Virtual Shop Manager Privacy Policy
Effective September 2, 2026 | Last updated September 12, 2026
Plain-language summary: Virtual Shop Manager LLC ("VSM," "we," "us," or "our") uses only the information reasonably needed to operate the service, connect each merchant's Shopify store, provide inventory and buylist tools, secure the service, and support users. We do not sell personal information or use it for third-party targeted advertising.
1. Scope and roles
This Policy explains how VSM collects, uses, discloses, retains, and protects information through the VSM website, Shopify app, merchant workspace, support channels, and public buylist tools (collectively, the "Service").
For merchant and account information collected directly by VSM, VSM determines why and how the information is used. For personal information a merchant directs VSM to process through Shopify or a merchant's public buylist, the merchant generally determines the purpose of that processing and VSM acts as the merchant's service provider or processor. Individuals may contact the applicable merchant or VSM about that information.
2. Information we collect
Merchant and account information. We may collect a business name, contact name, contact email, Shopify store domain, access-request information, workspace settings, support messages, subscription status, and billing-related records. Shopify processes app charges when paid plans are offered; VSM does not receive a merchant's complete payment-card number.
Shopify store information. With merchant authorization, VSM accesses the product, variant, SKU, price, cost, weight, inventory, location, publication, validation, and other store-operation information needed to provide catalog matching, inventory synchronization, alerts, bulk changes, and approved store updates. When a merchant uses order sorting, VSM accesses limited recent-order information: the order number and product-line titles, variants, SKUs, quantities, paid amounts, and currency.
VSM does not request or store Shopify order customer names, email addresses, telephone numbers, street addresses, payment details, or tracking details. Because Shopify classifies order resources as protected customer data, VSM still treats the limited order product-line information it uses as protected information.
Stock image updates. If a merchant enables replacement and approves Shopify's optional Files permission, VSM reads product catalog identifiers and main-image identifiers, URLs, dimensions, timestamps, alternative text, and image content to replace listing images with catalog stock images. This includes older listings and merchant-uploaded product photos. VSM uses this feature's Files access for selected product-image replacements and does not browse unrelated store files or request customer records. Shopify processes replacements, and the stock-image provider receives requests for the applicable catalog images. Merchant image content is not sent to the stock-image provider.
Public buylist information. A person who submits items through a merchant's public buylist may provide a name, email address or other contact information, selected items and quantities, condition descriptions, offer decisions, preferred payout type, selected cash payment service and its recipient username, email or phone (or check payee and mailing address), shipping carrier, tracking number and shipping confirmation, and communications about delivery, inspection, or payment. The merchant operating the buylist controls its offers, acceptance, inspection, payment, and customer relationship. VSM temporarily processes customer contact details only to operate that merchant's active workflow.
Public Buylist feedback. The optional feedback form sends a message to the VSM developer, not the merchant. It asks only for a report type, short title, and message; it does not request a name, contact information, offer or order number, payment information, or other personal details. Information a person voluntarily types into the message becomes part of the support report. VSM associates the report with the applicable merchant Buylist and may temporarily process a network address to limit abuse.
Technical and security information. We may process IP address, browser and device information, timestamps, session and authentication information, request and error logs, webhook delivery information, and security events. VSM uses essential session technologies needed for authentication, security, and operation. We do not use third-party advertising cookies.
Information from service providers. We may receive installation, authorization, store, subscription, and app-usage information from Shopify and operational information from infrastructure, email, catalog, or market-data providers used to deliver requested features.
Browser storage. The public Buylist stores item selections, quantities, conditions and payout preferences in your browser for draft saving and recovery. It also remembers your theme preference and may temporarily store a submission reference to prevent duplicate submissions. Saved item drafts do not include your name, contact details, cash-payment recipient details or customer note. You can use Delete saved draft or clear this site's browser data to remove a saved draft. Browser copies are separate from VSM's server records and backup retention; people with access to the same browser profile may see them.
3. How we use information
- Provide, maintain, secure, troubleshoot, and improve the Service.
- Authenticate users and isolate each merchant's data and Shopify connection.
- Perform catalog matching, inventory and listing review, approved synchronization, alerts, order-product sorting, and buylist workflows.
- Review access requests, administer subscriptions, communicate service notices, and provide support.
