Privacy Policy for EdgeWholesale

Last Updated: September 17, 2026

1. Overview & Principle of Least Privilege

EdgeWholesale is engineered with a strict Zero PII (Personally Identifiable Information) architecture. We believe that the most secure data is the data that is never collected. Our application functions natively within Shopify's ecosystem using pure Rust WebAssembly Shopify Functions, processing B2B wholesale discounts and minimum order validations directly on Shopify's global edge infrastructure.

2. Information We Collect

We collect and retain only the minimal operational data required to provide our service:

  • Merchant Store Information: Shopify store domain (e.g., store.myshopify.com), offline API access tokens required to authenticate with Shopify Admin APIs, and app configuration preferences (e.g., minimum order quantities, discount tier percentages).
  • Customer Data: None. We do not store, copy, or process customer names, email addresses, phone numbers, physical addresses, billing details, or payment credentials on our servers.

3. How Customer Data is Processed (Shopify Functions)

When a merchant's customer logs into their storefront and checks out, Shopify evaluates buyer tags (e.g., wholesale, b2b) ephemerally inside Shopify's isolated WebAssembly execution sandbox. This computation occurs entirely within Shopify's secure execution environment. No customer identity or cart contents are transmitted to or stored on our external servers.

4. GDPR & CCPA Privacy Compliance Webhooks

EdgeWholesale fully implements and supports Shopify's mandatory GDPR and privacy compliance webhooks:

  • customers/data_request: Because EdgeWholesale stores zero customer personal data, no customer records exist to export.
  • customers/redact: Because EdgeWholesale stores zero customer personal data, no customer records exist to purge.
  • shop/redact: When an app is uninstalled or a store erasure request is received, all associated merchant session tokens and store configuration records are permanently deleted within 48 hours.

5. Data Security & Hosting

Merchant session tokens and configuration metafields are stored in an encrypted production SQLite database hosted on private, isolated container infrastructure protected by TLS 1.3 encryption and automated security headers. We do not sell, rent, or monetize any merchant or store data.

6. Contact Information

If you have questions regarding this Privacy Policy or wish to exercise any data rights under applicable privacy laws, please contact our security and compliance team:

EdgeCommerce Labs / Endpoint Security
Email: support@endptsec.com
Website: https://endptsec.com