Legal
Privacy Policy
Europa Foundry (“Europa Foundry,” “we,” “us,” or “our”) operates PO Autopilot and the Europa Foundry website at europafoundry.com. Europa Foundry is based in Denver, Colorado, United States.
This Privacy Policy explains what information we process, why we process it, how long we retain it, the service providers we use, and the choices available to merchants and individuals whose information may be processed through PO Autopilot.
1. Our approach to privacy
PO Autopilot is built to process business orders, not to collect data for its own sake.
We aim to collect, use, and retain only the information reasonably necessary to provide, secure, and support the service.
We do not:
- sell merchant, buyer, or personal information;
- use merchant or buyer information for advertising;
- share merchant or buyer information for cross-context behavioral advertising;
- build advertising or behavioral profiles from merchant or buyer information;
- use merchant or buyer order content to train Europa Foundry models;
- opt merchant or buyer content into third-party AI model-training programs; or
- embed general-purpose behavioral analytics inside PO Autopilot.
2. Information PO Autopilot processes
Shopify store information
When a merchant installs or uses PO Autopilot, we process Shopify information needed to provide the service. Depending on the features being used, this may include:
- Shopify shop identifiers and shop domain;
- installation, authorization, subscription, and billing status;
- Shopify B2B companies and company locations;
- relevant company contacts;
- products, variants, SKUs, and Shopify identifiers;
- price lists and pricing information;
- inventory information;
- draft-order and order information;
- shipping or billing addresses when needed to match or verify an order; and
- other Shopify information reasonably necessary to match, validate, review, or create an order.
We do not intentionally request Shopify data that PO Autopilot does not need.
Order information provided to PO Autopilot
Merchants and their buyers may provide order information through:
- uploaded files;
- emailed attachments;
- orders written directly in an email body;
- the in-app Describe order feature; or
- other supported order-intake methods.
Supported inputs may include PDFs, Excel or XLSX files, CSV files, TXT files, images, and scanned documents.
These materials may contain information such as:
- buyer or company name;
- contact information;
- purchase-order numbers;
- product descriptions;
- buyer-specific SKUs;
- quantities;
- units of measure;
- case-pack information;
- prices;
- shipping or billing addresses;
- delivery instructions;
- order notes; and
- other information included by the sender.
Merchants are responsible for ensuring they have the right to provide information submitted to PO Autopilot.
Information created through PO Autopilot
As an order is processed, PO Autopilot may create and retain structured information such as:
- extracted order fields;
- Shopify company and location matches;
- product and variant matches;
- buyer-specific SKU mappings;
- UOM and case-pack mappings;
- merchant-approved mappings;
- discrepancies and items requiring review;
- duplicate-PO indicators;
- review decisions;
- Shopify draft-order references; and
- usage information needed to administer plan limits.
Support information
If you contact Europa Foundry for support, we may receive:
- company name;
- your name;
- email address;
- Shopify store URL;
- support topic;
- the contents of your message; and
- other information you choose to provide.
Please do not send passwords, API keys, payment-card information, or unnecessary full order documents through the support form.
Technical and security information
Our systems and service providers may process limited technical information needed to operate, troubleshoot, and secure the service, such as:
- IP address;
- timestamps;
- browser or device information;
- authentication and authorization events;
- application errors;
- request metadata; and
- security events.
We do not use this information for advertising or behavioral profiling.
3. Information from buyers and other individuals
PO Autopilot is primarily an administrative Shopify application. We do not place advertising trackers on merchant storefronts and do not use storefront scripts to monitor how shoppers browse a merchant’s store.
Information about a merchant’s buyers or contacts is generally received from:
- an order submitted to the merchant;
- the merchant directly; or
- Shopify, when needed to process the merchant’s orders.
For personal information submitted through a merchant’s use of PO Autopilot, we generally process that information to provide the service to that merchant.
4. How we use information
We use information only as reasonably necessary to:
- receive and interpret B2B orders;
- identify the appropriate Shopify B2B company and location;
- match buyer SKUs, products, variants, quantities, and units;
- apply and remember merchant-approved mappings;
- compare order information with Shopify data;
- identify missing, inconsistent, or ambiguous order details;
- perform supported checks involving pricing, quantities, units, shipping addresses, inventory, and duplicate POs;
- prepare and create Shopify draft orders;
- provide source-document access during the applicable retention period;
- authenticate merchants and operate their accounts;
- administer subscription plans and usage limits;
- provide support;
- troubleshoot and investigate errors;
- protect the service against fraud, abuse, and security threats;
- comply with applicable law and Shopify requirements; and
- establish, exercise, or defend legal claims when reasonably necessary.
