> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stockful.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Stockful collects, uses, stores and protects your store's data, who it is shared with, and the choices and rights you have over it.

**Last Updated:** September 4, 2026

## Company Details

* **Organization:** Stockful
* **Data Protection Contact:** [support@stockful.app](mailto:support@stockful.app)

## Overview

Stockful ("the App") is a Shopify application that provides inventory monitoring, historical tracking, analytics, forecasting, and notifications for Shopify merchants. This Privacy Policy explains how we collect, use, and protect information when you use the App.

## Information We Collect

When you install and use Stockful, we access and store the following data from your Shopify store:

### Store Information

* Store name, domain, and Shopify identifier
* Store email address, currency, and timezone
* Staff account information associated with the Shopify admin

### Inventory & Product Data

* Inventory levels and quantities across all locations (available, committed, reserved, etc.)
* Inventory item details (cost, tracking status)
* Product and variant information (titles, SKUs, handles, media)
* Product classification and attributes - category, collections, product type, vendor, tags, and flags such as gift card, taxable, requires shipping, country of origin, and weight
* Sales channel, market, and catalog membership - which channels and catalogs a product is published to, including market and B2B company-location names used to label filters
* Bundle relationships - which products are components of a bundle
* Merchant metafield values - only for the product and variant metafields you enable for filtering and reports
* Location names and addresses

### Order Data

* Order and fulfillment records (used solely for sales velocity calculations and demand forecasting)
* Order records returned by Shopify's API include customer personal data (names, email addresses, billing and shipping addresses). This data is processed only to compute aggregate sales velocity and demand forecasts. **Individual customer personal information is not retained, stored in our database, analyzed, or shared with third parties.**

### App Configuration

* Alert and report schedule delivery settings (recipient email addresses, Slack channel selections)
* Tracking preferences and thresholds
* Report configurations
* Subscription and billing status

### What We Do Not Collect Or Retain

* **Customer personal data at rest** - although the Shopify order API returns customer names, emails, and addresses as part of order records, Stockful does not store, retain, analyze, or share individual customer personal information. Order data is transformed into aggregate velocity and forecasting metrics, and the source customer fields are discarded.
* **Payment card information** - all billing is handled through the Shopify App Store; we never see card numbers, expiry dates, or CVV codes.
* **Customer browsing or behavioral data** - we do not track your storefront visitors, set cookies on your storefront, or receive analytics events from customer-facing pages.
* **Children's data** - see the Children's Privacy section below.

## How We Use Your Information

We use the information collected to:

* **Deliver the service** - monitor inventory levels, generate reports, send notifications, and provide forecasting
* **Improve the App** - analyze usage patterns and performance to enhance features and reliability
* **Provide support** - respond to your inquiries and troubleshoot issues
* **Communicate updates** - notify you of important changes to the App or these terms
* **Ensure security** - detect and prevent fraud, abuse, or technical issues
* **Meet legal obligations** - comply with applicable laws and Shopify's requirements

## AI Features

Stockful's AI features (the in-app assistant, weekly Slack digest, daily anomaly detection, AI-suggested thresholds, and the on-demand health check) are powered by [OpenAI](https://openai.com) via its API.

**What we send to OpenAI:**

* Aggregated product, inventory, and sales metrics (variant titles, SKUs, stock levels, velocity, days of supply, sell-through, projected stockouts)
* For the assistant: the message you type in chat and the relevant inventory context needed to answer it
* For digests, anomalies, and health checks: the metric snapshots needed to write the narrative or finding

**What we do not send to OpenAI:**

* Customer personal data (names, emails, addresses) from your order records. These are discarded during aggregation before any AI processing
* Payment, billing, or staff account credentials
* Any data from another merchant's store

**Data handling at OpenAI:**

Requests are sent through OpenAI's standard API and are subject to OpenAI's API data usage and retention terms. See OpenAI's [Enterprise Privacy](https://openai.com/enterprise-privacy) page for the current details.

**What Stockful stores:**

* Assistant chat messages and AI responses, kept against your shop so you can browse thread history
* AI-generated digests, anomaly narratives, and health-check findings, kept with the rest of your shop's app data
* Feedback you give on AI output (thumbs up/down, helpful/not helpful), used to improve our prompts

You can turn AI features off any time in **Settings → AI**.

