Legal

Privacy Policy

TermForge collects a deposit at checkout and captures the remaining balance later. To do that it reads your orders and charges the payment method the buyer already authorised. It never sees card details and never holds your money.

Last updated: July 13, 2026

PCD LEVEL 1

Summary

TermForge is a Shopify app for deposits, partial payments and net terms. It publishes your deposit plans as Shopify selling plans, tracks the outstanding balance on each order, and captures that balance automatically — on fulfillment, on a date you choose, or a set number of days after checkout. Because it must know which orders carry a balance, it requests order access, which makes it a Protected Customer Data Level 1 app.

What we access and what we store

Orders

We read your orders (read_orders, write_orders) to identify orders placed on a deposit plan, work out the balance, and record the balance payment against the order.

Payment mandate

We use Shopify’s payment mandate (write_payment_mandate) to charge the balance on the method the buyer authorised. We hold only Shopify’s mandate reference — never a card number.

Products & selling plans

We read and write products (read_products, write_products, write_own_subscription_contracts) to publish each deposit plan as a Shopify selling plan.

Draft orders

We use draft orders (read_draft_orders, write_draft_orders) to send an invoice for an unpaid balance, and — on the Studio plan — for net terms and draft-order deposits.

What we store in our own database

Only the Shopify order ID and order name, the amounts (total, deposit, balance, currency), the payment-mandate reference, and the balance status and dates — plus your shop domain, app settings and billing status.

We do not store customer names, email addresses, phone numbers or shipping addresses, and we never store card or bank details. Those remain with Shopify and your payment provider.

How we use it

  • Determine the outstanding balance on a deposit order and capture it when it falls due.
  • Retry a failed balance charge, and — if it keeps failing — ask Shopify to email the buyer an invoice with a secure checkout link so they can pay with another card.
  • On the Studio plan: apply net payment terms, create draft-order deposits with an invoice, and issue store credit — each only when you ask for it.
  • Operate billing, support, and the app itself.

We never use your data for advertising or model training, and we never sell or share it.

No AI

TermForge is deterministic. Deposits, schedules, retries and terms are rules — not predictions. Nothing from your store is sent to an AI model.

Third parties

  • Shopify — hosts your store, authorises the app’s Admin API access, vaults the buyer’s payment method, processes the balance charge, and sends the invoice email.
  • Our hosting — a dedicated server in the European Union, with encrypted backups.

There are no other sub-processors: no AI provider, no analytics vendor, no advertising network.

Retention & security

  • Encrypted at rest: Shopify access tokens are stored with AES-256-GCM encryption; all traffic is served over TLS.
  • Purpose-limited: order data is read for the balance calculation and is not retained beyond the fields listed above.
  • Deleted on uninstall: on app uninstall and on a Shopify shop-redaction request, your data is removed. We honour the mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact).

Your rights (GDPR / CCPA)

You may request access to, correction of, export of, or deletion of the data we hold. Because we store no customer personal data of our own, a customer data-request has nothing to return; a shop-redaction request deletes all of your shop’s data. Contact gheorghe.beschea@overheat.agency.