Legal
Shelfback – Privacy Policy
Last updated: 2026-08-30
Shelfback (“the App”, “we”, “us”) is a Shopify app that helps merchants keep
sold-out products out of prime collection positions and identify which products
to restock first. This policy explains what data the App accesses, how it is
used, and your choices. It is written to satisfy Shopify’s App Store
requirements and common privacy laws (GDPR/CCPA).
Who this applies to
This policy is for merchants who install Shelfback on their Shopify store.
Shelfback does not interact with, collect data from, or display anything to
your customers (shoppers). It has no storefront component.
What data the App accesses
When you install Shelfback, it requests these Shopify Admin API permissions and
uses them only for the App’s stated purpose:
| Permission | Why the App needs it | What the App does with it |
|---|---|---|
| read_products | Read product titles, handles, status, tags, vendor, type, images | Detect stock status; display your catalog in the dashboard |
| read_inventory | Read variant inventory levels and availability | Determine which products are out of stock or low |
| write_products | Reorder products within manually-sorted collections | Move sold-out products to the bottom of eligible collections |
| read_orders | Read order line items (quantity, product, line total) from the last ~30–60 days | Compute aggregate per-product units sold and revenue, to rank “best sellers at risk” and prioritize restocking |
About order data
The App reads order data solely to calculate aggregate, per-product sales totals (units sold and revenue over a rolling window). The App does not
read, store, display, or transmit customer personal information — no customer
names, emails, addresses, phone numbers, or payment details. Only a running
count and revenue figure per product are retained.
What data the App stores
The App stores, per store, only what is needed to operate:
- Your store domain and the store-owner email address (used to send you alerts).
- Per-product operational data: title, handle, status, image URL, stock status,
out-of-stock/restocked timestamps, and aggregate sales/revenue counts. - A record of automated actions (which products were moved, when, and why).
- Your App settings (thresholds, automation toggles, exclusions, notification
preferences). - Shopify session/authentication tokens required to call the Admin API.
The App does not store any shopper/customer personal data.
How data is used
- To detect out-of-stock and low-stock products and move sold-out products to
the bottom of eligible collections. - To rank products by restock priority and highlight best-sellers at risk.
- To send you (the merchant) email notifications and an optional daily
digest about your inventory.
We do not sell your data, and we do not share it with third parties except the
service providers strictly required to run the App (see below).
Third-party service providers
- Railway — application hosting and the PostgreSQL database where the data
above is stored. - Resend — sends your notification emails. Only your store-owner email
address and the message content are shared, to deliver the email. - Shopify — the source of the product/inventory/order data, via the
Admin API.
Data retention & deletion
- Data is retained while the App is installed.
- When you uninstall the App, its access is revoked. Shopify sends a
shop/redact request approximately 48 hours later, at which point the App
permanently deletes all stored data for your store. - You may request deletion of your data at any time by contacting us (below).
- The App fully implements Shopify’s mandatory compliance webhooks
(customers/data_request, customers/redact, shop/redact). Because the App
stores no customer personal data, the customer-level requests are no-ops; the
shop-level request performs a complete deletion.
Security
Data is transmitted over TLS and stored in a managed PostgreSQL database with
access restricted to the App. Authentication tokens are handled by Shopify’s
official app libraries.
Your rights
Depending on your jurisdiction (e.g. GDPR, CCPA), you may have rights to access,
correct, or delete your data, or to object to processing. Contact us to
exercise these rights.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected
by the “Last updated” date above.
Contact
For any privacy question or data request, contact:
support@twinecom.com