Merxio - Wholesale & B2B — a Shopify app by NielloSoft. Last updated 16 July 2026.
Merxio adds wholesale pricing and company accounts to a Shopify store. To do that it has to know which customers are approved trade buyers and what each one pays. This page says exactly what that involves, and nothing is buried.
| Data | Why we need it |
|---|---|
| Merchant Shop domain, email, plan, and an access token |
To identify the store, bill the subscription through Shopify, and call the Shopify API on the merchant's behalf. |
| Trade applicants and buyers Name, email, company name, VAT or tax number, country, phone, and anything they type into the application form |
This is what the merchant reviews in order to approve a wholesale account. It is submitted by the buyer, to the merchant, through a form the merchant put on their own storefront. |
| Pricing you configure Tiers, contract prices, volume breaks, negotiated prices, spending limits, credit limits |
It is the app. Without it there is no wholesale pricing. |
| Order totals Order number, total, payment status, and which company placed it |
Only to track what a company owes against its credit limit, and to clear that balance when an invoice is paid. We do not store line items, addresses, or any payment details. |
Shopify classifies customer name and email as protected customer data. We request Level 1 access, which is the lowest level, and we use it for two things: creating and tagging the Shopify customer when a merchant approves a trade application, and addressing the invoice emails Shopify sends on the merchant's behalf.
Nobody. We do not sell data, we do not share it with advertisers, and we do not use it to train anything. The only third parties involved are the ones that have to be:
Merxio does not send email and does not store any mail credentials. When a merchant approves a trade buyer, no message is sent by us — the buyer signs in through Shopify's own account system, which emails them a sign-in code from Shopify's infrastructure, not ours.
Quotes and order invoices are sent by Shopify, from the merchant's own verified sending domain. We supply the wording; Shopify does the sending. We do not operate a mail server and we have no mailing list.
For as long as the app is installed, plus 30 days.
Uninstall the app and Shopify sends us a shop/redact webhook. We delete the
shop's record and every trade profile, price list, company and order total attached to it.
Nothing is retained for analytics, backups beyond that window, or any other purpose.
If one of a merchant's buyers asks for their data, Shopify sends us a
customers/data_request webhook and we return everything we hold on that person
to the merchant. If they ask to be erased, Shopify sends customers/redact and we
delete it.
A buyer should make that request to the merchant they bought from — the merchant is the data controller, and we act on their instruction.
On servers in the European Union.
If this policy changes in a way that affects what we collect, we will update the date at the top and notify merchants in the app.
NielloSoft — privacy@niellosoft.com
For anything about a specific buyer's data, contact the merchant whose store you bought from. They control it; we only process it for them.