Last updated: July 10, 2026
Overview
ChronoBase Supplier ("the App") is a business-to-business (B2B) tool that lets a Shopify merchant connect their own wholesale supplier account, browse live wholesale catalog data, and import selected products into their own Shopify store as drafts. The App is designed for wholesale operations and does not collect, store, or process the personal data of a merchant's end customers.
Data we store
When you install the App and connect a supplier account, we store the following, scoped to your store:
| Data | Purpose | Protection |
|---|---|---|
Your .myshopify.com domain and installation status |
Identify your store and know whether the App is installed | Stored as-is |
| Shopify Admin API access token and granted scopes | Create and update products/inventory in your store on your behalf | Encrypted at rest (AES-256-GCM) |
| Your supplier account credentials | Fetch your live wholesale catalog, pricing, and stock | Encrypted at rest (AES-256-GCM) |
| Plan and subscription status | Apply the correct plan entitlements and billing state | Stored as-is |
| Supplier connectivity status (last check result and timestamp) and operational logs | Show whether your supplier connection is working and to troubleshoot the service | Business data — not personal data |
| Enriched product image URLs (paid image-enrichment add-on) | Preserve the product photos you spent a credit to find across reloads and include them when you import a product to Shopify | Business data (public image URLs) — not personal data |
| Image-enrichment credit balance, monthly allowance usage, and credit-transaction history | Track your remaining credits and provide an audit trail of grants, uses, and refunds for the paid add-on | Business data — not personal data |
Your wholesale catalog data (product names, brands, EANs, stock levels, wholesale/retail prices, and image references) is read live from your own supplier account each time you use the App. The embedded App does not keep a stored, per-store copy of your catalog; it is fetched on demand to display inventory and to let you import selected products into your Shopify store. The one exception is the paid image-enrichment add-on: when you enrich a product, the resulting public image URLs are saved (keyed to your store and the supplier product) so the images you paid a credit for persist across reloads and can be included when you import that product.
Customer personal data
The App does not read, request, or store any of your customers'
personal information. It requests only product and inventory permissions and never
accesses Shopify customer or order records. Because no customer data is held, the
mandatory customers/data_request and customers/redact
privacy requests have nothing to return or erase; the App acknowledges them as
required by Shopify.
How we use data
- To fetch your wholesale catalog and keep stock/price information current.
- To create and update products and inventory in your Shopify store when you choose to import a product.
- To apply your plan's entitlements and reflect your subscription status.
- To operate, secure, and troubleshoot the service (operational logs).
We do not sell your data or use it for advertising.
Third parties we share data with
To provide its features, the App exchanges data with the following services, only as needed:
| Service | What is sent | Why |
|---|---|---|
| Your wholesale supplier (dropshippingb2b.com) | Your supplier credentials and catalog requests | Retrieve your wholesale catalog, pricing, and stock |
| Shopify | Product and inventory data, billing status | Create/update products in your store and manage your subscription |
| Brave Search (optional image enrichment) | Product identifiers (brand, model, EAN) — no personal data | Find product photography for imported products |
| OpenAI (optional description generation) | Product attributes (brand, model, specs) — no personal data | Generate storefront-ready product descriptions |
Data retention and deletion
- When you uninstall the App, we immediately deactivate your store, blank the stored Shopify access token, delete your supplier credentials, and delete all image-enrichment data for your store (saved image URLs, credit balances, and the credit-transaction ledger).
- Shop data erasure (Shopify's
shop/redact, sent about 48 hours after uninstall) permanently deletes your store's remaining installation record and any remaining enrichment data. - You can also disconnect or replace your supplier credentials at any time from the App's settings.
Security
All traffic is served over HTTPS. Sensitive credentials (your Shopify access token and supplier credentials) are encrypted at rest. Inbound Shopify webhooks are verified by HMAC signature, and access to your store's data requires a valid, Shopify-issued session for your store.
Contact
Questions about this policy or your data? Contact us at help@tempuskronos.com.