Legal
Privacy policy
What Wharfly collects, why, who sees it and when it is deleted.
The short version
- Wharfly reads your products, inventory, locations and orders from Shopify, and keeps what you enter: suppliers, purchase orders, shipments, invoices, payments and your team.
- From orders, Wharfly reads only the order ID, creation date, whether it was cancelled, and each line item's quantity and variant ID, and keeps only the units sold for each product each day. It never reads customer details or order totals.
- We do not sell data. We do not use your data for advertising. AI features are not live and your data is not sent to any AI provider.
- This website sets no cookies and uses no analytics or tracking scripts.
- An admin can delete all of a store's data at any time in Settings. When you uninstall, sign in sessions are removed straight away and everything else is deleted about 48 hours later.
- To ask us anything about your data, email support@wharfly.app.
1. Who we are
Who operates Wharfly. Wharfly is a brand operated by Hunain Khatri, an individual trading as Wharfly, based in Malaysia. Wharfly is not yet a registered company. On this page, "we" means Hunain Khatri operating Wharfly.
This policy covers the Wharfly app for Shopify and this website, wharfly.app. You can reach us at support@wharfly.app.
For the merchant data described below, the merchant decides what goes into Wharfly and we handle it on the merchant's behalf to provide the service.
2. What we collect from Shopify
When a merchant installs Wharfly and approves its permissions, we receive data from the merchant's Shopify store. The permissions are read locations, read orders, write inventory and write products. We collect:
- Store details: the store's .myshopify.com address.
- Sign in details: the access tokens Shopify issues so Wharfly can work with the store, for the store and for each staff member who opens the app. For each staff member we also keep the name, email address, Shopify user ID, language setting and whether they are the account owner, which Shopify provides when they sign in.
- Products and inventory: products and variants with their titles, SKUs and costs, stock levels and locations. Wharfly also keeps a daily record of total stock value, units on hand and the number of products at risk, taken on each day the Home screen is opened, so it can compare with earlier periods.
- Shop settings: the store's currency and time zone.
- Sales, for demand planning: From each order Wharfly reads only the order ID, creation date, whether it was cancelled, and each line item's quantity and variant ID. It never reads customer details or order totals. From that Wharfly keeps the units sold for each product on each day. Shopify shares the last 60 days of orders, and Wharfly keeps those daily totals so older history builds up over time.
Wharfly does not store the names, email addresses, phone numbers or postal addresses of a merchant's customers.
Wharfly also writes to the store, only when a merchant asks it to: it adds received stock to inventory, it creates a product from a purchase order line for a new item and sets its price, and it creates and later removes demo products when a merchant adds or removes sample data.
3. What merchants enter into Wharfly
- Suppliers: names, categories, email addresses, phone numbers, addresses, payment terms and lead times. These can include personal data about the people at a supplier.
- Purchase orders: lines, quantities, costs, notes, approvals, receiving records and their history, including the names of the people who created or approved them.
- Shipments: carriers, tracking numbers, tracking links, shipped and delivered dates and notes.
- Accounting: supplier invoices, payments, deposits, journal entries and a chart of accounts.
- Team settings: each person's role, approval limit and whether they are active, and the store's self approval threshold.
4. What we do not collect
- Payment card numbers or bank details. Paid plans will be charged through your Shopify bill.
- Your customers' personal details, as explained above.
- Advertising identifiers, or data for profiling or advertising. We do not sell merchant data or customer data.
The Wharfly app does not include advertising or analytics trackers. Wharfly sets no cookies. Shopify's own libraries may set technical cookies needed to sign you in inside your Shopify admin.
5. This website
The website at wharfly.app sets no cookies and uses no analytics, advertising or tracking scripts. Its fonts and images are served from the site itself, not from third parties. The contact form does not send anything from the site: it opens your own email app with a message for you to send.
Like any website, it is delivered by a hosting provider, Cloudflare, which processes visitors' IP addresses and basic request information to deliver and protect the site.
6. How we use data
- To provide Wharfly: demand planning, purchase orders, approvals, shipments, suppliers and accounting.
- To keep the app secure, prevent misuse, and find and fix problems. Our servers keep logs of request paths, status codes and the store's .myshopify.com address for a limited time.
