Privacy policy
This policy explains how Plekify collects, uses and protects personal data in providing its software services.
Data we process. Account and billing details for the businesses we serve; property, rate and availability data you provide; booking and guest data that flows through the Service for your business; and limited usage data that helps us operate and improve the Service.
B2B integration services. If you use our Shopify B2B integration app ("B2B Sync"), we additionally process: (a) customer tier data — a text field on the Shopify customer record indicating trade tier (e.g., "Installer", "Distributor"); this is a business classification, not personal data; (b) application data — when a buyer applies for a trade account via our form, we collect company name, contact name, work email, phone (optional), and preferred tier, stored securely and used solely to process the application; (c) order data — order identifiers and totals synced to the merchant's ERP (NetSuite) for accounts-receivable tracking; no payment credentials are stored or transmitted.
Why we process it. To provide, secure and support the Service; to process fees; to meet legal and tax obligations; and, aggregated and de-identified, to improve the product.
Legal bases. Contract (running the Service you engaged us for), legitimate interests (security and product improvement), and legal obligation.
Sharing. We share data only with sub-processors that help deliver the Service — notably Shopify for commerce infrastructure, Oracle (NetSuite) as the ERP provider for B2B Sync clients, and our cloud-hosting provider (Hetzner) — under written, GDPR-compatible agreements, and where required by law.
International transfers. Data may be processed outside your country via our sub-processors, under standard contractual clauses or equivalent safeguards.
Security. We apply industry-standard controls, encryption in transit and at rest, and least-privilege access. Card data is handled by Shopify's PCI-DSS Level 1 infrastructure; Plekify does not store full card numbers.
Data deletion. When a customer requests erasure (via Shopify's customer redaction webhook) or a store uninstalls the B2B Sync app (via the shop redaction webhook), we delete all associated data — application records, order mappings, and audit logs — within 30 days.
Retention. We keep data for as long as your account is active and as needed to meet legal obligations, then delete or anonymise it.
Your rights. Subject to applicable law, you may request access, correction, deletion or portability of personal data, or object to processing. Contact hello@plekify.com.
Changes. We will update this policy as our practices evolve and notify you of material changes.