BuyerClear
Write to us

Privacy policy

Last updated 7 September 2026. Draft for the pre-alpha; it requires legal review before the first merchant.

Who we are

BuyerClear is a service for Shopify merchants that collects a buyer’s professional license or resale certificate, shows the merchant the entered details, any uploaded document and the result of a supported official-source lookup, and records the merchant’s decision. It is operated by an independent developer. Contact: hello@buyerclear.com.

Two roles

For buyer applications the merchant decides why data is collected and who is admitted; BuyerClear processes that data on the merchant’s instructions. For the merchant’s own account, BuyerClear is the controller.

What we collect from buyers

The application does not ask for payment details or government ID numbers beyond the professional credential. Merchants should not request unrelated sensitive information in custom questions. Normal request information is used to serve and protect the pages.

What we do with it

Where it is stored

Data is stored and processed on Cloudflare (Workers, D1, R2 and Workers AI). Names, emails, credential numbers and documents are encrypted at rest with keys held by BuyerClear. Documents are never used to train models. The merchant’s Shopify store receives approved account data. An enabled official register receives only the credential kind, jurisdiction, number and, for scoped professional checks, licence type and issuing authority needed for its lookup.

How long

Documents are scheduled for deletion 90 days after submission by default, or on the merchant’s configured retention schedule. A later decision does not extend an existing document’s deadline. Typed values, the decision and the audit trail are kept while the merchant uses BuyerClear, so that expiry and renewals can be tracked. Uninstalling disables the shop’s access and tokens. Shop data erasure is queued when Shopify sends its shop-redaction webhook; uninstalling does not erase it immediately.

The retention period for personal details after buyer access closes is not yet finalised. The proposal to remove names and emails after 90 days has not been adopted or automated. This must be resolved before the first merchant; hashes and dated decisions may still be personal data.

Merchant referrals

An opaque referral code present when an authenticated merchant opens the app may be recorded once for installation attribution. We do not store the full referral URL. The code is unverified and does not authorise any commission or payment.

Your rights

You can ask to see, correct or delete your data. Because the merchant decides why it is collected, write to the shop you applied to first; they can ask us to act. You can also write to hello@buyerclear.com and we will respond within 30 days. Your statutory rights depend on the privacy laws applicable to you and the merchant. The merchant handles requests about buyer applications, with BuyerClear assisting.

Cookies

BuyerClear’s application and status pages set no tracking cookies. Merchant decisions use the current Shopify staff session and a form-protection token. The public website can remember a chosen color theme in the browser’s local storage.

Your status link

Each application has a status page at a private status reference (100 bits of randomness for newly issued references; older references remain valid). It shows the state of the application and your address in masked form. Opening the prefilled update form also asks for the address on the application. This is an address match, not email-ownership verification. Anyone holding the link can see the application’s state, so treat it as private.

Security

Names, email addresses, credential numbers, uploaded documents and full evidence payloads in BuyerClear storage use AES-256-GCM under keys held by BuyerClear and travel over TLS. Operational metadata, including expiry, status, record identifiers and query times, is not field-encrypted and may still be personal data. Encrypted fields remain encrypted in database backups. Documents live in a private object store that is never public. Each encrypted field is sealed to its own shop and purpose, so a ciphertext cannot be moved between shops or fields and still open. Logs never contain names, emails, credential numbers, document text or tokens. Access to a document or a decision is recorded in a hash-chained audit trail with the staff member who did it. Tests use synthetic data in separate local or staging environments; production buyer data is not copied into testing.

If something goes wrong

The pages you reach without signing in are rate limited by address, and uploads are capped at 10 MB with the file type decided by the file’s own signature. A suspected security incident is assessed within 24 hours. If personal data was exposed, the affected merchants are told by email within 72 hours of confirming it, with what happened, what data was involved and what to do; buyers are told through their merchant. Write to security@buyerclear.com to report a vulnerability; we answer within one business day and will not pursue anyone who reports in good faith.

Changes

We will post changes on this page with a new date. Material changes are announced to merchants by email.