Privacy Policy
This policy covers the Stockitory app itself: what it accesses from your Shopify store, what we store, and how you can control it.
Effective date: 2026-07-23
Contact: support@stockitory.com
Who this covers
Stockitory (“the app”, “we”, “us”) is a purchase-order and inventory-receiving app for Shopify merchants, operated by morabie, an independent software developer, as a sole proprietorship. This policy explains what data Stockitory accesses through your Shopify store, what we store, and how you can control it.
What we access from your Shopify store
Stockitory requests these Shopify API scopes, and no others:
read_products- Look up product/variant title, SKU, and barcode when you add a line to a purchase order.
read_inventory- Show current on-hand stock counts.
write_inventory- Adjust inventory levels, but only when you explicitly receive a purchase order or record a stock count. Never on PO creation or edit.
read_locations- Let you pick which store location a purchase order or count applies to.
We do not request any customer-data scope. Stockitory never sees your customers' names, emails, addresses, order history, or any other personal data about the people who buy from your store.
What we store
Stockitory keeps its own database, separate from Shopify's, holding only merchant/operational data you create in the app:
- Supplier records you create (name, contact info you enter).
- Purchase orders and their line items, including a snapshot of each product's title/SKU/barcode at the time the line was added, so your PO history stays accurate even if a product is later renamed or deleted in Shopify.
- Receiving records (what was received, when, at what cost) and stock-count records.
- Your shop's billing/subscription status.
We do not store your customers' personal data, payment details, or order data. None of that is in scope for what the app does.
Where data is stored and who processes it
- Shopify: the platform Stockitory is built on. See Shopify's own privacy policy (shopify.com/legal/privacy) for how Shopify itself handles data.
- Neon (Postgres database hosting): stores the operational data listed above.
- Amazon Web Services: hosts the app's compute (AWS App Runner) and manages application secrets (AWS Secrets Manager); request/error logs are kept in AWS CloudWatch Logs for a limited retention period for debugging and reliability.
We do not sell merchant or store data to third parties, and we do not share it beyond what's needed to run the service (the processors listed above).
Data retention and deletion
- Data is kept for as long as your store has Stockitory installed, so your purchase-order history stays available to you.
- If you uninstall the app, we stop receiving new webhooks but do not immediately delete your data, in case you reinstall.
- If Shopify sends us a
shop/redactrequest (per Shopify's mandatory GDPR webhook requirements, sent some time after uninstall), we permanently delete every record tied to your shop from our database. - If Shopify sends us a
customers/data_requestorcustomers/redactwebhook, we acknowledge it but hold no customer data to return or delete. There is nothing to act on, by design (see “What we access” above).
Security
- All data in transit is encrypted (HTTPS/TLS).
- The app authenticates every request using Shopify's session-token system: no passwords, no third-party cookies.
- Application secrets are stored in AWS Secrets Manager, not in code.
Your rights
You can request a copy of, or deletion of, the data Stockitory holds about your store at any time by contacting us at support@stockitory.com, or by uninstalling the app (which triggers the deletion path above).
Changes to this policy
If this policy changes, we'll update the effective date above. Material changes will be communicated to installed merchants.
Contact
Questions about this policy or your data: support@stockitory.com