Privacy Policy

Stockly · Last updated September 1, 2026

Stockly ("we", "our", "the app") is a Shopify app that monitors inventory levels, automates purchase orders and supplier reorders, and sends alerts to store owners. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

  • Store information — your Shopify shop domain, access token, and account email, obtained via Shopify OAuth when you install the app.
  • Product and inventory data — product titles, SKUs, metafields, and inventory quantities synced from your Shopify store to power alert calculations and reorder forecasting.
  • Supplier and Purchase Order records — vendor contact details, sourcing platform URLs (e.g. AliExpress, Alibaba), shipment tracking numbers, preferred currencies, and order history created within the app.
  • Notification settings — email addresses you provide for receiving alerts, and your phone number if you verify it for WhatsApp alerts (coming soon).
  • Slack — an access token and incoming-webhook URL obtained via Slack OAuth when you connect a Slack workspace, used only to post alerts to the channel you choose.
  • Asana — an OAuth access token and refresh token, plus the workspace, project, and section names you select, used only to create a task in Asana for each stock event you map.
  • Klaviyo — the private API key you provide, used only to send inventory event data to your own Klaviyo account.
  • Outbound webhook — the URL you provide; we POST a JSON payload of the alert event to it. We do not store the payload beyond delivery.
  • Alert history — a log of notifications sent, including product name, alert type, and timestamp.
  • Back-in-stock subscribers — email addresses collected via the optional storefront widget from customers who opt in to restock notifications. These are collected with customer consent and are used solely to send a single restock email per product.
  • Order data (read-only) — aggregate sales counts from your last 30 days of orders, used only to calculate stock-out prediction ("days remaining"). Individual order details are not stored.

2. How We Use Your Data

  • To monitor your inventory and send low-stock, out-of-stock, and restock alerts by email or Slack (and WhatsApp, coming soon).
  • To generate purchase orders, track vendor lead times, compute reorder points, and convert multi-currency costs to your store base currency.
  • To provide 1-click shipment tracking across global postal and express logistics carriers.
  • To create Asana tasks and/or send events to Klaviyo or your outbound webhook URL, for the channels you choose to connect.
  • To calculate stock-out predictions, reorder dates, and sales velocity trends.
  • To send digest email summaries and back-in-stock notifications to subscribed customers.
  • To display analytics about your alert history and inventory health within the app.

We do not sell, rent, or share your data with third parties for marketing purposes.

3. Data Storage and Security

Data is stored in a PostgreSQL database hosted on Supabase (EU West region). Access tokens are encrypted at rest. We use HTTPS for all data in transit. Access to the database is restricted to application servers only.

4. Data Retention

Your data is retained for as long as your store has the app installed. When you uninstall Stockly, Shopify sends us a shop/redact webhook within 48 hours, which permanently deletes all your store data from our systems — including settings, product tracking records, purchase orders, suppliers, alert history, back-in-stock subscribers, and any connected Slack, Asana, or Klaviyo tokens and configuration.

5. Third-Party Services

  • Shopify — the platform through which you authenticate and from which we read inventory and order data. Subject to Shopify's Privacy Policy.
  • Supabase — database hosting. Subject to Supabase's Privacy Policy.
  • Fly.io — application hosting. Subject to Fly.io's Privacy Policy.
  • ExchangeRate API (open.er-api.com) — used to fetch public, real-time fiat currency exchange rates for multi-currency purchase order conversions. No store or merchant data is transmitted.
  • Google Gemini AI — used on-demand when you run the AI Supplier Extractor to parse product metafields for vendor contacts and marketplace URLs.
  • SMTP provider — used to deliver email notifications and purchase order emails. Email addresses are passed to our email provider only for the purpose of sending notifications.
  • Slack — if you connect Slack, alert payloads are sent to the workspace and channel you authorize. Subject to Slack's Privacy Policy.
  • WhatsApp (Meta) — coming soon. Once available, alerts to a verified WhatsApp number will be delivered via the WhatsApp Business Platform, subject to WhatsApp's Privacy Policy.
  • Asana — if you connect Asana, stock event data (product name, quantity) is sent to create tasks in the workspace and project you choose. Subject to Asana's Privacy Policy.
  • Klaviyo — if you connect Klaviyo, inventory event data is sent to your own Klaviyo account. Subject to Klaviyo's Privacy Policy.
  • Your outbound webhook endpoint — if you configure one, we POST alert event data to the URL you provide (e.g. Zapier, Make, or your own systems). You are responsible for how that destination handles the data.

6. GDPR and Your Rights

If you or your customers are in the European Economic Area (EEA), you have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of your data.
  • Object to or restrict processing of your data.
  • Data portability — receive your data in a structured format.

We comply with Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Back-in-stock customer emails are collected with explicit opt-in consent and can be deleted at any time via the unsubscribe link in each notification email or by contacting us.

7. Children's Privacy

Stockly is intended for use by Shopify merchants (businesses). We do not knowingly collect data from individuals under 16 years of age.

8. Changes to This Policy

We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes. Continued use of the app after changes constitutes acceptance of the updated policy.

9. Contact

For privacy-related questions or data requests, contact us at: [email protected]