Privacy Policy

TopOMS is an order management platform used by merchants to manage commerce operations across sales channels, including Shopify. This policy explains what personal data TopOMS processes, why it is processed, how long it is retained, and the choices available to merchants, their staff, and their customers.

1. Scope and our role

This policy applies to the TopOMS service, its public Shopify connector, and related support and operational services. “TopOMS”, “we”, “us”, and “our” refer to the TopOMS contracting party identified in the applicable TopOMS service agreement or order form. We do not identify a different legal entity on this page.

For account, business-contact, security, and service-administration data, that TopOMS contracting party normally acts as a data controller. For personal data that a merchant imports from Shopify or another sales channel and processes in TopOMS, the merchant normally acts as controller and TopOMS acts as its processor or service provider. The merchant decides why that customer data is used and is responsible for its customer-facing privacy notices and lawful basis. A separate agreement may describe these roles in more detail.

2. Personal data we process

Depending on the features a merchant enables, TopOMS may process:

  • Merchant and user data: names, business contact details, user and workspace identifiers, account roles, preferences, support communications, and authentication and audit information.
  • Store and integration data: store name and domain, Shopify identifiers, granted app scopes, connection status, webhook metadata, and encrypted access and refresh credentials needed to operate the integration.
  • Order and customer data: customer name, email address, telephone number, billing and delivery addresses, order contents, prices, discounts, taxes, currency, order notes, fulfillment and return details, and customer or order identifiers supplied by the connected channel.
  • Catalog and operations data: products, variants, inventory, warehouses, shipments, labels, tracking events, returns, and related records. Some records may contain customer personal data where it is necessary to fulfill or support an order.
  • Technical and security data: IP address, browser and device information, timestamps, application events, diagnostic information, and access logs used to operate, secure, and troubleshoot the service.

TopOMS does not need payment-card numbers to provide the Shopify connector. Merchants should not enter full card details or other unnecessary sensitive data into free-text fields.

3. Where the data comes from

We receive data from merchants and their authorized users, from connected platforms such as Shopify through authorized APIs and webhooks, and from enabled service providers such as couriers. We may also generate service, audit, and security records when people use TopOMS.

4. Why we process data

We process personal data only as needed to:

  • connect an authorized Shopify store to the correct TopOMS workspace;
  • synchronize orders, customers, products, inventory, fulfillment, returns, and related operational data;
  • prepare shipments, courier instructions, labels, tracking updates, and customer service workflows;
  • authenticate users, protect accounts, prevent misuse, investigate incidents, and maintain audit trails;
  • provide support, diagnose faults, maintain service reliability, and communicate material service changes;
  • honor privacy requests and Shopify compliance events, and meet legal or regulatory duties; and
  • analyze service performance using information limited to what is necessary for that purpose.

Where TopOMS is a controller, processing is generally necessary to perform the applicable service agreement, comply with law, or pursue legitimate interests in providing and securing the service. We rely on consent where the law requires it. Where TopOMS is a processor, we process customer data on the merchant’s documented instructions.

5. Shopify installation and compliance webhooks

The Shopify connector is installed and authorized through Shopify. Shopify provides the embedded app with a short-lived session token; TopOMS verifies it and exchanges it for the offline access credentials required for the scopes approved by the merchant. Integration credentials are encrypted at rest. The embedded connection flow is designed not to depend on third-party cookies inside the Shopify Admin iframe.

TopOMS receives and validates Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact. We use them to locate, provide, erase, anonymize, or remove covered Shopify data as applicable, in accordance with the merchant’s instructions, Shopify’s requirements, and legal retention duties. Privacy webhooks are not used for advertising.

6. Service providers, couriers, and disclosures

We do not sell customer personal data. We disclose data only where needed to provide or protect the service, follow the merchant’s instructions, or comply with law. Recipients may include:

  • hosting, storage, backup, database, security, monitoring, and communication providers that support TopOMS;
  • couriers, fulfillment providers, and other merchant-selected integrations that need recipient and shipment details to perform the requested service;
  • Shopify and other connected channels when synchronizing merchant-authorized operations;
  • professional advisers, auditors, or public authorities where disclosure is lawfully required; and
  • a successor in a corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

Processors and subprocessors are required to protect personal data and use it only for the contracted purpose. Current subprocessor information can be requested through the TopOMS support channel available in the account or on the website from which this policy was accessed.

