Legal
WhatBox — Privacy Policy
Last updated: 2026-08-04 · Operator: Snorka, LLC ("we", "us"), Princeton, Kansas, USA
Product: WhatBox — a Shopify application that helps merchants decide, per order, whether to ship in-house or via Amazon Multi-Channel Fulfillment (MCF), and routes fulfillment accordingly.
This policy explains what data WhatBox collects, and how we use, store, protect, share, and delete it. It applies to the merchants who install WhatBox and to the order data — including end-customer information — that we process on their behalf.
1. Our role
For the store data we process, the merchant (the Shopify seller) is the controller and WhatBox (Snorka, LLC) acts as a data processor, processing data only to provide the fulfillment-routing service the merchant has authorized.
2. Data we collect
- Merchant store data: products, variants, packaging/box configuration, order line items, and fulfillment settings — obtained from the merchant's connected Shopify store and Amazon Selling Partner account.
- Amazon account data: FBA / AWD inventory levels and MCF fee and fulfillment data, via the Amazon Selling Partner API (SP-API), for orders the merchant routes.
- End-customer (buyer) personal data: for an order a merchant routes to Amazon MCF, we process the buyer's name, shipping address, and phone number — solely to create that buyer's own shipment.
- Account/operational data: the merchant's contact email and configuration/settings.
We practice data minimization: we collect only what is needed to route and fulfill orders.
3. How we use data
- To compute each order's real in-house cost versus the Amazon MCF cost and present the comparison.
- To create, track, and (where needed) cancel MCF fulfillment orders on the merchant's behalf.
- To read inventory and fulfillment status to support routing decisions.
- To send the merchant operational notifications about their orders.
We do not sell data, use it for advertising, perform analytics on buyer identity, contact buyers, or provide data to data brokers.
4. How we store data
Data is stored and processed in the United States on Microsoft Azure (application services and an Azure Database for PostgreSQL). Azure provides the underlying physical security, network isolation, and platform maintenance.
5. How we protect data
- Encryption in transit: all connections use HTTPS/TLS.
- Encryption at rest: data is encrypted at rest by the platform; sensitive credentials (e.g. API tokens) receive an additional application-layer encryption before storage.
- Access control: access to production data follows least-privilege, need-to-know principles; administrative accounts require multi-factor authentication.
- PII handling: end-customer personal data is not written to logs in identifiable form.
6. Who we share data with (sub-processors)
We share data only with the service providers needed to deliver WhatBox, each engaged under equivalent data-protection obligations:
- Amazon — Multi-Channel Fulfillment and inventory (the fulfillment the merchant chooses).
- Shopify — the merchant's store platform (source of orders).
- Microsoft Azure — application hosting and database (US).
- Shipping rate/label providers (e.g. EasyPost, ShipStation) — carrier rate quoting and, where used, label generation.
- Postmark — transactional email delivery.
- TikTok Shop — fulfillment and orders, only if the merchant connects that channel.
We do not otherwise share, sell, or rent personal data.
7. Retention and deletion
- Personal data is retained only as long as needed to provide the service and meet legal/operational requirements.
- On request: we delete or redact personal data upon a valid request from the merchant or platform (we implement the platforms' data-deletion/redaction mechanisms, e.g. Shopify's
customers/redact, customers/data_request, and shop/redact).
- At the end of the relationship: when a merchant uninstalls or the contract ends, we delete or return the personal data in our possession, subject to any legal retention requirement.
8. Data-subject rights
We assist merchants and platform partners in responding to end-customer requests to access, correct, or delete personal data. End customers should direct such requests to the merchant they purchased from; we support the merchant in fulfilling them.
9. Amazon-specific commitments
Consistent with Amazon's Data Protection Policy and the Selling Partner Agreement:
- Buyer name, address, and phone obtained via SP-API are used solely to create that buyer's own MCF shipment — never for marketing, resale, analytics on buyer identity, or any secondary purpose.
- We retain such data only as long as needed to fulfill the order and meet legal obligations, then delete it.
- We do not combine Amazon data with data from other sources for any prohibited purpose.
10. Security incidents
If we become aware of a personal-data breach, we notify affected merchants and relevant platform partners without undue delay, and within 72 hours where required.
11. Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version. Material changes will be communicated to merchants.
12. Contact
Questions about this policy or your data: