PayMatch Privacy Policy

Last updated: 1 August 2026

What we collect

PayMatch is a Shopify app that matches bank-transfer payments to orders. To provide the service we store:

We never query Shopify's Customer API directly and never request the read_customers scope — order-matching uses only the customer name already attached to each order object.

How we use it

Data is used solely to match uploaded bank transactions against your open orders and mark orders paid when you confirm a match. We never sell data or use it for advertising.

Where data lives

Data is stored on Cloudflare's global infrastructure (Pages and D1).

Retention and deletion

Bank-transaction and statement records are automatically deleted 90 days after they were created, whether or not you acted on them. Uninstalling the app deletes all stored data for your shop immediately. We honor Shopify's GDPR webhooks using the order-ID lists those webhooks include: customer-redaction requests delete transaction records matched to that customer's orders immediately, shop-redaction requests delete everything immediately, and data-request requests are forwarded to our support address so you can fulfil the request. Full detail: our security & data protection policy.

Contact

Privacy questions: use the support form. See also our security policy.

← Back to PayMatch