- Detect abuse, investigate security events, enforce our Terms, and comply with legal obligations.
VSM does not use personal information for automated decisions that produce legal or similarly significant effects.
4. How we disclose information
We disclose information only as reasonably necessary to:
- Shopify, for installation, authorization, API operations, app billing, and platform compliance.
- Infrastructure, hosting, backup, domain, security, and email providers that help operate VSM.
- Catalog or market-data providers when a merchant requests a feature that depends on those services, using the minimum information reasonably needed.
- Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or complete a merger, financing, acquisition, or sale of assets subject to appropriate protections.
We do not sell personal information, share it for cross-context behavioral advertising, or disclose it to data brokers.
5. Retention and deletion
Active merchant workspace information is retained while the merchant uses VSM and as needed to provide the Service. Daily service database backups are retained for up to 14 days. Security, support, billing, transaction, and legal records may be retained for a reasonable period when needed for fraud prevention, dispute resolution, accounting, or legal obligations.
Image update records. VSM retains the merchant's image preference, progress and verification records, and original copies of replaced product images, including merchant-uploaded photos, as needed to provide, investigate, or recover image updates. Recovery copies are restricted to the merchant's workspace. Choosing to leave existing images stops remaining work; it does not delete completed records or revoke Shopify permission. Merchants can contact support about these records under the choices described below.
Buylist customer contact data. While a buylist offer remains active, VSM stores the submitter's name, contact address, submitted note, and cash-payment recipient details in encrypted form, inside only the applicable merchant workspace, so the merchant and customer can complete the workflow. VSM automatically deletes those customer fields when the offer is completed, declined, canceled, or expired. This deletion applies to those contact fields, not every record associated with the offer. VSM may retain the offer reference, item lines, amounts, status, shipment carrier and tracking details, and operational history needed for the merchant's records. Tracking details and information voluntarily included in operational notes may still relate to an individual; they are not treated as anonymous data.
Buylist email delivery. Recipient addresses and message contents are encrypted while waiting for delivery and are erased from VSM's delivery queue after the message is sent, canceled, or permanently fails. The merchant's email provider and the recipient's email provider may retain delivered messages under their own settings and policies; those external mailboxes are not controlled by VSM. Encrypted residual copies may remain temporarily in rotating service backups for up to 14 days and are used only for service recovery.
VSM receives and validates Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. VSM does not store Shopify customer identity information linked to individual customers, so customer requests ordinarily produce no customer identity record. Following a valid shop-redaction request, VSM removes the Shopify credentials, store bindings, pending installation information, retained Shopify webhook summaries, Shopify-linked alerts, imported order product lines, and inventory-matching metadata associated with that store. Residual copies may remain briefly in rotating backups until those backups expire.
Separate workspace, support, or legal information may be retained or deleted according to the merchant's instructions, the requester's rights, operational needs, and applicable law.
6. Security
VSM uses reasonable administrative, technical, and organizational safeguards appropriate to the information processed. Shopify access credentials and active buylist customer contact data are encrypted on the VSM server and are not returned outside the applicable merchant workflow. Merchant workspaces and store connections are isolated. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
7. Your privacy choices and rights
Depending on applicable law, an individual may have rights to request access, correction, deletion, restriction, portability, or an explanation of how personal information is used. To make a request, email vsmmessages@gmail.com. Buylist submitters should include the merchant name and offer reference, if available. We may verify identity and authority before acting. If VSM processes the information only for a merchant, we may refer the request to that merchant or assist the merchant in responding.
You may appeal a refusal by replying to our decision and stating that you are requesting an appeal. You may also contact the privacy or consumer-protection authority available in your jurisdiction.
8. International processing
VSM is based in South Carolina, United States. Information may be processed in the United States and other locations where Shopify or our service providers operate. Those locations may have different data-protection laws than the place where the information was collected.
9. Children
The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. A minor using a merchant's public buylist must have permission from a parent or legal guardian and must comply with the merchant's requirements. Contact us if you believe a child submitted information without appropriate authorization.
10. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the updated Policy with a revised date and provide additional notice when required by law.
11. Contact
Virtual Shop Manager LLC
Registered agent address: 6650 Rivers Ave., Ste. 100, Charleston, SC 29406, United States
Email: vsmmessages@gmail.com