Privacy Policy

BikeShop Desk Privacy Policy

Review draft โ€” not yet published. This page is a preview of BikeShop Desk's proposed privacy policy while it goes through internal review. The retention and request-handling commitments below describe our intended practice; some of the underlying operational steps are still being put in place and verified. Effective date will be set when this policy is published.

Privacy contact: support@cortola.com
Business mailing address: 11000 Anderson Mill Rd. Unit 5, Austin, TX 78750

BikeShop Desk is operated by Venture Sports Inc. dba Cortola ("Cortola," "we," "us," or "our"). This policy explains how we handle personal information in connection with BikeShop Desk and related support, including its Shopify admin app, POS extension, and Mobile Companion.

1. Our role and the merchant's role

BikeShop Desk helps merchants organize customer service and store operations. Merchants decide which customer and staff information they enter into the app, which features they use, and which staff members may access those features.

We handle customer and staff information to provide the app on the merchant's behalf. We also handle merchant account, subscription, security, and support information to operate our service. The precise legal roles of Cortola and the merchant depend on the processing involved and applicable law.

BikeShop Desk is currently offered to merchants whose business address is in the United States. Merchant records may include information about customers or staff in other countries.

A merchant's own privacy notice explains how that merchant uses its customers' information. This policy covers Cortola's handling of information through BikeShop Desk; it does not replace the merchant's notice or Shopify's policies for its own services.

2. Information we handle

The information handled depends on the merchant's plan, enabled features, configuration, and use of the app.

CategoryExamples and sources
Merchant and Shopify account informationShop domain and identifiers; authorized users' names, email addresses, Shopify identifiers, and account roles; permissions and session information needed to connect to Shopify.
Customer informationCustomer names, email addresses, phone numbers, and Shopify customer identifiers obtained through authorized Shopify access or entered by the merchant's team.
Customer-service and store recordsQueue entries, notes, follow-up tasks, staff assignments, product interests, and draft-order references or details needed for the merchant's workflow. We also handle Shopify product, inventory, location, and order information used by enabled features.
Staff and work recordsStaff names, email addresses, roles, store-location access, task activity, and, when Time Clock is used, time entries, corrections, approvals, and related audit records.
CommunicationsWhen an authorized communications integration is enabled, message content, communication notes, phone numbers, provider identifiers, timestamps, call duration, and status information needed to associate communications with the merchant's customer-service records.
Subscription and setup informationSelected plan and verified access status, subscription-verification records, enabled features, store settings, and setup-guide progress. Shopify handles app billing; BikeShop Desk does not ask merchants to enter payment-card details into the app.
Security, technical, and support informationAuthentication and session records, service events and errors, and information a person includes when contacting support. Our hosting infrastructure may also process ordinary connection information, such as network addresses and request metadata, to deliver the service.

Shopify, merchants, authorized staff, and enabled integrations are the main sources of app information. Please enter only information needed for the intended workflow, especially in free-text notes and messages. Do not place passwords, payment-card details, or unrelated sensitive information in those fields.

3. How we use information

We use information to:

Cortola uses customer information only to operate and support BikeShop Desk. We do not sell that information or use it for Cortola's own advertising. A merchant's communications with its customers remain subject to that merchant's instructions, notices, and any required consent.

4. Who receives information

An optional integration is used only when it is enabled for the merchant. Providers may also handle information under their own terms and privacy notices for the services they supply. A provider's inclusion here does not mean that every merchant uses that provider or that every provider receives every category of information.

5. App sessions and cookies

The embedded app uses Shopify's authentication mechanisms and session information. Mobile Companion uses a necessary session cookie to keep an authorized staff member signed in. In the current version, the mobile cookie can last up to 90 days, and access can be revoked sooner. Blocking necessary cookies can prevent Mobile Companion from working correctly.

The app does not include advertising pixels or tracking intended to follow shoppers across unrelated websites. Shopify and any separately enabled services may use their own cookies or similar technologies under their own notices. This policy does not describe cookies on a separate Cortola marketing website.

6. Where information is processed and how it is protected

The Cortola app and its primary database are currently hosted on Render in Ohio, United States. Information may therefore be processed outside the country where a merchant, staff member, or customer lives. Shopify and enabled providers operate their own services and processing arrangements.

The app uses HTTPS for its public connections, authenticated access, and controls based on the merchant's shop, staff roles, and locations. Mobile access credentials stored by the app are hashed. These measures reduce risk, but no service can guarantee absolute security.

