Otheriver Agent Portal Suite Privacy Policy
Effective date: August 18, 2026
This Privacy Policy explains how Otheriver Agent Portal Suite (the App) collects, uses, stores and discloses information when a Shopify merchant installs or uses the App.
The App is provided by Otheriver, Via Primo Riccitelli 3, 64100 Teramo (TE), Italy, VAT number 02172620672 (Otheriver, we, us). Contact us at apps@otheriver.com.
1. Our role
For merchant account and service administration data, Otheriver acts as a data controller. For customer and order data processed on behalf of a merchant, Otheriver generally acts as the merchant's data processor or service provider. Merchants remain responsible for their own privacy notices and lawful instructions.
2. Information we process
Depending on the merchant's configuration and use of the App, we may process:
- Shopify shop domain, installation status, app credentials and technical identifiers required to connect the App to Shopify;
- merchant, administrator and sales-agent account information, including name, email address, role, group, permissions and securely hashed password data;
- customer information made available by the merchant or Shopify, including name, email address, telephone number, billing or shipping address, company and tax-related fields, customer metafields and customer assignment information;
- product, collection, price, inventory and catalog information required to present the merchant's catalog to authorized agents;
- order and draft-order information, including selected products, quantities, customer association, notes, shipping choices, payment-method selection, totals and status;
- portal settings, branding preferences, enabled modules, mappings and workflow configuration;
- technical and security information such as IP address, user agent, timestamps, authentication events, audit records, application errors and rate-limit data;
- support communications and information voluntarily provided when requesting assistance.
3. How we use information
We process information to:
- provide and secure the agent portal and its Shopify integration;
- authenticate users and enforce roles, groups and permissions;
- display catalog, customer and order information to authorized users;
- create and manage Shopify customers, draft orders and orders at the merchant's instruction;
- attribute applicable orders to the App's Shopify sales channel;
- configure, personalize and maintain each merchant's portal;
- diagnose errors, prevent misuse, maintain audit records and improve reliability;
- respond to support requests and meet legal, security and Shopify platform obligations.
We do not sell personal information and do not use customer data for third-party advertising or unrelated profiling.
4. Legal bases
Where the GDPR or similar law applies, we rely on performance of our contract with the merchant, our legitimate interests in operating and securing the service, compliance with legal obligations, and the merchant's documented instructions. Merchants are responsible for establishing the lawful basis for customer data they direct us to process.
5. Service providers and disclosures
We disclose information only as necessary to operate the App, comply with law or protect the service. Providers may include:
- Shopify, for app installation, authentication and commerce data exchange;
- Railway, for application and database hosting;
- Resend, when transactional service emails are enabled;
- professional advisers, authorities or successor entities where required by law or a legitimate corporate transaction.
These providers process information under their own applicable terms and data-protection commitments. We do not authorize them to use merchant customer data for their own advertising.
6. International transfers
Service providers may process information in countries other than the user's country. Where required, we use appropriate safeguards for international transfers, such as contractual protections recognized by applicable law.
7. Retention and deletion
We retain information while the App is installed or while needed to provide the service, resolve disputes, maintain security records and meet legal obligations. Uninstalling the App disables the associated tenant access and removes the Shopify access credential. When Shopify sends an applicable customer or shop redaction request, the App deletes the corresponding locally stored customer or tenant data in accordance with that request. Backup copies may persist temporarily until overwritten through normal backup cycles, subject to legal or security requirements.
8. Security
We use technical and organizational safeguards designed to protect information, including encrypted HTTPS transport, access controls, role-based permissions, signed and HttpOnly session cookies, password hashing, webhook signature verification, audit logging and tenant-level data isolation. No system can guarantee absolute security.
9. Cookies and local storage
The App uses strictly necessary authentication and security cookies. It may also store interface preferences, language choices, remembered email selections and unsent workflow drafts in the user's browser. These technologies are used to provide requested functionality and are not used for third-party advertising.
10. Rights and requests
Individuals may have rights to access, correct, delete, restrict or object to certain processing, depending on applicable law. Shopify customers should normally contact the merchant that controls their data. Merchants and users may contact apps@otheriver.com. We will assist merchants with verified requests and respond as required by applicable law.
11. Children
The App is a business service intended for merchants and authorized business users. It is not directed to children.
12. Changes
We may update this Privacy Policy to reflect changes to the App, law or our practices. We will publish the revised version with a new effective date.
13. Contact
Otheriver
Via Primo Riccitelli 3
64100 Teramo (TE), Italy
VAT number: 02172620672
Email: apps@otheriver.com