StockLoop
Privacy Policy
Effective date: August 14, 2026
This Privacy Policy explains how StockLoop (“StockLoop,” “we,” “us,” or “our”) collects, uses, shares, and deletes information when a Shopify merchant installs or uses the StockLoop app. StockLoop is a replenishment workbench that helps merchants plan purchases, manage purchase orders, receive and count stock, and reconcile inventory with Shopify.
1. Information we collect
To provide StockLoop, we process the following merchant and Shopify store data:
- Products and inventory: products, variants, SKUs, inventory levels, and inventory adjustments needed to keep StockLoop and Shopify aligned.
- Sales aggregates: Shopify order and line identifiers, sold variant, current quantity, and order date are processed into product-level, time-based totals. The identifiers let edits, refunds, and cancellations replace an earlier contribution. We do not retain direct customer identifiers such as name, email, phone number, postal address, or payment details.
- Locations: Shopify location identifiers, names, and the inventory assigned to each location.
- Suppliers and purchasing: supplier details entered by the merchant, purchase orders, lead times, costs, payment terms, receiving records, and stock-count records.
- Store connection data: the shop identifier and authorization credentials required to connect StockLoop securely to the merchant’s Shopify store.
- Merchant-submitted documents: only when a merchant chooses an optional supplier-extraction feature, the purchase-order, invoice, or supplier document the merchant submits and the supplier fields extracted from it.
- Merchant notification preferences: when a merchant opts into the inventory action digest, the recipient email address, shop-local delivery hour, and delivery success or failure status needed to operate that email.
- Product-use milestones: allow-listed events such as first supplier creation, Buying Table view, purchase-order send, completed receipt, posted count, inventory-confidence view, and digest use. These records contain the store id, event type, internal resource id, and time; they do not contain customer, catalogue, supplier-contact, or digest-recipient data and are not sent to an external analytics provider.
2. How we use information
We use this information only to provide, secure, maintain, and support StockLoop’s replenishment features, including to:
- calculate product-level demand and explain suggested order quantities;
- create, send, and track purchase orders, including PDF and email delivery;
- support barcode receiving, stock counts, and inventory reconciliation;
- sync products, locations, and inventory with Shopify;
- extract supplier fields from a document when the merchant expressly chooses that feature;
- send an inventory action digest when the merchant expressly enables it;
- understand activation and improve StockLoop using privacy-minimal, first-party milestones; and
- respond to support, privacy, reliability, and security requests.
StockLoop does not sell merchant or Shopify data, use it for third-party advertising, or use it to build advertising profiles. Replenishment suggestions assist the merchant’s decisions; they do not make legal or similarly significant decisions about individuals.
3. Optional AI supplier extraction and third parties
AI supplier extraction is optional and runs only after a merchant submits a document for that purpose. Depending on the extraction service available, the submitted document may be sent securely to DeepSeek or Anthropic to identify supplier fields. We send only the content needed for that extraction. StockLoop data is not sent to either provider for advertising, and unrelated store data is not included.
Merchants should review documents before submitting them and remove any information that is not needed for supplier extraction. StockLoop does not intentionally send or store end-customer PII through this feature.
4. Retention, uninstall, and Shopify privacy webhooks
We retain store data only while it is needed to provide StockLoop to an installed store. When a merchant uninstalls StockLoop, we begin the deletion process and delete the store’s StockLoop data within 48 hours. We support and process Shopify’s mandatory privacy webhooks as follows:
- shop/redact: triggers deletion of the shop’s stored StockLoop data, including products, inventory, locations, suppliers, purchase orders, sales aggregates, submitted extraction documents, notification preferences, and product-use milestones.
- customers/data_request: we prepare a report containing any stored order and demand records named by Shopify. The merchant can securely download that report in StockLoop Settings and provide it to the requester.
- customers/redact: we delete the order and line identifiers named by Shopify. Anonymous product-level daily totals remain because they can no longer be connected to that order or customer.
A merchant may also request deletion before uninstalling by contacting us at the address below. Data may be retained only when and for as long as applicable law requires it, in which case it will be isolated from normal use.
- Processed webhook payloads are emptied after 30 days; their non-content delivery ids remain to prevent a duplicate delivery being applied twice.
- Customer data-request reports contain only the requested order-level demand records. They remain pending until the merchant opens them and are deleted 30 days after that.
- Public Stocky Rescue uploads and extracted rows are deleted after 7 days. A generated download link expires after 24 hours.
- Merchant import uploads and extracted review rows are deleted after 90 days. Supplier records a merchant approves are retained while the app is installed.
- Encrypted disaster-recovery backups are isolated from ordinary use. A deletion is applied to active systems within 48 hours and ages out of retained backup copies through backup rotation; a backup is restored only for disaster recovery, after which deletion requests are applied again.
5. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data we process. These include encrypted transport (TLS) for all connections; encryption at rest, with the database volume holding merchant data stored on an encrypted filesystem (LUKS2, AES-XTS with a 512-bit key); reducing order data to the fields we actually use before it is written to storage, so personal data we do not need is never stored; verifying that every webhook genuinely came from Shopify before acting on it; keeping administrative and internal endpoints unreachable from the public internet; scoping every request to the store that made it; access controls based on job requirements; backups; service monitoring; and procedures for responding to security incidents. No method of storage or transmission is completely secure, but we regularly review our safeguards and limit the data StockLoop handles.
6. Merchant privacy rights
Subject to applicable law, merchants may request access to, correction of, deletion of, restriction of, or a portable copy of their personal information. They may also object to certain processing or withdraw consent where processing relies on consent. A merchant can make a request using the contact details below. We may need to verify the requester’s identity and authority over the relevant store before completing the request.
European Economic Area and United Kingdom merchants may also complain to their local data protection authority. California residents may request to know, correct, or delete covered personal information. StockLoop does not sell or share personal information for cross-context behavioral advertising.
7. Changes to this policy
We may update this Privacy Policy to reflect changes to StockLoop, our data practices, or applicable law. We will post the revised policy on this page and update the effective date. If a change materially affects how we use store data, we will provide additional notice where required.
8. Contact
Questions, privacy requests, and security reports may be sent to support@getstockloop.com. Please include the Shopify store domain associated with the request so we can verify and process it.