Privacy & data
Protected customer data
TermForge collects a deposit at checkout and captures the remaining balance later. To do that it must read your orders and charge the balance on the payment method the buyer already authorised — so it requests order scopes and is Level 1.
PCD LEVEL 1
What TermForge accesses
read_orders / write_orders
To find the orders placed on one of your deposit plans, work out the outstanding balance, and record the balance payment against the order. Order data includes customer details — which is why this app is Level 1.
write_payment_mandate
To capture the balance on the payment method the buyer authorised at checkout. TermForge holds only Shopify’s mandate reference — it never sees or stores card numbers.
read_products / write_products / write_own_subscription_contracts
To publish each deposit plan as a Shopify selling plan, so the deposit option appears on the products you choose.
read_draft_orders / write_draft_orders
For draft-order deposits and net payment terms: creating the draft order and emailing the invoice with a secure checkout link.
What TermForge stores
For deposits, only what it needs to collect the balance: the Shopify order ID and order name, the amounts (total, deposit, balance, currency), the payment-mandate reference, and the balance status and dates. From order data it does not retain shipping addresses, and it never stores card or bank details — those stay with Shopify and your payment provider.
Request a quote (RFQ): when a shopper submits your storefront “Request a quote” form, TermForge stores the contact details they type in — name, company, email, phone, message — together with the products and quantities requested, so you can price and reply to the quote. This is the only place it holds buyer contact details, and only because the shopper provided them to request a quote. It is deleted on a customer- or shop-redaction request and never sold, shared, or used for advertising or model training.
How your data is handled
- Purpose-limited: order data is used only to determine and collect an outstanding deposit balance. It is never sold, shared, or used for advertising or model training.
- Encrypted at rest: Shopify access tokens are stored with AES-256-GCM encryption.
- Deleted on uninstall: on app uninstall and on a Shopify customer- or shop-redaction request, the associated data is removed.
- No card data, ever: balances are captured through Shopify’s payment mandate. TermForge never holds your money and never touches card details.
Honesty
A balance can only be captured automatically when the buyer’s payment method was vaulted at checkout (Shopify Payments and other gateways that support deferred payment). Where it can’t be, TermForge tells you and the balance stays visible on the Balances tab for you to collect.