Privacy Policy
Last updated: September 21, 2026
RestockKit is a Shopify app that watches a merchant's inventory and alerts the merchant when a product runs low. This policy explains what data the app processes, why, and how it is protected.
RestockKit stores no customer (buyer) data. It requests only the read_products, read_inventory, and read_locations scopes — the product, stock-level, and location information it needs to detect low stock. It requests no customer scopes, reads no orders, and never stores a buyer's name, email, or address.
1. What We Process
1.1 Merchant / Store Data
The store's myshopify.com domain, an expiring Shopify access token, and the subscription plan tier — the data needed to run the app for the store and bill it through Shopify.
1.2 Inventory Data
A working copy of the store's product, variant, SKU, vendor, location, and current stock-level information — the signal the app evaluates against your thresholds. This is the merchant's own catalog and inventory data; it contains no personal data about buyers.
1.3 Alert Configuration
The alert rules the merchant creates (thresholds, scopes, schedules), the recipient email addresses and any Slack incoming-webhook URL the merchant chooses to send alerts to, and an optional sender name. Recipient addresses are the merchant's own team or supplier contacts, entered by the merchant so RestockKit can deliver alerts to them.
We process the minimum data needed to provide the app's value and use it only for that purpose. We do not sell data, and we do not use it for advertising or automated decision-making.
2. How We Collect It
- From Shopify, when a merchant installs the app and grants access, and through inventory webhooks and the Admin API for the products, inventory levels, and locations the merchant already holds.
- From the merchant, when staff create alert rules and enter recipients in the embedded admin.
3. How We Protect It
- All traffic is served over TLS 1.2+.
- Data is stored on a DigitalOcean server; production access is SSH-key-only and limited to the operator, and the host runs standard hardening. Development and production data are kept separate.
- Access tokens are stored server-side only and are never exposed to the browser.
- Because RestockKit holds no buyer personal data, there is no customer name, address, or payment information at rest to expose.
- We maintain a security incident-response process and will notify affected merchants of a confirmed data breach within 72 hours.
4. How Long We Keep It
- Inventory and alert-configuration data are kept while the app is installed so alerts keep working.
- When a merchant uninstalls, access tokens are deleted immediately and the store's data is deleted in response to Shopify's shop-redaction request, in all cases within 30 days of uninstall.
5. Who We Share It With
We use a small number of sub-processors, only as needed to run the service:
- DigitalOcean — server and database hosting (United States).
- Mailgun — delivering alert and transactional emails to the recipients the merchant configures.
- Slack — only if the merchant enables Slack alerts, RestockKit posts alert messages to the incoming-webhook URL the merchant provides.
- Shopify — the platform the app runs on.
We do not share data with anyone else, and we never sell it.
6. Data Subject Rights (Shopify Privacy Webhooks / GDPR)
RestockKit implements Shopify's mandatory privacy webhooks in full. Because the app stores no customer personal data:
- A customer data request returns no customer records, because RestockKit holds none.
- A customer redaction has no customer data to remove.
- A shop redaction deletes all of the store's data (inventory copy, alert rules, and configuration).
These support the merchant's obligations under the GDPR, the CCPA/CPRA, and similar laws. Merchants agree to RestockKit's terms and this policy when they install the app.
7. Changes
We will update this page when our practices change and revise the date at the top.
8. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
NerdLabs (operated by Joren Winge)
Email: support@nerdlabs.us
Website: nerdlabs.us