Legal change log
Our Privacy Policy, Terms and Conditions, Data Processing Agreement, Cookie Policy, Acceptable Use Policy, Information Security Policy, Service Level Agreement, Sub-processors list and Data Subject Request process each commit to recording amendments here. This page is that record.
Material changes are announced here before they take effect. Where a change is adverse to a merchant, we seek affirmative acceptance rather than relying on this page alone.
2026-08-24 (fifth pass)
- Availability aligned with the EU/UK position. The Service Level Agreement said the Connector is "distributed globally" and the Privacy Policy described serving merchants "globally"; both now say the app is offered to merchants established outside the EEA and the UK (United States merchants at launch), while noting — in the Privacy Policy — that those merchants' shoppers may be located anywhere, which is why the UK and EU frameworks continue to apply to data subjects in those territories. No processing changed.
2026-08-24 (fourth pass)
- One position on EU/UK representation. Three documents took three different stances on Article 27: the Acceptable Use Policy argued no representative was needed because the app is B2B; the Data Processing Agreement argued the Article 27(2) "occasional processing" derogation applied; and the Data Subject Requests notice said representatives are required before offering the service in those territories. The two exemption arguments have been removed. All three documents now take the conservative position: Flag Eagle LLC has not appointed EU or UK representatives, and until it does, WB Connect is made available only to merchants established outside the EEA and the UK (enforced through the Shopify App Store listing's country availability). Before offering the app to merchants in the EEA or UK, representatives will be appointed and named in the Data Subject Requests notice. No processing changed; the legal posture was made consistent and conservative.
2026-08-24 (third pass)
- One deletion deadline, everywhere. The window for deleting a shop's data
after the
shop/redactwebhook was stated five different ways across the documents — 48 hours, 14 days, ~16 days, 30 days and 90 days. The system deletes on receipt of the webhook, so every document now carries the same commitment: within 48 hours ofshop/redact(approximately 4 days after uninstall in total), with a scheduled backstop that deletes no later than 90 days after uninstall if the webhook is never delivered. - The DPA's return-and-deletion clause described a process that did not exist. Clause 11.2 promised a notification email within 7 days, a 21-day election window and a 30-to-90-day deletion timetable. Deletion is automatic and much faster than that. The clause now describes the real mechanics, and merchants who want an export are directed to request one — free — before uninstalling.
- Sub-processor classification made consistent. Shopify Inc. and the merchant's 3PL were listed as sub-processors in some documents and expressly denied as sub-processors in others. The reasoned position in Privacy Policy Sections 5.1 and 5.2 is now applied everywhere: neither is a sub-processor of Flag Eagle LLC — Shopify is an independent controller and the 3PL is the merchant's own processor. The Sub-processor List, the DPA's Annex 3, the Terms and the SLA were restructured to match, OpenAI now appears in every roster, and the SES row in Annex 3 carried the same Ireland/London mix-up corrected elsewhere on 2026-08-24. No data flow changed; classifications and descriptions did.
- Log retention aligned. Authentication-log retention read 12 months in the Cookie Policy and 13 months in the Privacy Policy; both now say up to 13 months.
2026-08-24 (second pass)
- Three annexes were missing from the published Data Processing Agreement.
Annexes 1, 2 and 3 — details of processing, security measures, and the
authorised sub-processor list — are incorporated into the Standard
Contractual Clauses by clause 6.5, and the published page did not contain
them. A bare
---in the source was being read as an end-of-document marker, silently truncating everything after it. The same fault removed the effective-date line from eight other documents, which is why those dates still read 2026-06-10 after the earlier correction. All now publish in full. - Permissions, again. The FAQ, the How It Works page and
llms.txtstill said the app requests read and write access to products, and read/write orders. It does not, and has not since the permissions were cut to nine. The Data Processing Agreement's Annex 1 carried the old eleven-scope list too — invisible until the truncation above was fixed, and corrected in the same pass. - Data Subject Requests notice. It named the App Store listing as "Warehouse Bridge" and stated that the listing was configured to block installation by EEA and UK merchants. Neither was true: the app is not yet published on the App Store at all. Restated to describe the actual position.
2026-08-24
- Corrections to statements about the App Store listing. Several documents said WB Connect "is listed on the Shopify App Store on a single Free plan", and named the listing "Warehouse Bridge v3". Neither was accurate: the app is not yet listed, and its name is WB Connect. Every such statement now says the app is offered free of charge, and the old name has been removed. Nothing about the commercial position has changed — the app is free, creates no subscription and no charge, and always has.
- Hosting region — two documents still said Ireland. The Service Level
Agreement described AWS
eu-west-2as Ireland in two places and the Data Subject Requests page said data was "resident in Ireland".eu-west-2is London, United Kingdom, as the 2026-08-23 note said. No data moved. - London is not in the European Union. The Sub-processor List described the United Kingdom as an EU processing location in two places, a leftover from the same correction. Reworded.
- Amazon SES region — over-corrected. The Sub-processor List had moved SES
to
eu-west-2(London). Transactional email is sent fromeu-west-1(Ireland), which the Cookie Policy always said. Restored. - Requested permissions.
write_productsandwrite_ordersare no longer requested — the app reads your catalogue and never writes to it, and it never modifies an order. The Acceptable Use Policy previously described a purpose for each; those descriptions are gone and the list now matches the nine permissions actually requested. "Delivered" removed. The FAQ and two marketing pages listed delivered among the fulfilment events sent back to Shopify. There is no delivery signal — the app knows when a parcel ships and its tracking number, not when it arrives.
Sub-processor added: OpenAI. The Warehouse Bridge WMS includes an internal natural-language analytics assistant, used by 3PL warehouse operators to ask questions about their own warehouse activity. It is not part of the WB Connect Shopify app and cannot be opened by a Shopify merchant. OpenAI has been added to the Sub-processor List and to Section 5.3 of the Privacy Policy for vendor transparency. No Shopify protected customer data is transmitted to OpenAI: personal fields are removed from query results before any request is made, and a question containing an email address is refused without any request being made at all.
2026-08-23
- Billing. WB Connect is offered free of charge on a single Free plan. Earlier versions of these documents described a $0.00/month recurring AppSubscription created through the Shopify Billing API on install. That mechanism has been removed: installing WB Connect now creates no subscription, no charge and no billing record of any kind. The app remains free, as it always has been — only the mechanism described has changed.
- App architecture. WB Connect is an embedded Shopify app. It renders inside Shopify Admin and authenticates merchant requests with App Bridge session tokens, so it sets no cookies in the admin frame. Earlier versions described a non-embedded app authenticated by OAuth session cookies.
- Hosting region — correction. Several documents previously described our
AWS region
eu-west-2as being in Ireland. That was wrong:eu-west-2is London, United Kingdom, and that is where WB Connect data has been hosted throughout. No data moved; the description was inaccurate and has been corrected in every document that carried it. Transactional email is sent via AWS SES ineu-west-1(Ireland), which was and remains accurate. - Broken links. Nine legal URLs referenced across these documents returned 404 and have been corrected to the pages they were always meant to reach.
2026-06-10
- Initial publication of the WB Connect legal documents (Version 1.0-1.2).