backup, later privacy and uninstall events must be reconciled so erased data, revoked downloads and old notifications do not become active again.
Merchants and customers can also contact [email protected] about app processing or to request access, correction or deletion. The rights and request process in the company privacy policy apply alongside this notice.
Changes and contact
We update this notice when app processing or providers change and communicate material changes through the appropriate merchant-facing channel.
AvanSaber Inc. operates InventoryPath Order Exports. Contact [email protected].