Merchant terms

The agreement between BouquetOS and the shops that use it, including how we handle personal data on your behalf.

Last updated 5 August 2026

1. Who this is between

This agreement is between BouquetOS (“we”, “us”), the provider of the BouquetOS software, and the business that creates a BouquetOS account (“you”, the “merchant”). Reach us at support@bouquetos.com.

By creating an account or using the service you accept these terms. If you are agreeing on behalf of a business, you confirm you are authorised to bind it.

2. The service

BouquetOS is order and production software for flower shops. It takes orders from connected sales channels, schedules them for pickup or delivery, and helps you run the day. The connected Shopify app adds a date and time-window picker to your storefront cart and syncs the resulting orders into your BouquetOS account.

We may change or improve the service. If we remove something you depend on, we will tell you before it goes.

3. Your account

4. Fees

If you install BouquetOS from the Shopify App Store, your subscription is charged by Shopify through the Shopify Billing API and appears on your regular Shopify invoice. You approve the charge in your Shopify admin, and you can cancel it there at any time. We do not bill App Store merchants anywhere else.

If you buy BouquetOS directly from us, subscription fees are shown on our pricing page and billed through Stripe.

On either rail, fees are payable in advance and are not refundable for partial periods, except where the law requires otherwise.

5. Acceptable use

You agree not to:

Reporting a vulnerability in good faith to support@bouquetos.com is welcome and will not be treated as a breach of this section.

6. Our role with personal data

For personal data belonging to your customers, you are the controller (GDPR) and business (CCPA/CPRA): you decide what is collected and why. We are the processor and service provider, acting on your instructions. The addendum below governs that processing and forms part of these terms.

For your own account data — the people at your shop who sign in — we are the controller, and our privacy policy explains that handling.

7. Data processing addendum

7.1 Subject matter and duration

We process personal data to provide the service, for as long as your account is active, plus the retention window in §7.8.

7.2 Nature and purpose

Receiving orders from your sales channels; scheduling them by date and time window; assigning production to your staff; showing you fulfilment details; and syncing status back to the sales channel.

7.3 Categories of data and data subjects

Data subjects: your customers and the recipients of their orders.

Data: name; contact details supplied at checkout or in the cart form (email, phone, or a messaging handle); delivery address and delivery notes; order contents and value; and the requested fulfilment date and time window.

We do not request Shopify’s read_customers scope, and we do not collect payment card data — payment is handled by your sales channel and never reaches us.

7.4 Our instructions

We process personal data only on your documented instructions, including these terms, unless the law requires otherwise — in which case we will tell you first, unless that law forbids it. We will tell you if, in our opinion, an instruction breaches data protection law.

7.5 Confidentiality

Everyone we authorise to process personal data is bound by confidentiality and only gets the access their work requires.

7.6 Security

We maintain the following measures:

7.7 Sub-processors

You authorise us to engage the sub-processors below. Each is bound by terms no less protective than these. We will give notice before adding or replacing one, and you may object on reasonable data protection grounds.

7.8 Retention and deletion

Personal data on completed and cancelled orders is anonymised three years after the order’s fulfilment date, by an automated daily process. On termination we delete or return personal data within 30 days, except where the law requires us to keep it.

We also honour Shopify’s mandatory compliance webhooks: customers/redact anonymises the personal data on matching orders, customers/data_request is surfaced to us for response through you, and shop/redact scrubs stored credentials after uninstall.

7.9 Assisting you

Taking into account the nature of the processing, we will help you respond to data subject requests, and with security, breach notification and impact assessments. If we become aware of a personal data breach affecting your data we will notify you without undue delay with what we know, and keep you updated as we learn more.

7.10 International transfers

We process data in the United States. Where you transfer personal data from the EEA, the UK, or Switzerland, the parties agree that the European Commission’s Standard Contractual Clauses (module two, controller to processor), and the UK Addendum where applicable, are incorporated into this addendum, with you as data exporter and us as data importer.

7.11 CCPA and CPRA

We act as a service provider. We do not sell or share personal information as those terms are defined by the CCPA, and we receive no consideration for it. We will not retain, use or disclose personal information for any purpose other than performing the service under these terms, nor outside the direct business relationship between us, nor combine it with personal information from other sources except as the CCPA permits. We certify that we understand and will comply with these restrictions.

7.12 Audit

On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this addendum.

8. Confidentiality and intellectual property

Each party will protect the other’s confidential information. You keep all rights in your data. We keep all rights in the software. Nothing here transfers ownership either way.

9. Warranties and disclaimers

We will provide the service with reasonable skill and care. Beyond that, and to the extent the law allows, the service is provided “as is” without other warranties. We do not warrant that it will be uninterrupted or error free.

10. Limitation of liability

To the extent the law allows, neither party is liable for indirect, incidental or consequential loss, or for lost profits or lost data beyond the cost of restoring it from backups. Our total liability in any twelve-month period is limited to the fees you paid us in that period. Nothing here limits liability that cannot lawfully be limited.

11. Term and termination

Either party may terminate at any time. You can cancel from your account or by emailing us. We may suspend or terminate for material breach, or for non-payment, giving you notice and a reasonable chance to fix it where the circumstances allow. On termination your access ends and §7.8 governs your data.

12. Governing law

These terms are governed by the laws of the State of California, United States, without regard to its conflict of law rules. The parties submit to the exclusive jurisdiction of the state and federal courts located in Santa Clara County, California.

13. Changes

We may update these terms. For material changes we will give notice before they take effect, and the date at the top of this page always shows the current version. Continuing to use the service after a change means you accept it.

14. Contact

Questions about these terms, the addendum, or a data protection matter: support@bouquetos.com.