OrderOps is an inventory and shipping platform for Shopify retailers, operated by Ivory & Deene (OrderOps, we, us), an Australian business. This policy explains how we handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). It covers our websites (orderops.app), the OrderOps application (ship.orderops.app) and related services (together, the Service).
1. Two kinds of personal information
We handle personal information in two distinct roles:
- Account information — information about you and your team as our customer. We collect and hold this for our own purposes.
- Merchant customer information — information about your customers (order recipients) that flows from your Shopify store and your carriers into the Service. We process this on your behalf, on your instructions, so you can fulfil orders. The merchant remains the party with the customer relationship.
2. What we collect
Account information
- Name, email address, workspace/business name, timezone.
- Billing details: plan, subscription status and invoices. Payments are processed by Shopify (app charges on your Shopify invoice) — we never see or store payment card details.
- Usage and log data: sign-in events, actions in the app, device/browser metadata, IP addresses, and support correspondence.
Merchant customer information
- Order data synced from your Shopify store: recipient name, company, email, phone, shipping address, order contents, order notes and fulfilment status.
- Shipping data generated when you book shipments: labels, tracking numbers, tracking events, customs declarations and proof-of-delivery information returned by carriers.
We collect this information from you, from your Shopify store via Shopify's APIs and webhooks, from your carriers, and automatically when you use the Service. We do not collect government identifiers, and we do not buy data about you from third parties.
3. Why we use it
- To provide and operate the Service — including syncing orders, managing inventory, booking shipments and printing labels on your instruction.
- To administer accounts, billing and support.
- To secure the Service: authentication, fraud and abuse prevention, audit trails.
- To improve the Service, using aggregated or de-identified information where practicable.
- To meet legal obligations.
We send operational email (sign-in links, billing notices, service updates). We do not sell personal information, and we do not use merchant customer information for marketing.
4. Who we share it with
We share personal information only with the service providers needed to run OrderOps, and only for the purposes above:
- Shopify — your connected store platform (order and inventory sync).
- Shipping carriers you connect — Australia Post, StarTrack, Team Global Express, TNT/FedEx — recipient and parcel details, sent to create the shipments you request.
- Render — application and database hosting.
- Cloudflare — DNS and content delivery.
- Resend — transactional email delivery.
- Sentry — error monitoring (configured not to receive personal data).
- Google — address validation of shipping addresses.
We may also disclose information where required by law, or as part of a genuine business sale or restructure (with equivalent privacy protections).
5. Overseas disclosure
Some of our providers store or process data outside Australia — principally in the United States (hosting, email and error monitoring). Where personal information is handled overseas we take reasonable steps to ensure it is protected consistently with Australian privacy law and each provider's contractual commitments.
6. Security
- All traffic is encrypted in transit (TLS/HTTPS).
- Carrier credentials and store access tokens are encrypted at rest.
- Sign-in uses single-use, expiring email links — we never store passwords.
- Access to production systems is restricted, and tenant data is isolated per workspace.
No system is perfectly secure; if a data breach occurs that is likely to result in serious harm, we will notify affected parties and the OAIC as required by the Notifiable Data Breaches scheme.
7. Retention and deletion
- Account information is kept while your account is active and for a reasonable period afterwards for legal and accounting purposes.
- Shipment-level personal data (carrier payloads, proof-of-delivery, tracking events) is purged on a rolling retention cycle after shipments reach a terminal state.
- When a Shopify store is uninstalled, Shopify sends a shop-redaction request ~48 hours later and we erase that store's customer personal information and revoke its credentials.
- When a merchant forwards a customer redaction request from Shopify, we erase that customer's personal information from the affected orders.
- Backups age out on a fixed cycle after deletion from live systems.
8. Your rights
You may request access to or correction of the personal information we hold about you by emailing hello@orderops.app. We respond within a reasonable time and will explain if any exception applies.
If you are a customer of a store that uses OrderOps, the store is the right first contact for access, correction or deletion requests — we act on the store's instructions, and we support Shopify's customer data-request and redaction processes end to end.
If you have a privacy complaint, contact us first and we will respond within 30 days. If you are unsatisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
9. Cookies
The application uses essential cookies only: a session cookie to keep you signed in and security-related cookies. We do not run advertising trackers, and the marketing site does not set analytics cookies.
10. Changes
We may update this policy from time to time; the "Last updated" date above reflects the current version, and material changes will be notified by email or in-app.
11. Contact
Privacy questions and requests: hello@orderops.app.