BouquetOS is order and production software for flower shops. This page explains what data we handle, why, and what control you have over it.
Last updated 3 August 2026
When a flower shop uses BouquetOS, the shop is the controller of its customers’ personal data: it decides what to collect and why. BouquetOS is a processor acting on that shop’s instructions. We do not sell personal data, we do not share it with third parties for their own purposes, and we do not use it to train models or to make automated decisions with legal or similarly significant effects.
From the shop’s Shopify store, when the shop connects it: order records and the customer details attached to them — customer name, email address, phone number, the recipient’s name and phone number, and the delivery address. We also store order contents, amounts, the requested fulfillment date and time window, and the original order payload we received, so that an order can be re-checked if something maps incorrectly.
From the shop itself: the names, email addresses and roles of staff invited to the workspace, their working hours and pay rates where the timeclock is used, and the shop’s own settings — opening hours, closed dates, delivery rules.
From the shop’s storefront visitors: when the shop installs our storefront block, a shopper’s chosen fulfillment method, date and time window are written to their Shopify cart so the order arrives with those details. The block does not set advertising or analytics cookies and does not track shoppers across sites.
From this website: if you sign up, the email address and shop name you enter, plus billing details handled by our payment processor. We never see or store full card numbers.
Only to run the service the shop is paying for: importing and scheduling orders, printing run sheets, syncing fulfillment status back to Shopify, calculating hours and pay, and supporting the shop when something goes wrong. We use the minimum data each of those jobs requires, and we do not repurpose it.
We use a small number of vendors to run the service. Each processes data only to provide their part of it:
Our application servers and database run in the United States. If you are in the UK or EEA, this means your data is transferred outside your region; we rely on the standard contractual clauses offered by our hosting providers for those transfers. We can discuss regional hosting with shops that require it.
Personal details attached to a completed or cancelled order — customer and recipient names, phone numbers, email address, delivery address, note-card text and order notes — are automatically erased three years after the order’s fulfillment date. What remains is the anonymous business record: what was made, when, and for how much.
Three years is deliberate rather than arbitrary. Flower shops are seasonal and occasion-driven: customers return for the same anniversary, birthday or memorial year after year, and often ask for “the same as last time”. Three years covers that recurrence while still putting a firm limit on how long personal details are held.
The rest of the order record is the shop’s own business record, kept while the shop’s workspace is active. When a shop closes its account, its workspace and the data in it are deleted.
If a shop uninstalls the BouquetOS app from Shopify, the connection is marked uninstalled straight away and stops being used. Shopify then sends us a store redaction request — usually around 48 hours later — and we erase the stored access credentials at that point. We keep a minimal record linking the store to its workspace so that reinstalling reconnects to the same data instead of stranding it. Order records already imported remain the shop’s own records until the workspace itself is deleted.
Individual customer records are erased sooner on request — see below.
If you bought flowers from a shop that uses BouquetOS and want to see or delete your data, contact the shop directly: they are the controller and can act immediately. Shopify also forwards deletion and access requests to us automatically.
When we receive a deletion request, we erase that person’s name, email address, phone number, recipient details, delivery address, order notes, and the original order payload from the affected orders. Access requests are answered within 30 days. If a shop closes its Shopify store, we delete its stored credentials.
If we make a material change to how we handle personal data, we will update this page and notify shops with active workspaces before it takes effect.
Questions about this policy, or a data request: privacy@bouquetos.com.