FulfillRelay

Privacy policy

Effective July 12, 2026. This policy explains how Boreal Meridian Commerce Inc. processes information when providing FulfillRelay.

Information we process

  • Shopify store, installation, subscription, and app-session data.
  • Order, line-item, fulfillment, tracking, return, and needs-attention data.
  • Order email used only to verify a customer who starts a return and deliver a short-lived access code.
  • Supplier organization, member email, invitation, and access data.
  • Encrypted shipping information needed for active fulfillment.
  • Support messages, audit records, and service-security events.

FulfillRelay does not store card numbers or operate a wallet. Supplier payment checkout is processed by Shopify and the supplier store's configured payment gateway.

How information is used

We use information to authenticate users, route eligible paid orders, coordinate supplier work, confirm tracking and payment evidence, handle returns, provide support, prevent abuse, meet privacy requests, and maintain an auditable service.

We do not sell customer data or use it for targeted advertising. Return-assistance features, when enabled and requested by a merchant, may process the customer's submitted evidence image plus minimized, redacted case text. OpenAI requests use storage disabled and return evidence summaries and suggestions for human review; they do not make automated decisions with legal or similarly significant effects.

Service providers

FulfillRelay uses Shopify for commerce and app billing, Vercel for application hosting, Neon for PostgreSQL hosting, Resend for service email, Clerk for employee-console authentication, and OpenAI only for merchant-enabled, minimized return-evidence assistance. Provider use is limited to operating the service.

Retention and deletion

Protected shipping data is scheduled for deletion 90 days after the latest eligible order ingestion. Customer return access stores a hashed email match and hashed one-time code rather than the plaintext order email. Support content and access tokens also use bounded retention periods. Shopify privacy webhooks are used for customer data requests and shop or customer redaction. Some audit and transaction-evidence records may be retained where needed for security, disputes, or legal obligations.

Your choices

Merchants can uninstall FulfillRelay through Shopify and can contact support@fulfillrelay.com about access, correction, deletion, or privacy questions. Shopify customers should normally contact the merchant that controls their order.

Security and international processing

We use tenant scoping, access controls, encryption in transit and at rest for protected fields, bounded credentials, audit records, and deletion controls. Service providers may process information in countries outside your own, subject to their contractual safeguards.