Pallet — Privacy Policy

Last updated: August 8, 2026

Pallet ("we", "our", "us") is a Shopify app that provides B2B and wholesale pricing, and team/group ordering functionality (the "Ensemble" plan) to Shopify merchants.

What Data We Collect

We collect the minimum data necessary to provide wholesale pricing functionality: customer email addresses (to identify wholesale customers), customer names (to display in the merchant's admin dashboard), customer tags (to determine wholesale group membership), and wholesale registration form submissions (company name, contact name, email, and optionally phone, tax ID, and message).

We do NOT collect payment information, browsing history, IP addresses, cookies, or any data beyond what is listed above.

Team Ordering Data (Ensemble Plan)

For merchants using our Ensemble plan, the app collects end-user information — such as individual names, sizes, jersey numbers, and custom text — submitted through shared, public order links. We collect this data solely on behalf of the merchant, to compile a single aggregated order for the merchant to fulfil.

We do NOT use this data for marketing, advertising, tracking, or profiling. This data is retained only while needed to provide the service and is deleted when the merchant uninstalls the app (see Data Retention below).

How We Use Data

Customer data is used exclusively to identify which customers belong to which wholesale pricing groups, apply correct wholesale discounts at checkout, process wholesale registration applications, and display wholesale customer information in the merchant's admin dashboard.

We do NOT sell, share, or transfer customer data to any third parties. We do NOT use customer data for marketing, advertising, or profiling.

Data Protection Roles (GDPR & UK GDPR)

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the Merchant acts as the Data Controller for all customer, wholesale registration, and team-member data collected through the app. Pallet acts strictly as the Data Processor, processing this data only on the Merchant's instructions.

The Merchant is solely responsible for ensuring they have a valid legal basis — including obtaining any consent required by local law — to collect individual team-member names and details via the shared Ensemble ordering links.

Data Storage and Security

All data is stored in a PostgreSQL database with encryption at rest. All data transmission uses HTTPS (TLS 1.2+). Access to production data is limited to the app developer. Test and production environments are kept separate.

Data Retention

Customer and team-member data is retained only while the merchant's app is installed. When a merchant uninstalls Pallet, all shop data — including wholesale records and all Ensemble campaigns and team-member submissions — is deleted within 48 hours via Shopify's mandatory shop/redact webhook. Individual customer data is deleted upon request via Shopify's customers/redact webhook.

Merchant Rights

Merchants can view all stored customer data through the Pallet admin dashboard, delete individual registration records at any time, and uninstall the app to trigger deletion of all stored data.

Customer Rights

Customers can request data access or deletion through the merchant, which Shopify forwards to us via mandatory compliance webhooks. We respond to all data requests within 30 days.

Contact

For privacy questions or data requests, contact: contact@pallet-b2b.com

Changes

We may update this policy from time to time. Changes will be posted at this URL with an updated "Last updated" date.

← Back to Pallet