Privacy Policy

Last updated: July 22, 2026

1. Who we are

Stock Sorted ("we", "us", "our") is operated by Josef Richter, based in the Czech Republic. This app is available on the Shopify App Store and is designed to help merchants manage shared inventory across product variants.

2. What data we collect

When you install Stock Sorted, we access the following Shopify data:

  • Store URL and access token — to authenticate API calls to your store
  • Merchant account profile — store name, contact email, owner name, country, industry, and Shopify plan for account administration, support, billing context, and service operations
  • Product and variant data — titles, descriptions, SKUs, prices, inventory quantities (to display in the app, suggest setup, and sync inventory)
  • Order line items — variant IDs and quantities only (to calculate inventory deductions). We do NOT access customer names, emails, addresses, or payment information.
  • Inventory levels — to sync calculated quantities back to Shopify

3. How we use your data

Your data is used exclusively to provide the Stock Sorted service:

  • Calculate and sync shared inventory quantities across linked variants
  • Process order webhooks to deduct from shared stocks
  • Display inventory status and activity logs in the app
  • Take inventory snapshots for safety/recovery purposes

We do not sell your data or use it for advertising. We use limited product analytics and operational notifications to understand app health, installs, billing changes, and major feature usage.

When processing catalog, inventory, and order data to provide the app, we act on the merchant's instructions as a processor. For account administration, security, operational monitoring, and product improvement, we determine the purpose and means of processing and act as controller.

4. Analytics and consent

On the public Stock Sorted website, Google Analytics and browser-based PostHog remain off until you choose Accept in the analytics notice. Rejecting analytics does not affect access to the website or app. You can change or withdraw your choice at any time through Cookie preferences.

  • Consented public-site events contain the page path and title, device/browser data, and the placement of an App Store link you select. We strip URL query strings and do not capture form values.
  • Shopify may send our Google Analytics property App Store listing interactions and, when installation completes, our app API key, Shopify shop ID, shop name, and shop URL.
  • From the embedded app to Google Analytics, we send only a pseudonymous identifier and enumerated lifecycle milestones such as first shared stock, onboarding completion, plan changes, reinstall, and uninstall.
  • Separately, server-side PostHog product analytics may use the store URL as an account identifier and receive limited account, feature, and operational context such as the store name, country, plan, pool name, and event outcome. Browser analytics do not run inside the embedded Shopify app.

We do not send Google Analytics product titles or descriptions, SKUs, pool names, customer or order details, merchant email or owner name, authentication tokens, AI prompts or outputs, search text, or free-form error messages. Advertising storage, advertising user data, personalization, and Google Signals are disabled by our setup.

Google Analytics cookies on our public site expire after at most 90 days and are not extended by later activity. Our GA4 event-data retention is configured for two months. PostHog uses browser local and session storage after consent; the consent preference itself is also stored locally in your browser. Clearing site data removes these local choices and identifiers. Analytics providers necessarily receive an IP address to deliver each network request; our public PostHog events ask the provider not to enrich it into geolocation data.

5. Data storage and security

  • Data is stored in a PostgreSQL database hosted on Fly.io (US/EU regions)
  • All connections use TLS encryption
  • Shopify access and refresh tokens are encrypted before database writes
  • We do not store end-customer personal data (names, emails, addresses)

6. Data retention

  • Your data is retained as long as the app is installed on your store
  • When Shopify sends app/uninstalled or shop/redact, your store data is deleted
  • Inventory snapshots, sync logs, billing grants, and shared stock data are deleted with the store record
  • Third-party analytics records follow the retention periods stated above and are not necessarily deleted at the same moment as the application database

7. GDPR compliance

We are based in the EU (Czech Republic) and comply with the General Data Protection Regulation (GDPR) in our processor and controller roles. Specifically:

  • Data minimization — we only access the minimum data needed to provide inventory sync functionality
  • Right to erasure — uninstalling the app triggers automatic deletion of your data
  • Data portability — you can export your shared stock configurations and sync history at any time
  • No customer PII — we never access or store end-customer personal information
  • Consent and objection — you can reject or withdraw optional public-site analytics and may object to controller-side processing by contacting us

8. Shopify mandatory webhooks

We handle the following mandatory Shopify privacy webhooks:

  • customers/data_request — we confirm we hold no customer personal data
  • customers/redact — acknowledged (no customer data to redact)
  • shop/redact — all store data is permanently deleted

9. Third-party services

  • Shopify — we interact with the Shopify Admin API to read products and set inventory levels
  • Fly.io — application hosting and database
  • BetterStack and Sentry — production logs and error monitoring
  • Google Analytics and PostHog — consented public-site analytics and limited app-lifecycle analytics when configured
  • Slack — operational install, uninstall, and billing notifications when configured
  • Anthropic and Google Gemini — optional setup suggestions from product titles, product descriptions, variant titles, SKUs, and accepted shared-stock pool names

Google, PostHog, and other providers may process data outside the EEA. Where required, we rely on provider data-processing terms and safeguards such as the European Commission's Standard Contractual Clauses.

10. Contact

For privacy inquiries or data requests, contact:
Josef Richter
Email: josef.richter@me.com
Location: Czech Republic, EU