Royalty Payouts Paladin Live on the Shopify App Store

Pay creators their share, per sale.

Privacy policy

Last updated

Ioun Developers operates this website and the apps described on it.

Royalty Payouts Paladin is a Shopify app built and operated by Ioun Developers. It works out what a store’s creators have earned on each sale, and helps the store pay them. This policy describes what the app stores, why, who else sees it, and how it is deleted.

Merchants who install the app are our customers. Their creators and their buyers are not: we handle data about both on the merchant’s behalf, as a processor, so a creator or a buyer with a question should start with the store that installed the app.

What we store

About your store. Your myshopify domain, the access token the app uses to read your products and orders, and the session record Shopify’s library keeps for it. That token belongs to the installation rather than to a member of your staff, so it carries no staff names or email addresses and we store none. Also your own settings: the notification address for approval alerts, your PayPal client id and secret, your creator portal toggles and portal domain, your excluded order tags, your B2B setting, and your linked-store arrangements.

Your PayPal client secret is encrypted before it is written to the database.

About your creators, as you enter them. Name, and optionally an email address, a PayPal payout address, a bank-transfer notification address, a payout method, tags and a status. This comes from you, not from your buyers.

If the creator portal is enabled, we also store what that account needs: hashed, single-use sign-in tokens, pending sign-in address changes (also as hashes), the read-only access a creator has granted to a manager or accountant and the address it was granted to, their report subscriptions and any CC addresses on them, and a record of which scheduled emails have been sent so none is sent twice.

We do not store creators’ bank account or routing numbers. Where bank transfers are available, the payment provider collects those details directly from the creator.

About your products. Synced from Shopify: product and variant identifiers, title, variant title, SKU, vendor, product type, tags, handle, an image URL, a plain-text product description, price and unit cost. These are what royalty rules are attached to and what a creator sees named on a statement.

About your orders. For each order line a royalty rule covers, we store the Shopify order identifier, the line item identifier, the product title, the gross, net and basis amounts, the rate applied, the amount earned, the period, and the order date. Where a rule is restricted by country or to or away from B2B orders, the order’s country and company status are read from the order at the moment of calculation and are not stored.

The historical scan, which you run yourself to match old order lines to current products, also stores the order number, SKU, title, vendor, quantity and prices of the lines it surfaces, until you review them.

What the app produces. Your agreements, rules, splits, advances and recoup balances, the royalty ledger, payout batches and their lines, PayPal payout identifiers, payments you record by hand, and logs of which statements and reports were sent.

What we do not store

  • Your buyers’ personal information. No names, no addresses, no email addresses, no phone numbers. The only buyer-related data we hold is the order and line identifiers needed to attribute a sale to a royalty rule, plus the amounts on those lines.
  • Payment details of any kind. The app never touches your checkout, your buyers’ payments, or card details. Billing for the app itself is handled entirely by Shopify.
  • Anything used for advertising or profiling. Nothing here is sold, rented, or used to train anything.

Who else sees it

  • Shopify. The app reads your products and orders through Shopify’s APIs, under the permissions you granted at install, and Shopify handles all billing for the app.
  • PayPal. When you send a payout, your creators’ PayPal addresses and the amounts owed are sent to PayPal’s Payouts API, using your own credentials. We are not a payment processor and never hold the money.
  • Wise. A bank-transfer payout option exists for selected stores only. Where it is enabled, the merchant’s own credentials are used and Wise collects the creator’s account details directly.
  • Resend. Our transactional email provider. Recipient addresses and the contents of statements, reports, approval alerts and portal sign-in messages are processed in order to deliver them.
  • Railway. Our hosting provider. The app and its database run on Railway.

Data deletion

When you uninstall, your access tokens and session records are deleted immediately, so the app stops reading anything from your store at once. Everything else is kept.

About 48 hours later, Shopify sends the store erasure request that follows an uninstall, and the app deletes all of it in one transaction: creators, agreements, rules, the ledger, payout batches and lines, recorded payments, products, portal sign-in tokens, your settings, and the store record itself. Reinstalling inside that window brings your data back intact.

When Shopify sends a customer redaction request, the order and line identifiers on the affected ledger rows are replaced with a placeholder, the corresponding rows in the exclusion tally are deleted outright, and the same references on any historical scan rows, including the order number, are redacted. The money on the ledger row stays, because it is your record of what a creator earned.

When Shopify sends a customer data request, we return nothing, because we hold no personal information about your buyers to return.

Your creators’ data

A creator’s details are yours: you enter them, you correct them, and a creator asking to see or change what is held about them should ask you. Where the portal is enabled, a creator can update their own payout and sign-in addresses, and their own report preferences, directly. If we are asked to act on a creator’s request ourselves, we will refer it to the merchant who holds the data.

Contact

Questions about this policy, or about data held by the app, go to support@royaltypayouts.app. If your question is about a specific store’s royalties, the merchant who runs that store administers the data and is the right first stop.