Privacy policy

Last updated: 17 July 2026

Restock Relay is a Shopify app that sends one transactional email to a shopper when a product they asked about is back in stock. This page describes every category of personal data the app processes. It is written against what the software actually does; if you find a discrepancy, treat it as a bug and tell us at support@restockrelay.app.

Who is responsible for your data

If you are a shopper: the merchant whose store you subscribed on is the data controller. They decide to offer restock alerts and they own the resulting subscriber list. We are their processor — we handle the data on their instructions, under our merchant agreement, and for no other purpose. We do not sell, rent, share or otherwise disclose subscriber data to anyone, we do not use it to build profiles, and we do not use it across merchants.

If you are a merchant: we are the controller for the limited account data we need in order to run the app for you.

What we collect, and why

Shopper data (you gave it to us on a storefront)

When you submit the “Notify me” form on an out-of-stock product page, we store:

Your email address
To send you the alert you asked for. Nothing else.
The product variant you asked about
A Shopify variant identifier — and the related inventory item identifier — so we know which restock concerns you.
Your language / locale
So the alert is written in the language you were browsing in.
Timestamps and status
When you subscribed, whether the alert has been sent, and whether the subscription came from the storefront widget or from a list the merchant imported. We also record when an alert was queued and sent.

What we deliberately do not collect. The app requests only two read-only Shopify permissions: read_products and read_inventory. It has no access to Shopify customer records, orders, or payment data, and no write access to anything. If you happen to be logged into the store when you subscribe, Shopify offers us your customer ID: we discard it, we never write it to the database, and it is stripped from our logs. We do not track clicks or opens in the alerts we send.

Suppression data

If you unsubscribe, or if an email to you bounces or you report it as spam, we store your address together with the reason and the date on a suppression list. This exists precisely so we stop emailing you — see the retention section below for why we keep it rather than delete it.

Merchant account data

For each installed store we hold the store domain, the plan, install and uninstall timestamps, app settings, sender-domain configuration (the domain, the From address, DKIM verification state), and the authentication session Shopify issues at install — which includes the staff account’s name, email address and locale, and the access token. This is the standard Shopify session record and is what keeps you logged into the app.

Legal basis

The merchant, as controller, determines the basis. In practice a restock alert exists only because you actively asked for it: you typed your address into the form and pressed submit for one named product. We do not send anything you did not request, so processing is limited to fulfilling that request and to the legal obligation of honouring unsubscribes and complaints. Merchant account data is processed to perform our contract with the merchant.

How long we keep it

Who else processes it

Processor What for Where
Amazon Web Services — Amazon SES Sending the alert emails; bounce and complaint handling. eu-west-1 (Ireland)
Shopify The store platform itself: it hosts the storefront widget and tells us about inventory changes. Per Shopify’s own terms
Our application host and database Running the app and storing the data described above (PostgreSQL). Provider selection is being finalised; this page will name the provider and region before public launch.

That is the complete list. We run no analytics provider, no advertising pixel, no CRM sync and no cross-site tracking, on this website or in the emails we send.

Security

Data is encrypted in transit (TLS) and at rest. Credentials live in the host environment, never in our source code. Requests from storefronts are verified with Shopify’s HMAC signature before we accept them, and the subscribe endpoint is rate-limited. We log store domains and record identifiers — not shopper email addresses.

Your rights

Under the GDPR you can request access to your data, correction, erasure, restriction, portability, and you can object to processing.

Changes

If this policy changes materially we will update the date at the top. Questions go to support@restockrelay.app.