Privacy Policy — PivotOps for SHOPLINE

Last updated: 25 June 2026

This Privacy Policy explains how PivotOps (operated by Craftstreams, “PivotOps”, “we”, “us”) collects, uses, stores, and protects information when a SHOPLINE merchant installs and uses the PivotOps application (“the App”). It applies to data accessed through SHOPLINE’s APIs and to data merchants provide directly to PivotOps.

1. Information we collect through SHOPLINE’s APIs

With the merchant’s explicit authorization granted during installation, the App may access:

We request only the read permissions necessary to provide these features and do not request access beyond that scope.

2. Information we collect from merchants

When a merchant creates a PivotOps account, we collect contact details (name, email), workspace configuration, and the workforce data the merchant chooses to manage in PivotOps (such as staff records, schedules, onboarding documents, and compliance credentials).

3. Information from a merchant’s customers

PivotOps is a workforce-operations tool. We do not place cookies or tracking technologies on the devices of a merchant’s store customers, and we do not collect store-customer personal data by default. If a SHOPLINE GDPR data-request or redaction webhook references a customer, we process it as described in Section 7.

4. How we use information

We use the information solely to provide and improve the App’s services: generating staffing and scheduling recommendations from store activity, syncing staff into onboarding and compliance, securing the connection, and providing customer support. We do not sell, rent, or trade data, and we do not use it for advertising or for purposes unrelated to the App’s workforce-management function.

5. Data retention

We retain store data only while the App is installed and for as long as needed to provide the service. When a merchant uninstalls the App, we revoke the stored access token and stop processing store data. Following SHOPLINE’s shop-redaction webhook (sent after uninstall), we delete data associated with the store connection. Workforce data the merchant created in their PivotOps account is retained under the merchant’s PivotOps account terms and is deleted when the merchant deletes their PivotOps account.

6. Data location and security

PivotOps is operated by Craftstreams, which is established in Lagos, Nigeria. Data is stored with our infrastructure providers (Supabase and Vercel) in the United States and other global regions, and may be processed outside the merchant’s country. We apply industry-standard safeguards including encryption in transit, access controls, tenant isolation enforced at the database level, and signed/verified webhooks.

7. GDPR & data subject requests

Regardless of where a merchant’s customers are located, we honor SHOPLINE’s mandatory data webhooks. On a customer data-request, we log and fulfill any data we hold that matches. On a customer redaction request, we delete matching records. On a shop redaction request, we delete data associated with the store connection. We respond to these requests within the periods required by applicable law.

8. Contact us

If you have questions about this policy or wish to exercise a data right, contact us at privacy@pivotops.app.

PivotOps · Craftstreams · www.pivotops.app