Privacy Policy
Last updated 29 July 2026
MultiVendorOS ("the app") is a Shopify application operated by RedexSoft ("we", "us"). It turns a single Shopify store into a multi-vendor marketplace: when a customer buys from several vendors in one checkout, the app splits that order into one job per vendor, calculates the merchant's commission, and records what the merchant owes each vendor.
This policy explains what data the app touches, why, and what we will and will not do with it. It covers merchants who install the app, vendors who use the vendor portal, and the customers of those merchants whose order details pass through the app.
The short version. We process order data because splitting orders is the app's only function. We never sell it, never use it for marketing, never profile it, and never share it with anyone except the vendor fulfilling that specific order. Everything is deleted 30 days after you uninstall.
1. Who controls the data
For data belonging to a Shopify store, the merchant is the data controller and we are a data processor. We process store data only on the merchant's instructions, which are expressed through the permissions they grant at install and the settings they choose in the app.
For merchant and vendor account data — the people who sign in to the app — we are the controller.
2. What we collect, and why
From the Shopify store
| Data | Why the app needs it |
|---|---|
| Shop profile — domain, name, currency, timezone, plan | To identify the store, format money correctly and calculate deadlines in the merchant's own timezone. |
| Orders — line items, quantities, prices, discounts, taxes, shipping, financial status | The core function. Without line items and prices there is nothing to split and no commission to calculate. |
| Fulfillment orders and locations | To determine which vendor is responsible for which line of an order. |
| Customer name and shipping address | The vendor physically packs and ships the parcel, so they must know where it is going. Without it an order cannot be fulfilled. |
| Customer email and phone | Shown to a vendor only when the merchant explicitly enables it. Both settings are off by default. Used solely for delivery coordination — a courier unable to find an address, or confirming a delivery slot. |
| Products, variants and inventory | To attribute products to vendors, publish vendor products to the storefront and keep stock in step. |
From merchants and vendors directly
- Account details — name, email address, and for vendors a password we store only as an Argon2id hash.
- Vendor business details and any verification documents the merchant asks for.
- Vendor payout details. Bank account numbers are stored encrypted and are never displayed in full — not to the merchant, and not to us. Only the last four digits are ever shown.
Automatically
- Audit records of actions taken in the app — who approved a vendor, who changed a commission rate, who recorded a payout — with actor, IP address and timestamp. These exist so that financial decisions can be answered for later, and they are append-only.
- Error and performance logs, retained for 30 days.
3. What we never do
- We do not sell personal data. There is no circumstance in which we would.
- We do not use customer data for advertising, marketing or profiling.
- We do not enrich customer records against third-party data sets.
- We do not use merchant or customer data to train machine learning models.
- We do not contact a merchant's customers.
4. Who the data is shared with
Within a marketplace, a vendor sees only the orders assigned to them, and only the customer fields the merchant has chosen to expose. A vendor can never see another vendor's orders, products, earnings or customers. This is enforced at the database query layer rather than in the interface, and a request for another tenant's record returns "not found" rather than "forbidden", so the existence of other data is not disclosed.
Outside the app, data reaches only:
- Shopify — the source of the data and the destination for products and fulfillments we write back.
- Our hosting and database providers, under contract, solely to run the service.
- Payment providers, if and when a merchant enables automated vendor payouts, and only the details required to make that specific transfer.
- Authorities, where we are legally compelled. Where the law allows, we will tell the merchant first.
5. Where data is stored
Data is stored on servers in Germany, operated by our infrastructure provider. RedexSoft is established in India. Transfers out of the EEA, where they occur, rely on Standard Contractual Clauses.
6. How long we keep it
- While installed: for as long as the app is installed on the store.
- After uninstall: 30 days, then permanent deletion. The window exists so that a merchant who uninstalls by mistake, or reinstalls after changing plan, does not lose their vendor records and ledger.
- On request: a Shopify
customers/redactrequest is honoured immediately. Financial ledger entries are retained in anonymised form where accounting law requires it — the transaction survives, the person does not.
7. Security
- TLS 1.2 or higher for all traffic.
- Access tokens, bank details and other secrets encrypted at rest.
- Vendor passwords hashed with Argon2id. We cannot read them.
- Session tokens verified cryptographically on every request; a request that cannot prove which store it came from is rejected.
- Append-only audit and financial ledger records — enforced by database constraints, not only by application code, so they cannot be rewritten.
- Least-privilege permissions: the app requests 18 Shopify scopes, each mapped to a specific function it performs.
No system is perfectly secure. If a breach affects a merchant's data we will notify them without undue delay and within 72 hours of becoming aware, with what we know and what we are doing about it.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing.
If you are a customer of a store using this app, please contact that store first — they are the controller of your data and Shopify provides them with tools to action your request, which reach us automatically. If you contact us directly we will forward your request to the merchant and support them in answering it.
If you are a merchant or vendor, email privacy@multivendoros.com. We respond within 30 days and do not charge for a first request.
9. Children
The app is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.
10. Changes
We will post any change here and update the date at the top. Where a change materially affects how merchant or customer data is handled, we will email installed merchants at least 30 days before it takes effect.
11. Contact
RedexSoft
India
Privacy: privacy@multivendoros.com
Support: support@multivendoros.com