We do not repurpose merchant or buyer information for unrelated advertising, marketing profiles, data brokerage, or model training.
5. AI-assisted processing
PO Autopilot uses automated systems, including artificial intelligence, to help read documents and interpret plain-language order requests.
When AI processing is needed, relevant order content may be sent to the OpenAI API.
AI is used as an interpretation layer. Shopify data and merchant-approved rules remain authoritative for order processing. PO Autopilot is designed to bring unsupported, unclear, or inconsistent information to the merchant for review rather than invent order details.
Europa Foundry does not use merchant or buyer order content to train its own models and does not opt merchant or buyer content into third-party programs that use API content to train general-purpose models.
6. Service providers
We use a limited number of service providers to operate PO Autopilot and the Europa Foundry website.
Shopify
Shopify provides the commerce platform, APIs, authentication context, billing infrastructure, and store data used by PO Autopilot.
Amazon Web Services
We use Amazon Web Services (“AWS”) to host PO Autopilot application data and infrastructure.
AWS services used by PO Autopilot include Amazon S3 for private source-file storage and Amazon Textract for document processing. Other AWS services may be used to host the application, databases, encrypted backups, logs, and supporting infrastructure.
OpenAI
We use the OpenAI API when AI-assisted interpretation is needed. We send only information reasonably necessary to perform the relevant processing request.
Zoho Mail
We use Zoho Mail for inbound order email and business/support email. Email headers, message bodies, attachments, and related metadata may therefore be processed by Zoho when an order or support request is sent by email.
Cloudflare
We use Cloudflare for website delivery, security, and portions of our website infrastructure. The Europa Foundry support form uses Cloudflare Turnstile to help prevent automated abuse.
Google Analytics
We use Google Analytics 4 to understand traffic and interactions with the PO Autopilot listing in the Shopify App Store.
Google Analytics is not embedded inside PO Autopilot itself. We do not currently use general-purpose behavioral analytics inside the PO Autopilot application.
We configure user-level and event-level data retention for this App Store analytics property to two months where that setting applies.
We may change service providers as the service evolves. If a change materially affects how personal information is processed, we will update this Privacy Policy.
7. Data retention
We apply retention periods so that information is not kept longer than reasonably necessary for the purposes described in this policy.
Original order files
Original uploaded or emailed order files are stored in private, app-controlled AWS storage for no more than 90 days.
An automated storage lifecycle serves as a backstop so source files are deleted no later than 90 days after they are stored.
A source file may be deleted earlier when:
- the merchant deletes the associated order;
- deletion is required by a valid privacy request;
- the merchant uninstalls PO Autopilot and the applicable store-deletion process occurs; or
- the file is otherwise no longer necessary to provide the service.
PO Autopilot is not intended to serve as permanent document storage.
Temporary and failed-processing artifacts
Temporary files and failed-processing artifacts are deleted within 24 hours.
Structured order data
Structured and extracted information associated with an order is retained while that order remains in PO Autopilot.
When a merchant deletes an order, we delete the structured order data associated with that order, subject to limited information that must be retained for legal, security, or compliance purposes.
Remembered mappings and merchant configuration
Merchant-approved buyer SKU mappings, UOM and case-pack mappings, Shopify references, and similar reusable configuration may remain after an individual order is deleted because they are part of the merchant’s ongoing PO Autopilot configuration.
These mappings are retained until the merchant removes or replaces them, they are no longer necessary, or the merchant’s remaining PO Autopilot data is deleted following uninstall or an applicable privacy request.
Operational and security logs
Routine operational logs are retained for no more than 90 days.
Limited records may be retained longer when reasonably necessary to investigate a security incident, prevent fraud or abuse, comply with law, or establish or defend legal claims.
Support correspondence
Support correspondence is generally retained for up to 12 months after the support matter is resolved.
It may be retained longer when reasonably necessary for an ongoing security matter, legal requirement, or dispute.
Backups and disaster recovery
Encrypted backups and disaster-recovery copies containing application data are retained for no more than 35 days.
Backups are used for recovery and continuity purposes, not as a separate archive of deleted merchant data. Information deleted from active systems may remain in an encrypted backup until that backup expires through its normal lifecycle.
If a backup is restored for disaster recovery, applicable deletion requests and retention rules are reapplied to the restored data.
