Privacy Policy

Effective September 9, 2026

Pending legal review. This document describes how CreditDesk actually operates and names the contracting entity, address and governing law, but it has not been reviewed by qualified counsel. Before CreditDesk is offered to merchants it should be reviewed by a lawyer in the relevant jurisdictions.

How CreditDesk handles personal data. CreditDesk is a Shopify application that provides credit control, accounts receivable reporting and collections to merchants who offer net payment terms to their business customers. CreditDesk is operated by Lead Kings LLC, 290 Fern Ct, Hampton, GA 30228, United States.

1. Our role

CreditDesk processes two distinct categories of personal data, and our role differs for each.

For data about a merchant's customers — the buyers placing orders on payment terms — the merchant is the controller and CreditDesk is a processor. We act on the merchant's documented instructions, and the merchant decides what credit terms to set and what communications to send. Our processing of that data is governed by our Data Processing Addendum.

For data about the merchant themselves — the account owner and staff who install and operate the app — CreditDesk is the controller. This policy describes that processing directly.

2. Data we process

We deliberately collect the minimum required to provide the service. Specifically:

  • Buyer data, from the merchant's Shopify store: buyer name and email address, the company the buyer purchases on behalf of, and order and payment amounts, dates and status. We do not collect buyer phone numbers, and we do not collect billing or shipping addresses.
  • Merchant data: store domain, store name, the account email address, and the identity of staff who take actions in the app (recorded in an audit log).
  • Operational data: application logs, error reports, and records of emails we sent on the merchant's behalf, including recipient address, subject, and delivery status.
  • We never receive or store payment card numbers or bank account details. Payments are completed on payment pages hosted by Shopify or Stripe, and those details never reach our systems.

3. Why we process it

  • To maintain a receivables ledger: associating each order placed on payment terms with the correct company account so the merchant can see what is owed and by whom.
  • To enforce credit limits the merchant configures, including declining checkout for accounts that are over limit or on hold.
  • To send payment reminders, account statements and related communications to the merchant's customers, under the merchant's own identity and with the merchant's address for replies.
  • To operate, secure, support and improve the service, including diagnosing faults and preventing abuse.
  • We do not sell personal data. We do not share it with third parties for their own marketing. We do not use it to build advertising profiles, and we do not use buyer data to train machine learning models.

4. Legal bases

Where the GDPR or UK GDPR applies and CreditDesk is a processor, the merchant is responsible for establishing a lawful basis for processing their customers' data.

Where CreditDesk is a controller — for merchant account data — we rely on performance of a contract (to provide the service the merchant signed up for), our legitimate interests (securing and improving the service, preventing abuse), and compliance with legal obligations.

5. Sub-processors

We use the following providers to deliver the service. Each is bound by contractual obligations to protect the data they handle.

  • Amazon Web Services — application hosting, PostgreSQL database, cache, object storage, and inbound email (United States).
  • Postmark (ActiveCampaign) — delivery of transactional email sent on the merchant's behalf (United States).
  • Shopify — source of the order, company and buyer records CreditDesk reads, and the surface where buyers pay (merchant's own Shopify region).
  • Stripe — optional. Only if the merchant connects their own Stripe account to accept ACH bank payments; funds settle to the merchant, never to CreditDesk (United States).
  • Sentry — application error monitoring. Configured to avoid transmitting personal data in error reports (United States).

6. Retention and deletion

  • While an app installation is active, we retain ledger and communication records so the merchant has a continuous receivables history.
  • When a merchant uninstalls, all of their data is permanently deleted 30 days later. The delay exists so that a merchant who reinstalls does not lose their history; it is not an indefinite grace period.
  • When Shopify sends a shop redaction request, we delete that shop's data immediately rather than waiting for the 30-day window.
  • When Shopify sends a customer redaction request, we remove or anonymise that individual's personal data. Financial amounts and invoice records are retained in a form no longer linked to the individual, because the merchant needs them for their own accounting and tax obligations.
  • Raw inbound email sent to our published addresses is deleted after 30 days.

7. Security

Personal data is encrypted in transit and at rest, including database storage, cache, object storage and backups. Credentials that grant access to a merchant's store are additionally encrypted at the application layer with a rotatable key.

Access to production systems is limited to personnel who require it, actions that change data are recorded in an audit log, and every database query for merchant-owned data is constrained to a single merchant by a control enforced in code and verified by an automated test.

Our Security Incident Response Policy describes how we detect, contain and report security incidents, including notification timelines.

8. International transfers

Our infrastructure is hosted in the United States. Where personal data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to us, those transfers are made under the European Commission's Standard Contractual Clauses, together with the UK Addendum where applicable, as set out in our Data Processing Addendum.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable format.

If you are a buyer whose data appears in CreditDesk, the merchant you purchased from is the controller of that data. Please direct your request to them; we will assist them in responding. If you contact us directly, we will forward your request to the relevant merchant.

If you are a merchant, contact us at support@getcreditdesk.com and we will respond within the timeframe required by applicable law.

10. Cookies and tracking

The CreditDesk admin interface runs embedded inside the Shopify admin and uses session tokens issued by Shopify to authenticate each request. We do not set advertising or cross-site tracking cookies, and we do not embed third-party analytics or advertising scripts in the admin interface.

Emails we send on a merchant's behalf may include an open-tracking pixel so the merchant can see whether a reminder was opened. Delivery and open events are recorded against the message, not used to build a profile.

11. Children

CreditDesk is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.

12. Changes and contact

We will update this policy as the service changes and will revise the date shown above. Material changes affecting merchants will be communicated directly.

Questions about this policy: support@getcreditdesk.com. Security matters: security@getcreditdesk.com.