Valet Wholesale Management
Privacy Policy
Effective date: August 17, 2026 · Contact: sales@valethumidity.com
This privacy policy describes how the Valet Wholesale Management Shopify app (the “App”) collects and uses information when a merchant installs the App on their store.
Who this applies to
This policy covers data processed by the App on behalf of the installing merchant, including wholesale application submissions from prospective buyers and related Shopify customer records created when an application is approved.
Information we collect
- Wholesale applications: name, email, phone, business name, business type, website (optional), notes, and optional custom packaging interest submitted via the apply form or app proxy.
- Shopify shop data: shop domain, offline session / access tokens needed to run the embedded admin, create tagged customers, and manage checkout validation rules.
- Customer tags: when an application is approved, the App may create or update a Shopify customer and apply tags such as
wholesale and tier tags configured by the merchant. - Operational logs: application events and webhook acknowledgements needed for support and compliance.
How we use information
- Review and approve or reject wholesale applications
- Provision wholesale buyer access (customer account invite + tags)
- Send transactional email (applicant confirmations, decision notices, admin alerts)
- Send optional webhook notifications configured by the merchant (e.g. Slack)
- Enforce checkout gating for non-wholesale buyers via a Shopify Function
- Respond to Shopify mandatory privacy webhooks
Processors / subprocessors
- Shopify (platform hosting the merchant store and App distribution)
- Application hosting provider (e.g. Railway)
- Transactional email provider (e.g. Resend)
- Optional notification webhooks configured by the merchant
Data retention and deletion
Application records are retained while needed to operate wholesale onboarding for the installing merchant. The App honors Shopify’s mandatory compliance webhooks:
- customers/data_request — locate application data for the requested customer email.
- customers/redact — delete application records matching the requested customer email for that shop.
- shop/redact (after uninstall) — delete shop sessions, shop settings, and application PII stored by the App for that shop.
- app/uninstalled — delete sessions for that shop.
Sharing
We do not sell personal information. Data is shared only with processors listed above as needed to operate the App, or when required by law.
Security
Access to the embedded admin uses Shopify session tokens / OAuth. Webhooks are verified with Shopify HMAC authentication. Data is transmitted over HTTPS.
Contact
Privacy questions: sales@valethumidity.com
Support: /support