OrderFlow by Mentilead Back to Home

Privacy Policy

Last updated: September 2026

1. Introduction

This Privacy Policy explains how Mentilead ("we", "us", "our") collects, uses, stores, and protects personal data when you use the OrderFlow application ("the App", "OrderFlow"). OrderFlow is a Shopify application that provides B2B quick ordering functionality for Shopify merchants and their customers.

We are committed to protecting the privacy of merchants who install our App and the end customers who interact with the quick order page. This policy applies to all data processed through OrderFlow, whether you are a merchant (the data controller) or an end customer (the data subject).

By installing or using OrderFlow, you agree to the practices described in this Privacy Policy. If you do not agree, please uninstall the App and discontinue use.

This Privacy Policy is supplemented by our Terms of Service and Data Processing Agreement (DPA).

2. Data Controller and Data Processor

Under the General Data Protection Regulation (GDPR), data processing roles are defined as follows:

  • Data Controller: The Shopify merchant who installs OrderFlow. The merchant determines the purposes and means of processing their customers' personal data.
  • Data Processor: Mentilead (company behind OrderFlow). We process personal data on behalf of merchants according to their instructions and the functionality of the App.
  • Data Controller (for merchant data): Mentilead acts as a data controller for the merchant's own data (e.g., account information, billing details, app settings).

Our processing of end-customer data is governed by our Data Processing Agreement (DPA), which is incorporated by reference into our Terms of Service.

Company Information

3. Personal Data We Process

Merchant Data (we are the controller)

  • Shopify store domain and shop information
  • Merchant notification email address
  • Store contact email (copied from your Shopify store settings), used to send account emails such as export-ready notices when no notification email is set
  • Name and email address of the Shopify staff or collaborator accounts that open OrderFlow in your admin, and whether that account is the store owner — used to address account emails to the store owner when no notification email is set
  • OAuth access tokens and session data
  • App settings and branding configuration
  • Billing plan and subscription status
  • Cancellation feedback: the reason you pick and any optional comment you type when cancelling or downgrading on the Pricing page

End-Customer Data (we are the processor)

  • Order history: Customer name, email address, Shopify customer ID, order details (line items, quantities, totals), order timestamps. When OrderFlow is installed it imports orders from the preceding 12 months; orders placed after installation are captured as they occur.
  • Saved lists: List name, product selections, creation date, associated customer ID
  • Cart sessions: Current cart contents, customer ID (TTL: 7 days, automatically deleted)
  • B2B company or market context: Company name, company ID, location ID, catalog assignments, payment terms, or market context (TTL: 24 hours, automatically deleted)
  • B2B draft orders / approval requests: Customer name, email address, Shopify customer ID, company, line items, approval status and note (retained for 12 months, automatically deleted)
  • Buyer invitations: Invited buyer name, email address, company (retained for 90 days, automatically deleted)
  • Reorder-reminder markers: Shopify customer ID, recording that a reminder email was sent (retained for 7 days, automatically deleted)

Product Data (no personal data)

  • Product cache: SKU, title, price, variant ID, image URL (refreshed from Shopify product updates; expires after 90 days)
  • This data contains no customer PII and is used solely for product search and display

Technical Data

  • Server-side logs (email addresses masked): request metadata including IP address, error logs, performance metrics (retained for 14 days)
  • Edge access logs: IP address, user agent, approximate location (country/network), requested page path (without query parameters) — retained 90 days
  • Audit logs: actor, action, resource type/ID, timestamp (retained for 12 months)
  • Abuse-prevention counters: IP address or Shopify customer ID, used to limit request rates (retained for at most 2 hours)
  • Email suppression list: email addresses that bounced or complained, kept so we stop sending email to them
  • Asynchronous processing queues: webhook payloads, email and job messages in transit (retained for up to 14 days)
  • Browser localStorage: cart state and recent searches, keyed by shop and Shopify customer ID (see Section 6)

Statutory and Contractual Requirements

Providing your email address and customer information is necessary to use OrderFlow's ordering functionality. Without this data, OrderFlow cannot process orders or provide saved list features. You are not legally obligated to provide this data, but it is required to use the service.

5. How We Use Personal Data

We use personal data exclusively to provide, maintain, and improve the OrderFlow service:

  • Providing the service: Processing orders, managing saved lists, maintaining cart sessions, displaying order history, and enabling product search
  • B2B functionality: Detecting B2B company context, displaying catalog pricing, applying payment terms, and creating draft orders for approval
  • Merchant administration: Managing app settings, branding configuration, billing plans, and usage tracking
  • Transactional communications: Sending order confirmations, export completion notifications, and billing-related emails via Resend
  • Account emails to merchants: A small number of one-time emails about your OrderFlow account — a welcome after install, a reminder if your order page is not yet linked from your store, a nudge if no order has come through a live order page, a note when your first OrderFlow order arrives, and a confirmation when you choose a paid plan — sent via Resend to your notification email or, if none is set, the store owner's email (or the most recent staff user's) or your store's contact email
  • Weekly digest to merchants: An optional Monday email, sent via Resend to your notification email (or, if blank, the store owner's account email, else your store's contact email) only when something needs your attention, summarising pending B2B draft orders, buyer invitations without an order or that could not be delivered, Free-plan usage, and your OrderFlow order counts, revenue and new-buyer count. It contains counts and totals only — no buyer names or email addresses — and can be turned off in Settings → Notifications and reminders
  • Security and compliance: Maintaining audit logs, detecting unauthorized access, and fulfilling GDPR data subject requests
  • Service improvement: Analyzing anonymized usage metrics (via CloudWatch EMF) to improve reliability and performance