- To answer support requests and privacy requests.
- To meet legal obligations.
Where the law asks for a legal basis, ours are providing the service the merchant asked for, our legitimate interest in running and securing it, and legal obligations. Depending on where you live, laws such as the GDPR or Malaysia's Personal Data Protection Act 2010 may give you rights described below.
7. Who we share data with
We do not sell data. We use a small number of service providers to run Wharfly, and they may handle data only to provide their service to us:
| Provider | What it does |
|---|---|
| Shopify | The source of store data and the place Wharfly writes to on your request. Shopify also handles sign in, and will handle plan billing once paid plans launch. |
| Railway | Hosts the Wharfly app and its Postgres database, where merchant data is stored, in the United States (US West, California). |
| Cloudflare | Hosts this website, and forwards email sent to support@wharfly.app to our mailbox through Email Routing. |
Wharfly does not send email itself. When you email a purchase order to a supplier, Wharfly prepares the message and your own email app sends it.
We may also disclose data if the law requires it, or to protect our rights, safety or the security of the service.
8. AI features
AI features are not live. Wharfly does not send your data to any AI provider today. Before any AI feature launches, we will update this policy to name the provider and explain what data is sent, and the feature will not run before then.
9. How long we keep data, and deletion after uninstall
- We keep a merchant's data while Wharfly is installed on their store.
- A merchant can also delete all of their Wharfly data at any time in the app, under Settings, Delete all data, after typing the store address to confirm. CSV export is available beforehand.
- What Delete all data removes: it permanently deletes the suppliers, purchase orders, shipments, bills, payments, ledger entries, sales history and team roles Wharfly holds for the store, while the app stays installed. It cannot be undone. Shopify products, orders and customers are not affected, apart from the demo products that sample data creates, which are removed.
- When a merchant uninstalls, Wharfly removes all saved sign in sessions for the store straight away.
- About 48 hours after uninstall, Shopify sends Wharfly a store data erasure notice. When it arrives, Wharfly deletes all other data it holds for the store: suppliers, purchase orders, shipments, invoices, payments, journal entries, accounts, sales history, stock history, team members and settings.
- Changes already made in the Shopify store, such as stock added when goods were received, stay in Shopify. Demo products created by sample data remain in the store unless sample data was removed in the app first.
- Backups held by our hosting provider, if any, age out under the provider's own schedule.
- We keep emails about support and privacy requests for as long as we need them to deal with the request and to show we did.
10. Requests about a merchant's customers
Shopify passes customer data requests and customer erasure requests to apps. Wharfly receives these notices, and because it does not store customer personal data, there is nothing to return or erase. If you are a customer of a Wharfly merchant, please contact that merchant.
11. Security
Wharfly is served over encrypted connections. Every request is authenticated with Shopify's signed session tokens, and Shopify's webhook notices are verified before we act on them. Each store's data is kept separate from every other store's, and actions such as approving or cancelling purchase orders and deleting data are limited by role. Merchant data is stored in an encrypted database volume at our hosting provider. No system is perfectly secure, so we cannot promise absolute security.
12. Where data is stored, and international transfers
Merchant data is stored in a managed PostgreSQL database. The Wharfly app database is hosted by Railway in the United States (US West, California). If you are outside the United States, using Wharfly means your data is processed there.
We operate from Malaysia, and Shopify and Cloudflare run servers in several countries, so data may also be handled in a country other than the one where you or we are based. Where the law requires safeguards for this, we rely on the safeguards our providers offer.
13. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a copy of it, and complain to your data protection authority.
To use a right, email support@wharfly.app from an address you use with your store, say what you would like us to do, and include your store's .myshopify.com address. We may need to confirm who you are first. We aim to reply within 24 hours on business days.
If you work at a supplier that a merchant has added to Wharfly, the merchant decided to add your details, so the quickest route is usually to ask them. You can also write to us.
14. Children
Wharfly is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data about children.
15. Changes to this policy
We may update this policy. We will post the new version here with a new date at the top, and for material changes we will take reasonable steps to tell merchants.
16. Contact
Questions or requests: support@wharfly.app. You can also use the contact page.