Privacy policy
Last updated 8 October 2026
Wholora (“we”, “us”) is a Shopify app operated by XI NENG CHAN. This policy explains what information the app processes when a merchant installs it and when the merchant's customers submit a wholesale application. For data that buyers submit, the merchant is the controller and we act as a processor on the merchant's behalf.
Information we process
- Store information: shop domain, store name, contact email, currency and the plan you choose. Session tokens needed to call the Shopify API on your behalf.
- Staff information: the name or email of the staff member who approves or rejects an application, recorded for your audit trail.
- Wholesale applications: the details a buyer enters in your application form, such as company name, contact name, business email, phone, address, tax/VAT number and answers to your questions.
- B2B credit and order balances: for orders placed by B2B companies — on the Pro plan for every company location, on other plans only for the company locations you set a credit limit for — we store the order ID, order name, company and location names and IDs, the credit limit you set, the outstanding amount, due date and payment status. We do not store line items, card details or payment credentials.
How we use it
- To show applications to you and create B2B companies in your Shopify store when you approve them.
- To check EU VAT numbers against the European Commission's VIES service when you enable it.
- To calculate outstanding balances and enforce the credit limits you set.
- To send the notification emails you turn on (to you, or to applicants about your decision).
- To provide support, keep the service secure and meet legal obligations.
We do not sell personal information, use it for advertising, or share it with data brokers.
Service providers
We use a small number of providers to run the app, each bound by data protection terms:
- Shopify (platform, billing and data you already hold in Shopify).
- Our cloud hosting and managed database providers, which store data in encrypted form.
- Resend, for transactional email, only if email notifications are enabled.
- The European Commission VIES service, which receives VAT numbers for validation.
Retention and deletion
Applications and balances are kept while the app is installed so you can review them, with these exceptions: on plans without the receivables report, a company location's order balances are deleted when you remove its credit limit or when the location (or its company) is deleted in Shopify, and when you move to such a plan the balances of every location without a credit limit are deleted. With the receivables report, the balances of a deleted company location are kept for that report, since its unpaid orders are still owed. When you uninstall, Shopify sends us a deletion request 48 hours later and we permanently delete all data for your store. We also delete a buyer's data when Shopify forwards a customer redaction request, and provide data on request through Shopify's customer data request process.
Security
Data is transmitted over HTTPS, access to production systems is restricted, and requests from Shopify are verified with HMAC signatures or session tokens.
Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA) you may have the right to access, correct, delete or export personal data, and to object to processing. Buyers should contact the store they applied to; merchants can contact us directly.
Contact
Questions or requests: support@wholora.app.