StockLoop
Terms of Service
Effective date: July 29, 2026
These Terms of Service (the “Terms”) form an agreement between StockLoop (“StockLoop,” “we,” “us”) and the Shopify merchant that installs or uses the StockLoop app (“you,” “Merchant”). By installing StockLoop you accept these Terms and the Privacy Policy, which is incorporated into them. Part B below is our data protection agreement and applies to any personal data we process on your behalf.
Part A — Service terms
1. What StockLoop does
StockLoop is a replenishment workbench for Shopify stores. It mirrors your products, locations and inventory, calculates demand from your sales history, suggests reorder quantities, and helps you create, send, receive and reconcile purchase orders and stock counts. StockLoop is a planning and record-keeping tool: it does not buy goods, hold stock, or act as a party to your dealings with suppliers.
2. Your account and responsibilities
- You are responsible for the accuracy of the data you enter or import — supplier contacts, costs, lead times, minimum order quantities and case packs. Suggested order quantities are only as good as these inputs.
- You are responsible for reviewing anything before it leaves StockLoop or changes your Shopify data: purchase orders before they are sent, extracted supplier details before they are applied, and stock-count variances before they are posted.
- You must have the authority to connect the Shopify store you install StockLoop on, and you must keep access to StockLoop limited to people who need it.
- You must not use StockLoop to break the law, infringe anyone’s rights, interfere with the service or other users, or attempt to gain access to data that is not yours.
3. Suggestions are advice, not decisions
Reorder points, suggested quantities and stockout estimates are calculated from historical sales and the settings you provide. They are estimates. Demand changes, suppliers miss dates, and history does not always predict the future. You remain responsible for your purchasing decisions and their commercial consequences.
4. Fees
Paid plans are billed through Shopify under Shopify’s billing terms. Prices and plan limits are shown in the Shopify App Store and in the app before you subscribe. If we change the price of a plan you are on, we will tell you before the change takes effect and you may cancel instead of accepting it. Shopify handles charges, refunds and taxes according to its own policies.
5. Availability and support
We aim to keep StockLoop available and correct, but we do not promise uninterrupted service. Shopify API limits, Shopify outages, network problems and maintenance can all interrupt syncing. Support is provided by email at support@getstockloop.com.
6. Intellectual property
StockLoop and everything in it other than your data remains ours. Your store data, supplier records and purchase orders remain yours; we process them only to provide the service as described in these Terms and the Privacy Policy.
7. Disclaimers and limits
StockLoop is provided “as is.” To the extent permitted by law we disclaim implied warranties of merchantability, fitness for a particular purpose and non-infringement. To the extent permitted by law, neither party is liable for indirect, incidental, special or consequential losses, or for lost profits or lost goodwill, and our total liability arising out of these Terms is limited to the fees you paid us for StockLoop in the twelve months before the claim arose. Nothing here limits liability that cannot be limited by law.
8. Term and termination
These Terms apply for as long as StockLoop is installed. You may stop using StockLoop at any time by uninstalling it, which ends the agreement. We may suspend or end access if you materially breach these Terms, if required by Shopify or by law, or if we discontinue the app — in the last case we will give reasonable notice where we can. On termination we delete your data as described in the Privacy Policy and in section B7.
9. Changes to these Terms
We may update these Terms to reflect changes to StockLoop, our practices, or the law. We will post the revised Terms here with a new effective date, and for material changes we will make reasonable efforts to notify you in the app or by email. Continuing to use StockLoop after a change takes effect means you accept the revised Terms.
10. Governing law
These Terms are governed by the laws of the jurisdiction in which StockLoop is established, and the courts of that jurisdiction have exclusive jurisdiction over disputes, except that either party may seek injunctive relief where necessary to protect its rights. Nothing in these Terms deprives a merchant who is a consumer under local law of protections that cannot be waived.
Part B — Data protection agreement
This Part applies where we process personal data on your behalf and forms the data processing terms between us. Where applicable data protection law requires a written processing agreement, this Part is that agreement.
