QuoteCrate — Privacy Policy

Effective date: August 23, 2026

QuoteCrate is a Shopify app that lets a store's B2B and wholesale buyers request a quote, lets the merchant price it, and lets the buyer accept and check out at that price. This policy explains what personal data the app handles, why, who it is shared with, and how it is kept and deleted.

Who we are

QuoteCrate ("the app", "we") is operated by Seung Yong Oh, based in the Republic of Korea. For any privacy question or request, contact us at 12jason@donacouse.com.

What we collect

We collect only what the quote workflow needs.

From a store's buyers (entered on the merchant's storefront quote-request form, and in the quote conversation):

  • Name
  • Email address
  • Company name (optional)
  • The note and messages the buyer writes about their quote
  • The products and quantities the buyer requests

From the merchant / store (to run the app inside Shopify admin):

  • Shopify session data provided by Shopify when the app is installed (store domain, access token, and — for logged-in staff — the staff member's name and email).
  • Store-level information read from the Shopify Admin API: the store's name, currency, primary storefront domain, and the store's contact email (used only to send the merchant their quote notifications).

What we do NOT collect: We do not read your customers' data through the Shopify Admin API — buyer details come only from the quote form. We do not use cookies, analytics, advertising, or behavioral tracking on your storefront. The app runs inside Shopify admin using Shopify's own session tokens.

How we use it

  • To deliver quote requests to the merchant and show them in one list.
  • To let the merchant price a quote and send it, and to notify the merchant by email when a request or message arrives.
  • To email the buyer that their quote is ready and let them accept it.
  • To create a Shopify draft order and checkout link when a quote is accepted, so the buyer can pay the quoted price.

We do not sell personal data, and we do not use it for advertising.

Who we share it with (sub-processors)

  • Shopify — the platform the app runs on; creating the draft order / checkout when a quote is accepted. Data: buyer name and email, line items and prices.
  • Resend — sending transactional email (quote notifications, "quote ready", conversation messages). Data: recipient email address and message content.
  • Neon — database hosting where quote data is stored (United States). Data: all stored quote data.
  • Railway — application hosting (European Union). Data: data in transit while the app runs.

Where data is processed

The app is operated from the Republic of Korea. Quote data is stored in a database hosted in the United States (Neon), and the application is hosted in the European Union (Railway). By using the app you understand that data may be processed in these locations.

How long we keep it, and deletion

We keep quote data for as long as the app is installed on the store, because a quote is the merchant's own record of a negotiation and order. Data is deleted or redacted in line with Shopify's mandatory privacy webhooks:

  • Customer data request — When a store owner forwards a buyer's request for their data, we compile everything we hold about that buyer for that store and provide it to the store owner to pass on.
  • Customer redaction — When a buyer's data is to be erased, we remove their name, email, company, note and the entire message thread from that store's quotes, and disable the buyer's private quote link. The quote record itself is kept in redacted form because it is the merchant's business/order record.
  • Shop redaction — About 48 hours after a merchant uninstalls the app, we permanently delete all of that store's quote data, line items, messages, settings and sessions.

Your rights

Depending on where you live, you may have the right to access, correct, or delete your personal data, or to object to or restrict its processing. Buyers should contact the store they requested a quote from; the store can request the data from us or ask us to redact it. Merchants and anyone else can also contact us directly at 12jason@donacouse.com and we will respond.

Data security

Data is transmitted over encrypted connections (HTTPS/TLS) and stored with our database provider under their security controls. Access tokens and secrets are kept in server-side configuration, never exposed to the storefront.

Children

The app is a business tool for wholesale ordering and is not directed to children.

Changes to this policy

We may update this policy as the app changes. The effective date at the top shows when it was last updated. Material changes will be reflected here.

Contact

Questions or requests about this policy or your data: 12jason@donacouse.com (Seung Yong Oh, Republic of Korea).