## Legal Bases for Processing

We process your data under the following legal bases, depending on your jurisdiction:

* **Contractual necessity** - processing required to deliver the service you've installed
* **Legitimate interests** - improving service quality, ensuring security, and preventing abuse
* **Consent** - where required by local law (e.g., Brazil's LGPD, India's DPDP Act), consent is obtained during app installation

## Third-Party Services

We share data with the following third-party service providers to operate the App. We do not sell, rent, or trade your personal information.

| Service                              | Purpose                                                                                  | Data Shared                                                                                                                      |
| ------------------------------------ | ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| [Cloudflare](https://cloudflare.com) | Application hosting, backend infrastructure, and file storage (Workers, Pages, R2)       | All app data, report files                                                                                                       |
| [Neon](https://neon.tech)            | Primary database (PostgreSQL)                                                            | All app data (primary data store)                                                                                                |
| [Shopify](https://shopify.dev)       | E-commerce platform integration                                                          | Store data via API - read access for everything the App displays, plus the narrow write access set out under Data Security below |
| [Resend](https://resend.com)         | Transactional email delivery                                                             | Recipient email addresses, notification content                                                                                  |
| [Slack](https://slack.com)           | Notification delivery (optional integration)                                             | Inventory alert messages, channel identifiers                                                                                    |
| [Sentry](https://sentry.io)          | Error tracking and monitoring                                                            | Exception data, shop identifier (no inventory data)                                                                              |
| [Axiom](https://axiom.co)            | Operational analytics and event logging                                                  | Event logs, shop identifier, operational metrics                                                                                 |
| [Trigger.dev](https://trigger.dev)   | Background job execution                                                                 | Task payloads (shop identifiers, job parameters)                                                                                 |
| [OpenAI](https://openai.com)         | AI assistant, weekly digest, anomaly narratives, threshold suggestions, and health check | Aggregated product, inventory, and sales data; assistant chat messages. Never customer contact details.                          |

Each provider processes data in accordance with their own privacy policies and is contractually obligated to protect your information.

## Data Security

We implement the following security measures to protect your data:

* **Encryption in transit** - all data transmitted over HTTPS/TLS
* **Access control** - multi-tenant isolation ensures each store can only access its own data
* **Scoped API access** - the App uses the minimum Shopify API scopes required for its features. Most scopes are read-only. The full set is:

  | Scope                                                                                                  | Type  | Purpose                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
  | ------------------------------------------------------------------------------------------------------ | ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | `read_products`                                                                                        | Read  | View product catalog to display inventory.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
  | `write_products`                                                                                       | Write | Three uses: (1) publish app-owned metafields in the `app--stockful` namespace (stock status, days of supply, velocity trend, projected stockout, ABC class, restock status, sold last 30d, tracked flag) so storefronts can display live inventory data; (2) enable the `admin_filterable` capability on merchant-created product and variant metafield definitions so Stockful can filter products by those metafields - the toggle changes only the definition's capability flag, never a merchant metafield value; (3) write variant barcode, retail price and unit cost. Every price or cost write follows an explicit merchant action: editing a variant's fields in Stockful, accepting the retail prices Stockful proposes when a purchase order is received (the merchant reviews each row and any rejected row cancels the whole update), or enabling landed-cost sync, which is off by default and writes the recalculated unit cost when a delivery is received. We do not modify product titles, descriptions, options, media, or any non-Stockful metafield values. |
  | `read_locations`                                                                                       | Read  | List locations to show inventory by location.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
  | `write_locations`                                                                                      | Write | Update a location's name, address, phone number and whether it fulfills online orders, from the location's page in Stockful. Every write follows an explicit merchant edit; nothing changes a location on its own. The address matters beyond the location list - it is the delivery address printed on purchase orders and packing slips sent to suppliers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
  | `read_inventory`                                                                                       | Read  | Read inventory levels for monitoring and forecasting.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
  | `write_inventory`                                                                                      | Write | Two kinds of write, both started by an explicit merchant action. Quantities: applying a stock adjustment or stock count the merchant has built and confirmed in Stockful, and posting the component consumption and finished output of a production run they mark complete. Each quantity change is sent with the figure Stockful last read as a compare-and-swap baseline, so a level that moved in the meantime is rejected rather than overwritten, and a stock count may activate an inventory item at a location that was not yet tracking it. Metadata: correcting missing cost, SKU and HS code on inventory items, from the health-check fix page or the variant edit form. Nothing writes stock on its own - no sync, forecast, or alert changes a quantity.                                                                                                                                                                                                                                                                                                            |
  | `read_orders`, `read_all_orders`                                                                       | Read  | Read order and fulfillment history for sales velocity and demand forecasting. Only aggregate metrics are retained; individual customer personal data is not stored.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  | `read_fulfillments`, `read_merchant_managed_fulfillment_orders`, `read_third_party_fulfillment_orders` | Read  | Attribute stock movements correctly across fulfillment services.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
  | `read_inventory_transfers`                                                                             | Read  | Read inventory transfers to show stock in transit and track the status of transfers created from Stockful.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
  | `write_inventory_transfers`                                                                            | Write | Two uses, both started by an explicit merchant action: (1) acting on a transfer suggestion creates a draft transfer (tagged `stockful`) that the merchant completes in Shopify; (2) marking a purchase order as shipped creates the supplier-inbound transfer for that order as ready to ship (tagged `stockful-po`). Stockful only touches transfers it created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  | `read_inventory_shipments`                                                                             | Read  | Read inventory shipments to keep incoming-stock figures accurate as shipments move and arrive.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
  | `write_inventory_shipments`                                                                            | Write | Create and update the shipment behind a purchase order when the merchant marks that order as shipped - adding the ordered items and saving the tracking details they enter in Stockful. Only shipments Stockful created for a purchase order are modified.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
  | `read_inventory_shipments_received_items`                                                              | Read  | Read received-item quantities on shipments so incoming stock clears correctly when shipments are received, including partial receipts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
  | `write_inventory_shipments_received_items`                                                             | Write | Record received quantities against a purchase order's shipment when the merchant receives stock in Stockful, including partial receipts, so Shopify inventory and incoming-stock figures stay in sync.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
  | `read_publications`, `read_product_listings`                                                           | Read  | Read which sales channels and catalogs a product is published to, so products can be filtered by sales channel, market, or catalog.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  | `read_markets`                                                                                         | Read  | Read the store's markets to label region and B2B catalog filters. Only used if the store has Markets configured.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
  | `read_companies`                                                                                       | Read  | Read B2B company locations to label company-location catalog filters. Only used if the store sells B2B.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
  | `read_reports`                                                                                         | Read  | Run Shopify's analytics queries (ShopifyQL) to import historical sales and inventory-movement aggregates, so sales velocity and stockout history can be backfilled beyond the order data available at install. Only aggregate per-product metrics are read; individual customer personal data is never queried or stored.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
  | `write_app_proxy`                                                                                      | Write | Required by Shopify to register the App Proxy used by storefront features; does not modify store data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
* **Token-protected downloads** - report files require authenticated download tokens
* **Credential protection** - API keys and access tokens are stored securely (AES-256-GCM at rest) and never exposed to the frontend
* **Alignment with Shopify standards** - development and security practices follow Shopify's app development guidelines

