Jump to section
Introduction
Welcome to Stockpilot. We respect your privacy and are committed to protecting your store's data. This policy explains what we collect when you install our Shopify application, why we collect it, and your rights under applicable law.
This policy applies to all merchants who install Stockpilot from the Shopify App Store.
Data Collection
To deliver inventory intelligence, purchase order management, and vendor CRM features, we retrieve specific metadata from your Shopify store via the official Admin API:
- Merchant Identity: Store name, primary email, and domain — used to authenticate your account and scope all data to your shop.
- Inventory & Product Data: Stock levels, variant IDs, SKUs, product titles, and vendor names — used to power the SKU Leaderboard, stockout alerts, and draft order creation.
- Order & Sales Data: Order totals, line item counts, and historical sales frequency — used to calculate velocity, ABC classification, and safety stock recommendations. No customer names, emails, or addresses are accessed.
- Vendor Metadata (your input): Supplier names, contact details, lead times, and MOQ you enter in the Vendor CRM — stored in our database and scoped exclusively to your shop.
- Store Settings: Your store address and preferred location — used to pre-fill purchase orders.
Strict Privacy Guarantee: We do not collect, store, or access any Personally Identifiable Information (PII) of your store's customers. Customer names, emails, and shipping addresses are never accessed or stored.
Purpose of Processing
We use the data we collect solely to provide the services you've requested:
- Generating real-time safety stock alerts, stockout predictions, and replenishment recommendations.
- Powering the purchase order workflow — from draft creation to receipt tracking.
- Maintaining your private Vendor CRM and supplier directory.
- Providing technical support specific to your store configuration.
- Ensuring compliance with Shopify's developer platform policies.
We do not use your data for advertising, cross-merchant analytics, or any purpose beyond operating the app for your store.
Your Legal Rights
Under applicable law (including GDPR and CCPA), you have the right to:
- Request a copy of all metadata we hold for your store.
- Request immediate correction of inaccurate data.
- Request permanent deletion of your store's data.
- Withdraw consent at any time by uninstalling the app — deletion is automatic.
To exercise any of these rights, contact us at the address in Section 7.
Data Retention
We keep your store's data only for as long as you use the app.
The moment you uninstall Stockpilot, we delete the credentials that let us reach your store, so we can no longer read anything from it. Shopify then instructs us to erase the store's data — it sends that instruction around 48 hours after an uninstall — and at that point we permanently delete everything we hold for your store: your settings, suppliers, cost prices, purchase orders, reorder rules and restock waitlist.
That short gap is deliberate. Uninstalls are sometimes accidental, and reinstalling within it brings your data back exactly as you left it. Once the erasure runs, it is permanent and cannot be recovered.
We comply with Shopify's mandatory privacy webhooks (customers/redact, shop/redact, customers/data_request). You can also ask us to erase your data at any time using the details in Section 7.
Contact Details
For questions about this policy, to request a data export, or to exercise your privacy rights:
Email: support@getstockpilot.xyz
Business: Stockpilot
Availability: Mon–Fri, 9 am – 5 pm GMT
Last updated: August 2026