1. Who we are
Stock Sorted ("we", "us", "our") is operated by Josef Richter, based in the Czech Republic.
This app is available on the Shopify App Store and is designed to help merchants manage
shared inventory across product variants.
2. What data we collect
When you install Stock Sorted, we access the following Shopify data:
-
Store URL and access token — to authenticate API calls to your store
-
Merchant account profile
— store name, contact email, owner name, country, industry, and Shopify plan for account administration, support, billing context, and service operations
-
Product and variant data
— titles, descriptions, SKUs, prices, inventory quantities (to display in the app,
suggest setup, and sync inventory)
-
Order line items
— variant IDs and quantities only (to calculate inventory deductions). We do NOT access customer names, emails, addresses, or payment information.
- Inventory levels — to sync calculated quantities back to Shopify
3. How we use your data
Your data is used exclusively to provide the Stock Sorted service:
- Calculate and sync shared inventory quantities across linked variants
- Process order webhooks to deduct from shared stocks
- Display inventory status and activity logs in the app
- Take inventory snapshots for safety/recovery purposes
We do not sell your data or use it for advertising. We use limited product
analytics and operational notifications to understand app health, installs,
billing changes, and major feature usage.
When processing catalog, inventory, and order data to provide the app, we act on the
merchant's instructions as a processor. For account administration, security,
operational monitoring, and product improvement, we determine the purpose and means
of processing and act as controller.
4. Analytics and consent
On the public Stock Sorted website, Google Analytics and browser-based PostHog remain
off until you choose Accept in the analytics notice. Rejecting analytics does not
affect access to the website or app. You can change or withdraw your choice at any
time through Cookie preferences.
-
Consented public-site events contain the page path and title, device/browser data,
and the placement of an App Store link you select. We strip URL query strings and
do not capture form values.
-
Shopify may send our Google Analytics property App Store listing interactions and,
when installation completes, our app API key, Shopify shop ID, shop name, and shop URL.
-
From the embedded app to Google Analytics, we send only a pseudonymous identifier and
enumerated lifecycle milestones such as first shared stock, onboarding completion,
plan changes, reinstall, and uninstall.
-
Separately, server-side PostHog product analytics may use the store URL as an account
identifier and receive limited account, feature, and operational context such as the
store name, country, plan, pool name, and event outcome. Browser analytics do not run
inside the embedded Shopify app.
We do not send Google Analytics product titles or descriptions, SKUs, pool names,
customer or order details, merchant email or owner name, authentication tokens, AI
prompts or outputs, search text, or free-form error messages. Advertising storage,
advertising user data, personalization, and Google Signals are disabled by our setup.
Google Analytics cookies on our public site expire after at most 90 days and are not
extended by later activity. Our GA4 event-data retention is configured for two months.
PostHog uses browser local and session storage after consent; the consent preference
itself is also stored locally in your browser. Clearing site data removes these local
choices and identifiers. Analytics providers necessarily receive an IP address to
deliver each network request; our public PostHog events ask the provider not to enrich
it into geolocation data.
5. Data storage and security
- Data is stored in a PostgreSQL database hosted on Fly.io (US/EU regions)
- All connections use TLS encryption
-
Shopify access and refresh tokens are encrypted before database writes
- We do not store end-customer personal data (names, emails, addresses)
6. Data retention
- Your data is retained as long as the app is installed on your store
-
When Shopify sends app/uninstalled or shop/redact, your store data is deleted
-
Inventory snapshots, sync logs, billing grants, and shared stock data are deleted with the store record
-
Third-party analytics records follow the retention periods stated above and are not
necessarily deleted at the same moment as the application database
7. GDPR compliance
We are based in the EU (Czech Republic) and comply with the General Data Protection
Regulation (GDPR) in our processor and controller roles. Specifically:
-
Data minimization
— we only access the minimum data needed to provide inventory sync functionality
-
Right to erasure
— uninstalling the app triggers automatic deletion of your data
-
Data portability
— you can export your shared stock configurations and sync history at any time
-
No customer PII
— we never access or store end-customer personal information
-
Consent and objection
— you can reject or withdraw optional public-site analytics and may object to
controller-side processing by contacting us
8. Shopify mandatory webhooks
We handle the following mandatory Shopify privacy webhooks:
-
customers/data_request — we confirm we hold no customer personal data
- customers/redact — acknowledged (no customer data to redact)
- shop/redact — all store data is permanently deleted
9. Third-party services
-
Shopify
— we interact with the Shopify Admin API to read products and set inventory levels
- Fly.io — application hosting and database
- BetterStack and Sentry — production logs and error monitoring
-
Google Analytics and PostHog
— consented public-site analytics and limited app-lifecycle analytics when configured
-
Slack
— operational install, uninstall, and billing notifications when configured
-
Anthropic and Google Gemini
— optional setup suggestions from product titles, product descriptions, variant titles,
SKUs, and accepted shared-stock pool names
Google, PostHog, and other providers may process data outside the EEA. Where required,
we rely on provider data-processing terms and safeguards such as the European
Commission's Standard Contractual Clauses.
10. Contact
For privacy inquiries or data requests, contact:
Josef Richter
Email: josef.richter@me.com
Location: Czech Republic, EU