7. Retention and deletion

We retain information only for the purposes described in this policy, subject to applicable legal obligations and valid privacy requests. Our retention rules are:

InformationRetention rule
Customer-service and operational recordsKeep while needed to provide the service. Review continued need with the merchant at least every 12 months. Remove or anonymize records within 30 days after determining they are no longer needed.
Staff profiles and Time Clock historyInclude in the same review, taking account of the merchant's instructions and applicable employment-record requirements. Disable departed staff access promptly. We do not apply a single universal payroll-record period.
Ordinary support correspondenceRemove within 12 months after the support case closes. Remove unnecessary sensitive attachments sooner.
Cortola-controlled temporary exports and troubleshooting filesRemove as soon as no longer needed and no later than 7 days after creation. Merchant-downloaded files are under the merchant's control.
Routine service and diagnostic logsKeep for up to 30 days, or a shorter provider period. Our current Render runtime-log window is 7 days.
Security and privileged-access recordsKeep for up to 90 days, unless a documented active incident or legal obligation requires a limited longer period. This rule does not mean all hosting plans provide 90 days of access-log history.
Used or expired mobile pairing recordsRemove within 7 days after use or expiry. Pairing links expire for access after 15 minutes.
Expired or revoked mobile session recordsRemove within 30 days after expiry or revocation. Mobile sessions allow access for no more than 90 days and can be revoked earlier.
Subscription-verification informationKeep what is needed to determine current app access and remove it with the shop's app data. Shopify handles its own billing records.
Minimal privacy-request completion evidenceKeep for 24 months after closure. Keep case references, dates, verification outcome and completion details rather than exported content. Remove customer identifiers when no longer needed.

Changing plans or disabling a feature does not automatically erase historical records. Any required legal exception is limited to the necessary information and purpose, with restricted access and a review or end date.

Removing the app ends its authorized access but does not immediately erase every stored record. Shopify sends subsequent deletion requests. For Shopify privacy requests, we target completion within 7 days and complete the requested action within 30 days of receipt unless a legal retention requirement prevents deletion. We follow an earlier applicable deadline where required. Identity checks or a processing failure do not restart the clock.

Deletion from BikeShop Desk does not automatically delete the merchant's original Shopify records or information held independently by an enabled provider. The merchant should preserve any records it is required to retain before requesting shop deletion.

Backups. Our current Render recovery window is 3 days. Render logical backups can remain available for at least 7 days after creation; provider cleanup may take longer. We do not promise that every backup disappears within 7 days. Recovery copies are kept separate from ordinary active use. Before restoring customer data to active service, completed deletions must be reapplied. Cortola-controlled downloaded copies follow the temporary-file rule above.

Expiration of access credentials does not itself erase the associated database record. The separate cleanup periods above govern retained records.

8. Privacy requests and choices

Depending on applicable law, a person may have rights to request access to, correction of, deletion of, or a copy of personal information, or to restrict or object to certain uses. Applicable law may also provide a right to complain to a privacy regulator.

If you are a merchant's customer or staff member, contact that merchant first about information it has entered into BikeShop Desk. The merchant controls its customer-service and employment records and can direct the handling of that information. You can also contact Cortola using the privacy contact above, identifying the relevant merchant and the nature of your request.

We may need information to verify identity and authority before acting on a request. Please do not send passwords or unnecessary sensitive documents. We will coordinate with the merchant where appropriate and explain any applicable limits on a request.

For supported customer-data access cases, an authorized merchant administrator can review the applicable records and download a protected copy through the authenticated app. Confirming receipt is a separate step from generating the download. Information belonging to other people must be considered during scope review. Files downloaded by a merchant are then under that merchant's control.

Cortola's privacy owner coordinates requests sent to support@cortola.com. We record the original receipt date, verify authority, track the applicable deadline and keep unresolved or partially completed requests open. We explain any applicable limitation or documented legal retention requirement rather than treating file generation alone as fulfillment.

9. Changes to this policy

We will update this policy when the app's data practices change and revise the effective date. Where applicable law requires an additional notice or consent, we will provide or obtain it before making the relevant change.

10. Contact

Venture Sports Inc. dba Cortola
BikeShop Desk privacy inquiries
Email: support@cortola.com
Mail: 11000 Anderson Mill Rd. Unit 5, Austin, TX 78750