## Our Role Under GDPR

For the purposes of the EU/UK General Data Protection Regulation (GDPR) and equivalent laws:

* You (the merchant) are the **data controller** for your store data and your customers' personal data.
* Stockful acts as a **data processor** on your behalf, processing the data only in line with your instructions and this Privacy Policy.

A standalone [Data Processing Agreement](/policies/data-processing-agreement) governs this relationship and satisfies Article 28 of the GDPR. EU/UK-based merchants are deemed to have accepted the DPA on installation; a counter-signed copy is available on request at **[support@stockful.app](mailto:support@stockful.app)**.

## Data Retention and Deletion

* **Inventory and analytics data** - retained for historical tracking and forecasting while the App is installed
* **Report files** - automatically cleaned up based on retention settings
* **Upon uninstallation** - app data is retained for 48 hours in case you reinstall, then permanently deleted
* **If a free trial ends without a subscription** - app data is retained for 30 days after tracking stops (we email a warning before deletion), then permanently deleted
* **Shopify compliance** - we honor all Shopify GDPR/privacy webhooks (customer data requests, customer redaction, and shop redaction)
* **Support records** - retained for up to 3 years for quality and legal purposes
* **Legal obligations** - data may be retained longer where required by applicable law

## Your Rights

Depending on your jurisdiction, you may have the following rights regarding your data:

* **Access** - request a copy of the data we hold about your store
* **Correction** - request correction of inaccurate data
* **Deletion** - request deletion of your data (or uninstall the App)
* **Portability** - request your data in a machine-readable format
* **Restriction** - request that we limit processing of your data
* **Objection** - object to processing based on legitimate interests

### Regional Rights

* **GDPR (EU/EEA/UK)** - you have the right to lodge a complaint with your local supervisory authority
* **CCPA/CPRA (California)** - you have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
* **PIPEDA (Canada)** - you may access and challenge the accuracy of your information
* **LGPD (Brazil)** - you may request confirmation of processing, access, correction, anonymization, or deletion

To exercise any of these rights, contact us at **[support@stockful.app](mailto:support@stockful.app)**.

## Children's Privacy

Stockful is a business-to-business application intended for use by Shopify merchants. We do not knowingly collect information from children under 13 (or the applicable age in your jurisdiction). If you believe we have inadvertently collected such information, please contact us immediately.

## Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.

## Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

* **Email:** [support@stockful.app](mailto:support@stockful.app)
