StockFlow — Privacy Policy
StockFlow is an embedded Shopify Admin app, built by Plinth, that helps merchants manage suppliers, purchase orders, receiving, and inventory costing. This policy explains what data we process, why, who we share it with, and how we keep and delete it.
1. Data we process
When you install and use StockFlow, we store the following to provide the app's features:
Store & settings. Your myshopify.com domain and a Shopify
access token (so the app can call the Shopify Admin API on your behalf); and settings you enter
(company name, address, reply-to email, currency, PO number prefix, default tax rate).
Supplier and purchasing data you create. Supplier records (name, email, phone, address, notes, lead time, payment terms, account number, tax rate — business contact information about your suppliers that you enter); supplier–product links, purchase orders and line items, receiving records, weighted-average costs, and any files you attach to a purchase order.
Data we read from Shopify. Products, variants, inventory items, inventory levels, and locations (to build POs and sync received stock); and order line-item quantities, used only to estimate sales velocity for reorder forecasting.
2. Data we do NOT collect
StockFlow does not collect, store, or process your customers' personal data — no customer names, emails, phone numbers, addresses, or payment information. Our forecasting reads only product/variant identifiers and quantities from orders, never customer fields.
3. How we use data
Solely to operate the app: managing suppliers and purchase orders, generating PO PDFs, emailing POs to your suppliers, receiving stock and syncing inventory quantities to Shopify, and calculating reorder suggestions and inventory cost. We do not sell your data or use it for advertising.
4. Sharing and sub-processors
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Railway | Application hosting and database | All app data in §1 |
| Resend | Sending purchase-order emails to suppliers | Supplier email, the PO PDF/CSV, your reply-to address |
| Shopify | Platform APIs and authentication | API requests scoped to your store |
We do not share your data with any other third parties except where required by law.
5. Data retention and deletion
- We retain your data for as long as the app is installed.
- When you uninstall, your sessions are revoked. Within 30 days
we delete your store's data in response to Shopify's
shop/redactrequest — this cascades to all suppliers, purchase orders, line items, receiving records, attachments, variant costs, and settings. - Because we hold no customer personal data, Shopify's
customers/redactandcustomers/data_requestwebhooks have no customer data to erase or return; we acknowledge them as required. - You may request deletion of your data at any time by emailing plinth.support@gmail.com.
6. Security
- All traffic is served over HTTPS.
- Every request is authenticated through Shopify session tokens, and the app only ever accesses data belonging to your own store.
- Access tokens and app data are stored in our hosting provider's managed database with access restricted to the application.
7. International transfers
Data may be processed in the regions where our sub-processors operate (including the United States). By using the app you consent to this processing.
8. Your rights (GDPR / CCPA)
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your data. Email plinth.support@gmail.com to exercise them; we honor Shopify's mandatory data-deletion webhooks automatically.
9. Changes to this policy
We may update this policy; we will revise the effective date above and, for material changes, notify merchants through the app or by email.