Last updated July 15, 2026

Privacy Policy

This policy describes how EIL Dropship Hub handles information when an authorized merchant installs or uses the Shopify app and its connected operations portal.

Who provides the service

Boreal Meridian Commerce Inc. owns and provides the software, is the legal Shopify App Store publisher, and is the charging entity for app subscriptions processed through Shopify App Pricing. ExpandOcean International Limited is a licensed business user and operates the connected EIL catalog, supplier, settlement, fulfillment, tracking, and return workflows.

The applicable merchant agreement identifies the parties' data-protection roles for a particular store.

Information we process

We process the merchant store domain, Shopify authorization and scope status, app plan and subscription state, install generation, privacy-request status, and minimized security and operational receipts.

To provide merchant operations, the app can process Shopify order and line-item details, product and inventory references, amounts and currency, financial and fulfillment state, customer and shipping contact details such as name, postal address, email address, and phone number, supplier-work references, tracking details, returns and supporting media, supplier-charge and settlement status, and related notifications.

The app does not collect a buyer's card or bank credentials. An app subscription is approved and billed through Shopify App Pricing. Any separately configured supplier settlement uses only the provider and commercial flow approved for that merchant.

How information is used

  • Connect and authenticate the merchant store.
  • Import, review, search, and reconcile eligible Shopify orders.
  • Create durable EIL supplier work and report fulfillment status.
  • Display supplier charges and supported settlement status.
  • Synchronize tracking and manage return requests and evidence.
  • Prevent duplicate, stale, cross-tenant or uncertain mutations.
  • Protect the service, diagnose failures, and retain minimized receipts.
  • Meet legal, privacy, fraud-prevention, and contractual obligations.

Service providers and disclosure

Information may be shared with Shopify, Boreal, EIL, and approved infrastructure, database, security, fulfillment, tracking, return-media, and settlement providers only as needed for the enabled services, privacy requests, or legal obligations. Provider-dependent functions remain unavailable unless the exact merchant, provider, and service configuration is approved and ready.

We do not sell merchant or customer personal information and do not use order data for third-party advertising.

Retention and deletion

Operational records are retained only for documented service, dispute, security and legal needs. Shopify privacy and uninstall webhooks are used for customer data requests, customer redaction, shop redaction and credential revocation. A request that requires verified external-object or backup handling remains action-required until that work is completed; it is not falsely marked delivered or deleted. Records subject to a legal obligation are minimized and access-restricted; other covered information is deleted or irreversibly anonymized under the applicable process.

Security and choices

Shopify access credentials are kept server-side and protected by restricted access, credential-generation, install-generation, tenant, and privacy-state checks. Production release controls require protected credential storage and block the service when required security evidence is missing.

Merchants can manage their app subscription through Shopify, uninstall the app through Shopify, and contact support about access, correction, export, or deletion requests.