We do not:

  • Sell, rent, or trade personal data to third parties
  • Use personal data for our own marketing or advertising purposes
  • Profile end customers or build behavioral profiles
  • Use personal data for automated decision-making or profiling as defined by GDPR Article 22

6. Cookies and Local Storage

OrderFlow does not set any HTTP cookies. We use browser localStorage for two items:

Item Purpose Contents
Cart state Keeps the current cart contents between page loads Cart items, keyed by shop and Shopify customer ID
Recent searches Shows the buyer's recent search terms Search terms, keyed by Shopify customer ID

These items are keyed by shop and Shopify customer ID. They contain no names or email addresses and stay in the buyer's browser.

Optional: Google Analytics 4

Only if the merchant sets a Google Analytics 4 (GA4) measurement ID, and only after the buyer has allowed analytics through the store's Shopify cookie consent (Shopify's Customer Privacy API), the order page loads Google's gtag.js. gtag.js sets Google's first-party analytics cookies (_ga and _ga_<id>) and sends page views, searches (the search term only if the merchant has enabled this), add-to-cart, checkout-start and CSV-import row counts directly from the buyer's browser to the merchant's GA4 property. Google Signals and ad personalization are disabled. No name, email address, customer ID or order ID is sent. Without consent, nothing loads and nothing is sent. Mentilead does not receive this data; the merchant is responsible for their GA4 property, their terms with Google and their cookie notice.

7. Data Storage and Security

Infrastructure Location

All data is stored and processed within the European Union:

  • Region: AWS eu-central-1 (Frankfurt, Germany)
  • Database: Amazon DynamoDB (single-table design)
  • File storage: Amazon S3 (for data exports and uploaded files)
  • Message queues: Amazon SQS (for async processing)

Security Measures

  • Encryption at rest: All DynamoDB tables and S3 buckets use AWS-managed encryption (AES-256)
  • Encryption in transit: All communications use HTTPS/TLS 1.2+
  • Data at rest: Customer data, including email addresses, is stored in DynamoDB tables encrypted with AWS-managed keys; OrderFlow applies no additional application-level field encryption
  • Email masking in logs: Server-side logs mask email addresses and are retained for 14 days
  • Access control: IAM least-privilege policies for all service components
  • S3 access: Private buckets with pre-signed URLs (time-limited access)
  • Backups: Daily automated backups retained for 90 days, plus 35-day point-in-time recovery
  • Monitoring: AWS CloudWatch for alerts, AWS X-Ray for tracing, CloudWatch Logs Insights for analysis

8. Data Retention

We retain data only as long as necessary for the purposes described in this policy:

Data Type Retention Period Deletion Method
Cart sessions 7 days Automatic (DynamoDB TTL)
Product cache 90 days Automatic (DynamoDB TTL)
B2B company context 24 hours Automatic (DynamoDB TTL)
OAuth sessions Offline: until uninstall. Per-staff online sessions (staff name, email): 24 hours after the access token expires Immediate deletion on uninstall; online sessions also expire automatically
Saved lists Until deleted by the customer, a customers/redact request, or shop deletion 12 months after uninstall Customer action, customers/redact, or daily cleanup job
Uploaded files (CSV/XLSX) 30 days Automatic (S3 lifecycle policy)
Data export files 14 days Automatic (S3 lifecycle policy)
Order records 5 years from the end of Mentilead's financial year to which the records relate, while the app is installed; deleted with all other shop data 12 months after uninstall Automatic (DynamoDB TTL) — bogføringsloven §12(1); daily cleanup job after uninstall
Billing/subscription records 5 years from the end of Mentilead's financial year to which the records relate Automatic (DynamoDB TTL) — bogføringsloven §12(1)
Audit logs 12 months Automatic (DynamoDB TTL) — security of processing
B2B draft orders / approval requests 12 months Automatic (DynamoDB TTL)
Buyer invitations 90 days Automatic (DynamoDB TTL)
Reorder-reminder markers 7 days Automatic (DynamoDB TTL)
Abuse-prevention counters (IP address or customer ID) At most 2 hours Automatic (DynamoDB TTL)
Asynchronous processing queue messages Up to 14 days Automatic (SQS message retention)
Server logs 14 days Automatic (log retention policy)
Edge (CloudFront) access logs 90 days Automatic (S3 lifecycle policy)
Query results over edge access logs (abuse investigation; include IP addresses, stored in the EU) 7 days Automatic (S3 lifecycle policy)
Backups 90 days Automatic (backup lifecycle)