7. International data transfers

TopOMS serves merchants in Serbia and the European Economic Area. A service provider or connected integration may process data in another country. Where data is transferred across borders and the law requires safeguards, the responsible TopOMS contracting party uses an approved transfer mechanism, such as an adequacy decision or contractual safeguards, together with supplementary protections where appropriate.

8. Retention and deletion

TopOMS keeps personal data only for as long as necessary for the purposes described above, the merchant’s documented instructions, contractual commitments, dispute handling, and applicable legal obligations.

  • Raw source payloads received with channel orders may contain customer PII. TopOMS retains those raw payloads for 12 months from the order’s creation, after which the payload is replaced with a redaction marker.
  • Operational order data may be retained separately where the merchant needs it for fulfillment, accounting, fraud prevention, legal claims, or other lawful business requirements.
  • Integration credentials are retained while the store remains connected and are removed or invalidated when they are no longer needed, subject to secure backup cycles and compliance obligations.
  • Logs, backups, and support records are retained for limited periods appropriate to security, recovery, support, and legal needs.

For customer records TopOMS acts on the merchant’s documented instructions. While a store remains connected and the merchant’s TopOMS agreement is active, customer records are retained for as long as the merchant needs them to run the business — order fulfillment, customer service, returns, warranty and complaint handling, accounting, and fraud prevention. TopOMS does not anonymize a merchant’s live customer records on a fixed schedule, because doing so would destroy records the merchant is still lawfully using and, in part, legally required to keep.

Customer personal data is deleted or anonymized when any of the following happens:

  • Shopify sends a verified customers/redact request for that customer, or the merchant or the person concerned submits a valid erasure request.
  • Shopify sends a verified shop/redact request, or the store is disconnected from TopOMS — the store’s data is then erased, and customer records that exist only for that store are anonymized.
  • The merchant’s TopOMS agreement ends — customer personal data is anonymized or deleted within 90 days of the end of the agreement, once any final export the merchant has asked for has been provided.

Records that law requires TopOMS or the merchant to keep — invoices, accounting documents, tax records, and evidence needed to defend a legal claim — are kept for the period the applicable law prescribes and are deleted once that period expires. Where an order cannot be deleted because fulfillment, accounting, or dispute records depend on it, TopOMS removes the personal data from that order instead of the order itself: names, addresses, email addresses, phone numbers, delivery notes, and shipping-label data are erased, and only non-identifying references, statuses, and amounts remain.

A verified Shopify erasure request or a valid data-subject request may require earlier deletion or anonymization, unless retention is required or permitted by law.

9. Your data-protection rights

Subject to the GDPR, Serbian data-protection law, and other applicable law, a person may have rights to access, correct, erase, or restrict personal data; receive portable data; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. A person may also complain to the competent data-protection authority.

Shopify customers should normally submit a request to the merchant from whom they purchased, because that merchant controls the order and customer data. The merchant can then use the applicable Shopify privacy process or contact TopOMS so we can assist. TopOMS users may submit requests through the support channel shown in their account or on the website from which this policy was accessed. We may need to verify identity and authority before acting on a request.

10. Security

TopOMS uses administrative, technical, and organizational safeguards appropriate to the nature of the data and risk, including access controls, encrypted integration credentials, protected transport, tenant separation, logging, and backup and recovery measures. No internet service can guarantee absolute security. Merchants should promptly report suspected unauthorized access through their TopOMS support channel.

11. Changes to this policy

We may update this policy when the service, subprocessors, or legal requirements change. The date above identifies the latest version. Where required, we will provide additional notice of material changes through TopOMS or the merchant’s registered contact channel.

12. Contact

For privacy questions, requests, or complaints, contact TopOMS using the support or contact channel displayed in your TopOMS account or on the TopOMS website from which you accessed this policy. Your service agreement or order form identifies the responsible TopOMS contracting party and its formal contact details.