B1. Roles
For personal data originating from your Shopify store, you are the controller and StockLoop is the processor. We process that data only on your instructions, which are given by installing StockLoop and using its features, and as set out here and in the Privacy Policy. We will tell you if we believe an instruction breaches applicable data protection law.
B2. What we process, and why
The subject matter is the provision of replenishment planning for your store. The duration is the period StockLoop is installed, plus the short deletion window in section B7. The categories of data subject are your end customers, only to the extent that order activity is involved.
A webhook is reduced to the Shopify order identifier before storage. Shopify classifies order resources as protected customer data, so StockLoop handles the identifiers and order-level demand facts as pseudonymous personal data. StockLoop then reads the current order from Shopify and retains only Shopify order and line identifiers, sold variant, current quantity, and order date so an edit, refund, or cancellation can replace the earlier demand contribution. We do not receive into storage end-customer names, email addresses, phone numbers, or billing or shipping addresses. Product-level daily sales totals are retained separately from the order identifiers and are not tied to an identifiable person.
B3. Purpose limitation
We use this data only to calculate demand and produce the replenishment features you use. We do not use it for our own purposes, do not sell or share it, do not use it for advertising or profiling, and do not use it to train machine learning models. Order data is never sent to any third-party AI service.
B4. Confidentiality and access
Access to production data is limited to personnel who need it to operate and support the service, is authenticated individually, and is subject to confidentiality obligations that survive the end of their engagement.
B5. Security
We maintain technical and organisational measures appropriate to the risk, including:
- encryption in transit using TLS for all connections to the service;
- encryption at rest: the database volume holding merchant data is stored on an encrypted filesystem (LUKS2, AES-XTS with a 512-bit key);
- data minimisation at the point of collection, as described in section B2, so that personal data we do not need is never stored;
- verification of the authenticity of every webhook Shopify sends before it is acted upon, and rejection of requests that fail verification;
- separation of the public internet from internal services, with administrative and internal endpoints unreachable from outside;
- strict scoping of every request to the shop that made it;
- backups of merchant data, and monitoring of service health and errors.
No set of measures makes storage or transmission completely secure. We review these measures as the service changes.
B6. Sub-processors
You authorise us to use the sub-processors below. We impose data protection obligations on them no less protective than these terms, and we remain responsible for their performance. We will give you notice before adding or replacing a sub-processor that processes personal data, and you may object on reasonable data protection grounds — in which case you may stop using the affected feature or uninstall StockLoop.
- Hosting provider — operates the servers and database that run the service.
- Email delivery provider — delivers purchase orders to the supplier addresses you enter. Processes the supplier contact details and purchase order contents you choose to send.
- AI extraction provider — used only for the optional supplier-extraction feature, and only for documents you submit to it. Not used for order data.
B7. Deletion and return
When StockLoop is uninstalled we begin deletion and remove your store’s
data within 48 hours, including on receipt of Shopify’s
shop/redact webhook. Stored webhook payloads are emptied 30 days
after they are processed. Public Rescue imports are deleted after 7 days and
their download links expire after 24 hours; in-app import review data is deleted
after 90 days. You may request earlier deletion, or a copy of your data, by
contacting us. Encrypted disaster-recovery copies are isolated from normal use
and age out through backup rotation; if restored, outstanding deletion requests
are applied again. We otherwise retain data beyond these points only where law
requires it, isolated from normal use.
B8. Data subject requests and assistance
We will assist you in responding to requests from your end customers, and we
process Shopify’s customers/data_request and
customers/redact webhooks. Because we do not store end-customer
personal data, there is ordinarily no customer record for us to provide or
erase. We will also give you the information you reasonably need for a data
protection impact assessment or an audit of our compliance with this Part.
B9. Incidents
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and give you the information you need to meet your own notification obligations, together with what we know about the cause, the data involved, and the steps we are taking.
B10. International transfers
Our service and sub-processors may process data in countries other than yours. Where data protection law requires a transfer mechanism, we rely on an approved mechanism such as the applicable standard contractual clauses, and we apply safeguards appropriate to the data involved.
11. Contact
Questions about these Terms, this data protection agreement, or a privacy request: support@getstockloop.com.