After Uninstall

When a merchant uninstalls OrderFlow, OAuth sessions are deleted immediately. All remaining data is retained for 12 months to allow for reinstallation. After 12 months, a daily cleanup job permanently deletes all DynamoDB items for the shop and its uploaded and exported files. Shopify's shop/redact webhook is processed asynchronously and does not shorten the 12-month period. Deleted data can remain in backups and previous S3 object versions for up to 90 days. The billing/subscription ledger is kept separately under the Danish Bookkeeping Act (bogføringsloven). Merchants who want their data deleted sooner can email privacy@mentilead.com; the request is handled under Section 12.

9. Sub-Processors and Third-Party Services

We use the following sub-processors to provide the OrderFlow service:

Sub-Processor Purpose Data Location Data Processed
Amazon Web Services (AWS) Infrastructure (compute, database, storage, queues) eu-central-1 (Frankfurt, DE) All application data
Shopify Inc. E-commerce platform, OAuth, App Proxy US/Canada (Shopify infrastructure) Store data, customer data (via API)
Resend Transactional email delivery US Email address, email content
GitHub Source code hosting and CI/CD US Source code only (no customer data)

We will notify merchants of any changes to our sub-processor list by updating this Privacy Policy and, where appropriate, by email notification. Merchants may object to a new sub-processor within 30 days of notification.

10. International Data Transfers

Our primary data processing occurs within the EU (AWS eu-central-1, Frankfurt). However, some sub-processors are based in the United States:

  • Shopify: Transfers are governed by Shopify's own data processing terms and their participation in recognized data transfer mechanisms
  • Resend: Email delivery requires transfer of email addresses and content. Resend processes data under Standard Contractual Clauses (SCCs)
  • GitHub: No customer data is transferred — only source code

For all international transfers, we ensure appropriate safeguards are in place as required by GDPR Chapter V, including Standard Contractual Clauses (SCCs) approved by the European Commission, and we conduct transfer impact assessments where necessary.

11. Data Breach Notification

In the event of a personal data breach, we will:

  1. Notify the affected merchant(s) without undue delay and within 72 hours of becoming aware of the breach
  2. Provide details of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to mitigate the breach
  3. Assist the merchant in fulfilling their own breach notification obligations to supervisory authorities and data subjects
  4. Document the breach in our internal records regardless of whether notification to the supervisory authority is required

Report suspected breaches to privacy@mentilead.com.

12. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Article 15): Request a copy of the personal data we hold about you
  • Right to rectification (Article 16): Request correction of inaccurate personal data
  • Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten")
  • Right to restriction (Article 18): Request restriction of processing in certain circumstances
  • Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format
  • Right to object (Article 21): Object to processing based on legitimate interest

For Merchants

Exercise your rights by contacting privacy@mentilead.com. You can also export your data via Settings > Data & privacy > Data export and deletion. To have your data deleted before the automatic deletion 12 months after uninstall, email privacy@mentilead.com.

For End Customers

End customers should direct data subject requests to the merchant (data controller) who installed OrderFlow. The merchant can then use OrderFlow's built-in tools to fulfill the request, or contact us for assistance. We respond to requests processed through Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact) automatically. customers/redact replaces the customer's name and email on retained order and draft-order records with a redaction marker and deletes their saved lists, cart, context rows and uploaded files; customers/data_request reports to the merchant what OrderFlow holds.

We will respond to all rights requests within 30 days. If a request is complex, we may extend this by an additional 60 days with notification.

13. Data Protection Officer

As a small organization, Mentilead is not legally required to appoint a Data Protection Officer under GDPR Article 37. However, all privacy matters are handled directly by the company owner. For any data protection queries, contact:

14. Supervisory Authority

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

You may also contact the supervisory authority in your own EU member state.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • The "Last updated" date at the top of this page will be revised
  • For material changes, we will notify merchants via email and/or an in-app notification
  • Continued use of OrderFlow after notification constitutes acceptance of the updated policy

We encourage you to review this policy periodically.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us:

Appendix: GDPR Article 13/14 Transparency Information

The following table provides the specific information required by GDPR Articles 13 and 14 in a concise format:

Requirement Information
Identity of controller (merchant data) Mentilead, Denmark
Identity of controller (customer data) The Shopify merchant who installed OrderFlow
Contact details privacy@mentilead.com
Purposes of processing See Section 5
Legal basis See Section 4
Recipients / sub-processors See Section 9
International transfers See Section 10 — safeguarded by SCCs
Retention periods See Section 8
Data subject rights See Section 12
Right to lodge complaint See Section 14 — Datatilsynet (Danish DPA)
Automated decision-making None — OrderFlow does not use automated decision-making or profiling
Source of data Directly from merchants (via app installation), from Shopify (via API), and from end customers (via the quick order page)