Billing, tax, and legal records
Limited transaction, accounting, tax, security, or legal records may be retained longer when required by law or reasonably necessary to establish or defend legal rights.
8. Order deletion and app uninstall
Merchants can delete order records from PO Autopilot. Deleting an order removes the associated structured order data and any still-retained source file, except for limited information that must be retained for legal, security, or compliance reasons.
Approved reusable buyer mappings are treated as merchant configuration and are not automatically deleted merely because one order that helped create the mapping is deleted.
When a merchant uninstalls PO Autopilot, we respond to Shopify’s required store-redaction process by deleting the merchant’s remaining PO Autopilot data unless applicable law requires us to retain specific information.
We also respond to applicable Shopify customer data-access and customer-redaction requests.
Our policy is to complete applicable deletion and redaction requests promptly rather than retain information for the maximum period permitted.
9. Privacy rights and requests
Depending on applicable law, individuals may have rights concerning their personal information, including rights to:
- request access;
- request correction;
- request deletion;
- request restriction of certain processing;
- object to certain processing; or
- receive information about how their personal information is processed.
Merchants
Merchants may contact Europa Foundry directly about information associated with their PO Autopilot account or store.
Buyers and other individuals
If your information was provided to PO Autopilot through a Shopify merchant, contacting that merchant first is generally the most direct way to identify the relevant order or account.
You may also contact Europa Foundry directly. We may need information from the merchant or Shopify to verify and properly process the request.
We will not discriminate against an individual for exercising applicable privacy rights.
10. Data sales, advertising, and automated decisions
Europa Foundry does not sell merchant or buyer personal information.
We do not share personal information for cross-context behavioral advertising or targeted advertising.
We do not build advertising profiles from Shopify, purchase-order, or buyer data.
We do not use personal information processed through PO Autopilot to make automated decisions that produce legal or similarly significant effects on individuals.
11. Security
We use technical and administrative safeguards designed to protect information handled by PO Autopilot.
These safeguards include, where applicable:
- encryption in transit;
- encryption at rest;
- encrypted backups;
- private access controls for source documents;
- strong authentication for administrative access;
- separation of production and test environments;
- restricted human access to merchant and buyer information;
- access and security logging;
- automated retention and deletion controls; and
- procedures for responding to security incidents.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Human access to merchant information
Europa Foundry does not routinely inspect merchant order content.
Human access is limited to circumstances where it is reasonably necessary to:
- provide support;
- investigate an error;
- address a security incident;
- prevent fraud or abuse;
- comply with law; or
- operate the service where automated processing is insufficient.
Where practical, support-related access will occur at the merchant’s request or with the merchant’s knowledge.
Access is limited to authorized people with a legitimate need to access the information.
13. International processing
Europa Foundry is based in Denver, Colorado, United States.
Information may be processed in the United States and in other countries where our service providers operate. Those countries may have privacy laws that differ from the laws where the information originated.
Where applicable law requires safeguards for international transfers of personal information, we use available contractual or other legally recognized transfer mechanisms.
14. Website and analytics privacy
The Europa Foundry website does not currently use advertising trackers.
The Support page uses Cloudflare Turnstile for abuse prevention and sends support submissions through our email infrastructure.
We use Google Analytics only in connection with the PO Autopilot Shopify App Store listing as described above. Google Analytics is not embedded in the PO Autopilot application.
15. Payment information
PO Autopilot subscriptions are billed through Shopify.
Europa Foundry does not receive or store merchants’ full payment-card information for Shopify App Store subscriptions.
We may process subscription status, plan information, usage information, and related billing records needed to administer the service.
16. Sensitive information
PO Autopilot is designed for ordinary B2B order processing.
Merchants and buyers should not intentionally submit sensitive information that is unnecessary for an order, including:
- payment-card numbers;
- passwords or API keys;
- government identification numbers;
- medical or health information; or
- other highly sensitive personal information unrelated to order processing.
If unnecessary sensitive information is submitted, it will be handled according to the security and retention practices described in this policy.
17. Children
PO Autopilot is a business service intended for merchants and business users.
It is not directed to children, and Europa Foundry does not knowingly solicit personal information from children through PO Autopilot.
18. Changes to this policy
We may update this Privacy Policy as PO Autopilot, our infrastructure, or applicable requirements change.
When we make material changes, we will update the effective date or last-updated date and provide additional notice when required.
19. Contact
For privacy questions, requests, or concerns:
Europa Foundry
Denver, Colorado, United States
support@europafoundry.com
For security reports: