StockLoop

Privacy Policy

Effective date: August 14, 2026

This Privacy Policy explains how StockLoop (“StockLoop,” “we,” “us,” or “our”) collects, uses, shares, and deletes information when a Shopify merchant installs or uses the StockLoop app. StockLoop is a replenishment workbench that helps merchants plan purchases, manage purchase orders, receive and count stock, and reconcile inventory with Shopify.

We minimise end-customer data. We do not store customer names, email addresses, phone numbers, billing or shipping addresses, or payment details. We do retain pseudonymous Shopify order and line identifiers with product, quantity and date while they are needed to correct demand after an edit, refund or cancellation. Shopify treats order data as protected customer data, and so do we.

1. Information we collect

To provide StockLoop, we process the following merchant and Shopify store data:

2. How we use information

We use this information only to provide, secure, maintain, and support StockLoop’s replenishment features, including to:

StockLoop does not sell merchant or Shopify data, use it for third-party advertising, or use it to build advertising profiles. Replenishment suggestions assist the merchant’s decisions; they do not make legal or similarly significant decisions about individuals.

3. Optional AI supplier extraction and third parties

AI supplier extraction is optional and runs only after a merchant submits a document for that purpose. Depending on the extraction service available, the submitted document may be sent securely to DeepSeek or Anthropic to identify supplier fields. We send only the content needed for that extraction. StockLoop data is not sent to either provider for advertising, and unrelated store data is not included.

Merchants should review documents before submitting them and remove any information that is not needed for supplier extraction. StockLoop does not intentionally send or store end-customer PII through this feature.

4. Retention, uninstall, and Shopify privacy webhooks

We retain store data only while it is needed to provide StockLoop to an installed store. When a merchant uninstalls StockLoop, we begin the deletion process and delete the store’s StockLoop data within 48 hours. We support and process Shopify’s mandatory privacy webhooks as follows:

A merchant may also request deletion before uninstalling by contacting us at the address below. Data may be retained only when and for as long as applicable law requires it, in which case it will be isolated from normal use.

5. Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data we process. These include encrypted transport (TLS) for all connections; encryption at rest, with the database volume holding merchant data stored on an encrypted filesystem (LUKS2, AES-XTS with a 512-bit key); reducing order data to the fields we actually use before it is written to storage, so personal data we do not need is never stored; verifying that every webhook genuinely came from Shopify before acting on it; keeping administrative and internal endpoints unreachable from the public internet; scoping every request to the store that made it; access controls based on job requirements; backups; service monitoring; and procedures for responding to security incidents. No method of storage or transmission is completely secure, but we regularly review our safeguards and limit the data StockLoop handles.

6. Merchant privacy rights

Subject to applicable law, merchants may request access to, correction of, deletion of, restriction of, or a portable copy of their personal information. They may also object to certain processing or withdraw consent where processing relies on consent. A merchant can make a request using the contact details below. We may need to verify the requester’s identity and authority over the relevant store before completing the request.

European Economic Area and United Kingdom merchants may also complain to their local data protection authority. California residents may request to know, correct, or delete covered personal information. StockLoop does not sell or share personal information for cross-context behavioral advertising.

7. Changes to this policy

We may update this Privacy Policy to reflect changes to StockLoop, our data practices, or applicable law. We will post the revised policy on this page and update the effective date. If a change materially affects how we use store data, we will provide additional notice where required.

8. Contact

Questions, privacy requests, and security reports may be sent to support@getstockloop.com. Please include the Shopify store domain associated with the request so we can verify and process it.