Privacy Policy

Last updated: September 21, 2026

RestockKit is a Shopify app that watches a merchant's inventory and alerts the merchant when a product runs low. This policy explains what data the app processes, why, and how it is protected.

RestockKit stores no customer (buyer) data. It requests only the read_products, read_inventory, and read_locations scopes — the product, stock-level, and location information it needs to detect low stock. It requests no customer scopes, reads no orders, and never stores a buyer's name, email, or address.

1. What We Process

1.1 Merchant / Store Data

The store's myshopify.com domain, an expiring Shopify access token, and the subscription plan tier — the data needed to run the app for the store and bill it through Shopify.

1.2 Inventory Data

A working copy of the store's product, variant, SKU, vendor, location, and current stock-level information — the signal the app evaluates against your thresholds. This is the merchant's own catalog and inventory data; it contains no personal data about buyers.

1.3 Alert Configuration

The alert rules the merchant creates (thresholds, scopes, schedules), the recipient email addresses and any Slack incoming-webhook URL the merchant chooses to send alerts to, and an optional sender name. Recipient addresses are the merchant's own team or supplier contacts, entered by the merchant so RestockKit can deliver alerts to them.

We process the minimum data needed to provide the app's value and use it only for that purpose. We do not sell data, and we do not use it for advertising or automated decision-making.

2. How We Collect It

3. How We Protect It

4. How Long We Keep It

5. Who We Share It With

We use a small number of sub-processors, only as needed to run the service:

We do not share data with anyone else, and we never sell it.

6. Data Subject Rights (Shopify Privacy Webhooks / GDPR)

RestockKit implements Shopify's mandatory privacy webhooks in full. Because the app stores no customer personal data:

These support the merchant's obligations under the GDPR, the CCPA/CPRA, and similar laws. Merchants agree to RestockKit's terms and this policy when they install the app.

7. Changes

We will update this page when our practices change and revise the date at the top.

8. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

NerdLabs (operated by Joren Winge)
Email: support@nerdlabs.us
Website: nerdlabs.us