WhichBox Privacy Policy
Last updated: July 6, 2026
WhichBox ("the app") helps merchants map product SKUs to physical storage locations (bins and boxes) and view those locations while fulfilling orders. This policy describes what information the app collects, why, and how it is handled.
Information the app collects
When installed on your store, the app stores:
- Store information — your myshopify.com domain and an API access token, required for the app to function.
- Box location data you create — SKU-to-box mappings and optional notes that you enter or import via CSV.
To display pick lists, the app reads open and recently fulfilled orders from your store (order numbers, line items, SKUs, and quantities). This order data is displayed in real time and is not stored by the app. The app does not collect, store, or process customer personal information such as names, email addresses, or shipping addresses.
How information is used
- To show box locations on orders and products in your admin.
- To group open orders into pick lists by box.
- To sync box locations to product variant metafields in your store (when you use "Sync All to Shopify").
Your data is never sold, shared with third parties, or used for advertising.
Data retention and deletion
- When you uninstall the app, your access token and all box location data are deleted automatically.
- The app honors Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact). Shop data is deleted within the required timeframe after a redaction request.
Data storage
App data is stored in a managed PostgreSQL database. Access is restricted to the app itself and transmitted over encrypted connections (HTTPS/TLS).
Contact
Questions or data requests: pillgates777@gmail.com