Privacy policy
Last updated 7 September 2026. Draft for the pre-alpha; it requires legal review before the first merchant.
Who we are
BuyerClear is a service for Shopify merchants that collects a buyer’s professional license or resale certificate, shows the merchant the entered details, any uploaded document and the result of a supported official-source lookup, and records the merchant’s decision. It is operated by an independent developer. Contact: hello@buyerclear.com.
Two roles
For buyer applications the merchant decides why data is collected and who is admitted; BuyerClear processes that data on the merchant’s instructions. For the merchant’s own account, BuyerClear is the controller.
What we collect from buyers
- Business name, your name and email address.
- Credential type, issuing state, credential number, the name printed on the credential and its expiry date.
- A PDF, JPEG or PNG when you upload a supporting credential document. Professional form profiles can be submitted without a file. Licence type and issuing authority are stored with scoped professional applications.
- The application reference and the times of submission and decision.
- Answers to up to five additional questions configured by the merchant.
The application does not ask for payment details or government ID numbers beyond the professional credential. Merchants should not request unrelated sensitive information in custom questions. Normal request information is used to serve and protect the pages.
What we do with it
- Read any uploaded document with a machine reader to prepare a comparison for the merchant. The reader never approves or rejects anyone.
- Send the credential number, kind and jurisdiction, plus the licence class and issuing authority for scoped professional checks, to the separate BuyerClear Registry Worker. It calls only sources enabled in the source-policy table. Your name, email, document, shop and application identifier are never sent.
- Show the merchant’s staff the typed values, any uploaded document and the registry result so that a person can decide.
- After approval, create a company and contact in the merchant’s Shopify store using the submitted business name, contact name and email, or link the existing company location selected by staff. Store expiry on newly created locations; preserve existing linked location expiry data.
- Keep an audit trail of who decided what and when.
- Where an existing subscription includes scheduled rechecks, re-check approved credentials against supported registers every 90 days and raise a staff-review alert if a register stops confirming one. This never changes access on its own.
- If the merchant enables it, share a decision receipt and status tags in Shopify. Other installed apps can read the receipt. It contains decision dates, a hash and credential type, jurisdiction and expiry, but no name, email, license number, document or raw registry record. A hash is not a guarantee of anonymity.
Where it is stored
Data is stored and processed on Cloudflare (Workers, D1, R2 and Workers AI). Names, emails, credential numbers and documents are encrypted at rest with keys held by BuyerClear. Documents are never used to train models. The merchant’s Shopify store receives approved account data. An enabled official register receives only the credential kind, jurisdiction, number and, for scoped professional checks, licence type and issuing authority needed for its lookup.
How long
Documents are scheduled for deletion 90 days after submission by default, or on the merchant’s configured retention schedule. A later decision does not extend an existing document’s deadline. Typed values, the decision and the audit trail are kept while the merchant uses BuyerClear, so that expiry and renewals can be tracked. Uninstalling disables the shop’s access and tokens. Shop data erasure is queued when Shopify sends its shop-redaction webhook; uninstalling does not erase it immediately.
The retention period for personal details after buyer access closes is not yet finalised. The proposal to remove names and emails after 90 days has not been adopted or automated. This must be resolved before the first merchant; hashes and dated decisions may still be personal data.
Merchant referrals
An opaque referral code present when an authenticated merchant opens the app may be recorded once for installation attribution. We do not store the full referral URL. The code is unverified and does not authorise any commission or payment.
Your rights
You can ask to see, correct or delete your data. Because the merchant decides why it is collected, write to the shop you applied to first; they can ask us to act. You can also write to hello@buyerclear.com and we will respond within 30 days. Your statutory rights depend on the privacy laws applicable to you and the merchant. The merchant handles requests about buyer applications, with BuyerClear assisting.
Cookies
BuyerClear’s application and status pages set no tracking cookies. Merchant decisions use the current Shopify staff session and a form-protection token. The public website can remember a chosen color theme in the browser’s local storage.
Your status link
Each application has a status page at a private status reference (100 bits of randomness for newly issued references; older references remain valid). It shows the state of the application and your address in masked form. Opening the prefilled update form also asks for the address on the application. This is an address match, not email-ownership verification. Anyone holding the link can see the application’s state, so treat it as private.
Security
Names, email addresses, credential numbers, uploaded documents and full evidence payloads in BuyerClear storage use AES-256-GCM under keys held by BuyerClear and travel over TLS. Operational metadata, including expiry, status, record identifiers and query times, is not field-encrypted and may still be personal data. Encrypted fields remain encrypted in database backups. Documents live in a private object store that is never public. Each encrypted field is sealed to its own shop and purpose, so a ciphertext cannot be moved between shops or fields and still open. Logs never contain names, emails, credential numbers, document text or tokens. Access to a document or a decision is recorded in a hash-chained audit trail with the staff member who did it. Tests use synthetic data in separate local or staging environments; production buyer data is not copied into testing.
If something goes wrong
The pages you reach without signing in are rate limited by address, and uploads are capped at 10 MB with the file type decided by the file’s own signature. A suspected security incident is assessed within 24 hours. If personal data was exposed, the affected merchants are told by email within 72 hours of confirming it, with what happened, what data was involved and what to do; buyers are told through their merchant. Write to security@buyerclear.com to report a vulnerability; we answer within one business day and will not pursue anyone who reports in good faith.
Changes
We will post changes on this page with a new date. Material changes are announced to merchants by email.