Privacy Policy
Last updated: July 23, 2026
1. Who we are
SellerThreshold ("we", "us") provides a US sales-tax economic nexus monitoring service for e-commerce merchants. Contact: support@sellerthreshold.com.
2. Data we collect
Merchant account data: email, name, and authentication identifiers.
Store data (via Shopify and other integrations): shop domain, OAuth access tokens, and per-order metadata strictly required to calculate nexus: order ID, order date, order total, tax collected, currency, and the destination US state/region.
What we do NOT store: customer names, emails, phone numbers, street addresses, IP addresses, or payment/card information. We deliberately drop these fields when normalizing orders.
Payments: handled by Stripe. We store subscription status only; Stripe holds all card data.
3. How we use data
- Calculate rolling 12-month nexus exposure per US state.
- Send merchant-configured alerts (email / Slack) when thresholds approach.
- Provide reports and CSV/PDF exports to the merchant.
- Authenticate the merchant and manage their subscription.
We do not sell, rent, or share merchant or customer data with third parties for advertising.
4. Subprocessors
- Lovable Cloud / Supabase — hosting, database, and authentication.
- Stripe — subscription billing.
- Shopify — source of order data (with merchant consent via OAuth).
- Resend / email provider — transactional email delivery.
5. Data retention & deletion
Order data is retained while the store is connected plus 24 months, which is the maximum lookback window for economic-nexus rules. On uninstall we mark the store as disconnected. When Shopify sends the shop/redact webhook (48 hours after uninstall) we delete the store row and all associated order data. Merchants can also request deletion at any time by emailing support@sellerthreshold.com.
6. Security
All data is encrypted in transit (TLS) and at rest. Access tokens are stored encrypted. Access is limited to SellerThreshold engineers on a need-to-know basis. Row-level security policies isolate each merchant's data.
7. GDPR / CCPA rights
Because we minimize collection of end-customer PII, most GDPR/CCPA data-subject requests are satisfied automatically. Shopify merchants may exercise access, rectification, or deletion rights via Shopify's compliance webhooks, which we honor. Merchant accounts may request access, export, or deletion of their own account data at support@sellerthreshold.com.
8. Changes
Material changes to this policy will be announced by email to active merchants at least 14 days in advance.