Privacy Policy

Effective Date: December 19, 2025

Last Updated: December 19, 2025

This Privacy Policy explains how Back-in-Stock ("we," "us," or "our") collects, uses, stores, and protects merchant and customer data when you use our Shopify app. We are committed to transparency and compliance with privacy laws including GDPR, CCPA, and applicable data protection regulations.

1. Information We Collect

1.1 Merchant Data

When you install Back-in-Stock on your Shopify store, we collect and store:

1.2 Customer Data

When your store's customers subscribe to back-in-stock notifications via the storefront widget, we collect:

1.3 Technical Data

1.4 Data We Do NOT Collect

2. How We Use Your Data

2.1 Primary Purpose: Back-in-Stock Notifications

2.2 App Functionality & Support

2.3 Legal Compliance

3. Data Sharing & Third Parties

3.1 Third-Party Services We Use

We share data with the following third-party services to provide app functionality:

Service Purpose Data Shared
Shopify APIs Product data, inventory updates Shop domain, access tokens
SMTP Email Service Send restock notification emails Customer emails, email content
Database Hosting (Oracle/PostgreSQL) Data storage and persistence All app data (encrypted)

Note: We use reputable third-party infrastructure providers with appropriate security certifications. We do not sell, rent, or share your data with third parties for marketing purposes.

3.2 We Do NOT Share Data With

4. Data Retention & Deletion

4.1 Retention Periods

4.2 Automatic Deletion

Data is automatically deleted in the following scenarios:

5. Data Security

We implement industry-standard security measures to protect your data:

5.1 Technical Safeguards

5.2 Operational Safeguards

5.3 Limitations

While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security but commit to:

6. Your Rights (GDPR & CCPA)

6.1 Merchant Rights

As a merchant, you have the right to:

6.2 End Customer Rights (GDPR)

Customers who have subscribed to restock notifications have the right to:

6.3 How to Exercise Your Rights

For Merchants: Contact us at [email protected] with your shop domain.

For Customers: Contact your merchant directly, or email us at [email protected].

GDPR Automated Compliance: We automatically respond to Shopify's GDPR webhooks (customers/data_request, customers/redact, shop/redact) to fulfill data access and deletion requests within required timeframes.

7. Children's Privacy

Back-in-Stock is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected].

8. International Data Transfers

Your data may be transferred to and processed in countries outside of your jurisdiction, including the United States and European Union. We ensure appropriate safeguards are in place:

9. Cookies & Tracking

Back-in-Stock uses minimal cookies and tracking:

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

Notification: We will notify you of material changes via email to your shop's billing email address or through an in-app notification at least 30 days before the changes take effect.

Effective Date: The "Last Updated" date at the top of this policy indicates when changes were last made.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email (General Inquiries): [email protected]

Email (Privacy & Data Requests): [email protected]

Response Time: We will respond to all privacy requests within 30 days (or as required by applicable law).

12. Legal Basis for Processing (GDPR)

Under GDPR, we process data based on the following legal grounds:

13. Data Protection Officer

For EU/UK merchants and customers, you may contact our Data Protection Officer (DPO) at:

Email: [email protected]


Summary

What we collect: Shop info, customer emails, product subscriptions
Why: To send automated restock notifications
How long: Until you uninstall the app or customer data is deleted via GDPR request
Your rights: Access, delete, export your data anytime
Security: Encrypted storage, HTTPS, HMAC verification, regular audits