Last updated: August 8, 2026
Pallet ("we", "our", "us") is a Shopify app that provides B2B and wholesale pricing, and team/group ordering functionality (the "Ensemble" plan) to Shopify merchants.
We collect the minimum data necessary to provide wholesale pricing functionality: customer email addresses (to identify wholesale customers), customer names (to display in the merchant's admin dashboard), customer tags (to determine wholesale group membership), and wholesale registration form submissions (company name, contact name, email, and optionally phone, tax ID, and message).
We do NOT collect payment information, browsing history, IP addresses, cookies, or any data beyond what is listed above.
For merchants using our Ensemble plan, the app collects end-user information — such as individual names, sizes, jersey numbers, and custom text — submitted through shared, public order links. We collect this data solely on behalf of the merchant, to compile a single aggregated order for the merchant to fulfil.
We do NOT use this data for marketing, advertising, tracking, or profiling. This data is retained only while needed to provide the service and is deleted when the merchant uninstalls the app (see Data Retention below).
Customer data is used exclusively to identify which customers belong to which wholesale pricing groups, apply correct wholesale discounts at checkout, process wholesale registration applications, and display wholesale customer information in the merchant's admin dashboard.
We do NOT sell, share, or transfer customer data to any third parties. We do NOT use customer data for marketing, advertising, or profiling.
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the Merchant acts as the Data Controller for all customer, wholesale registration, and team-member data collected through the app. Pallet acts strictly as the Data Processor, processing this data only on the Merchant's instructions.
The Merchant is solely responsible for ensuring they have a valid legal basis — including obtaining any consent required by local law — to collect individual team-member names and details via the shared Ensemble ordering links.
All data is stored in a PostgreSQL database with encryption at rest. All data transmission uses HTTPS (TLS 1.2+). Access to production data is limited to the app developer. Test and production environments are kept separate.
Customer and team-member data is retained only while the merchant's app is installed. When a merchant uninstalls Pallet, all shop data — including wholesale records and all Ensemble campaigns and team-member submissions — is deleted within 48 hours via Shopify's mandatory shop/redact webhook. Individual customer data is deleted upon request via Shopify's customers/redact webhook.
Merchants can view all stored customer data through the Pallet admin dashboard, delete individual registration records at any time, and uninstall the app to trigger deletion of all stored data.
Customers can request data access or deletion through the merchant, which Shopify forwards to us via mandatory compliance webhooks. We respond to all data requests within 30 days.
For privacy questions or data requests, contact: contact@pallet-b2b.com
We may update this policy from time to time. Changes will be posted at this URL with an updated "Last updated" date.