Last updated: September 23, 2026
When a store installs Inventory Management, Shopify issues an API access token, a refresh token, and the granted access scopes, which we store together with the store's myshopify domain. We use these only to access the store's data on the merchant's behalf. If a staff member opens the app with an online session, Shopify also provides that staff member's name, email, locale, user ID, and account-owner/collaborator status, which we keep until the app is uninstalled (see Retention). The app does not currently collect any information about shoppers.
To show low-stock thresholds and status, we also store a copy of each product and variant's title, SKU, and current inventory quantity, which collections each product belongs to, and the threshold values the merchant configures (store-wide, per-collection, and per-product). This is store and product data, not personal data about shoppers or staff.
We use this data only to run the app for the installing store; it is never sold or shared for advertising.
Session data, and the product/inventory/threshold data described above, are deleted when the app is uninstalled, and again when Shopify sends the shop/redact request, which happens 48 hours after uninstall.
We answer Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Shoppers with questions about their data should contact the store owner, and merchants can contact us directly using the details below.
This policy is updated whenever new features start processing new data (for example, shopper emails for back-in-stock alerts), and the date above changes to reflect that.
Questions about this policy or a data request/deletion can be sent to hoangtrongtaitb95@gmail.com.