ForbindeOperations

Legal

Privacy Policy

Last updated September 3, 2026

Forbinde (“we”, “us”) is a commerce operations bridge. Merchants connect storefronts (for example Shopify, Wix, or BigCommerce) and shipping or warehouse destinations (for example LumaSwift) so we can quote rates, purchase shipping labels, route optional warehouse fulfillment, and write tracking back to the store.

This policy explains what we collect through marketplace installs and our operator console at app.forbinde.com. It is written for marketplace listing and merchant trust. It is not a substitute for legal advice.

1. Who this covers

  • Merchants / operators who create a Forbinde workspace, install our app, or sign in to the console.
  • End customers of merchants whose order, shipping, and contact details appear on orders we process for the merchant.

2. Information we collect

From storefront APIs and OAuth / install flows

  • Store metadata (name, domain, store or site identifiers, granted scopes)
  • OAuth access tokens (encrypted at rest) needed to call the storefront APIs
  • Order data: line items, payment and fulfillment status, customer name and email, shipping and billing addresses
  • Product / catalog and inventory data used for mapping and optional warehouse sync
  • Shipment and tracking data we write back to the store

From merchants directly

  • Account name, email, and password (password stored hashed)
  • Destination credentials you paste (API keys, warehouse IDs, ship-from address) for rate quotes and labels
  • Support messages you send to us

Automatically

  • Operational logs (organization id, integration ids, order ids, error codes) — not full payment card data
  • Session cookies for signed-in operators

We do not intentionally collect payment card numbers. Checkout payments stay on the storefront.

3. How we use the information

  • Authenticate installs and keep storefront connections working
  • Import and normalize orders; hold or send them according to your connection settings
  • Obtain live shipping quotes and purchase labels when you use the labels path
  • Optionally create warehouse / WMS orders when you opt into warehouse fulfillment
  • Write fulfillment and tracking back to the storefront
  • Provide the operator console, billing gates where applicable, support, security, and abuse prevention

We do not sell personal information.

4. Sharing / subprocessors

We share data only as needed to run the product:

  • Connected destinations you choose (for example LumaSwift) receive ship-from / ship-to addresses, parcel details, and order references required for quotes, labels, or warehouse fulfillment
  • Storefront platforms (Shopify, Wix, BigCommerce, etc.) receive fulfillment / tracking updates we push back
  • Infrastructure providers that host our application, database, and logs (for example our cloud VPS and related services)

We may disclose information if required by law or to protect the security of the service.

5. Retention

  • OAuth tokens and live connection credentials: until you disconnect, uninstall, or we purge the integration
  • Orders and related operational history: retained for fulfillment history; events are purged on a retention schedule (default about 90 days for integration events)
  • Privacy / compliance audit records: retained as needed to show we handled a request
  • Operator accounts and sessions: until you delete the account or sessions expire

6. Marketplace privacy / uninstall behavior

  • Shopify: we acknowledge GDPR compliance webhooks (customers/data_request, customers/redact, shop/redact) and app/uninstalled
  • BigCommerce: uninstall and remove-user callbacks revoke access; merchants can also request customer export / redact via our authenticated privacy API
  • Wix: disconnect / uninstall clears connection credentials; contact support for customer data requests

7. Security

Access tokens are encrypted at rest. Production traffic uses HTTPS. Access to operator data is limited to authenticated workspace members. No method of transmission or storage is perfectly secure; contact us if you suspect a breach involving Forbinde.

8. International transfers

We may process and store information in the United States or other countries where our hosting providers operate. If you are in the EEA/UK, contact us about your rights (access, correction, deletion, restriction, portability, and objection where applicable).

9. Children

Forbinde is a B2B operations product. It is not directed to children under 16.

10. Contact

Privacy questions and data requests: forbinde@protonmail.com

Related: Terms of Service · Support

Questions? forbinde@protonmail.com