Privacy policy
Last updated: 17 July 2026
Restock Relay is a Shopify app that sends one transactional email to a shopper when a product they asked about is back in stock. This page describes every category of personal data the app processes. It is written against what the software actually does; if you find a discrepancy, treat it as a bug and tell us at support@restockrelay.app.
Who is responsible for your data
If you are a shopper: the merchant whose store you subscribed on is the data controller. They decide to offer restock alerts and they own the resulting subscriber list. We are their processor — we handle the data on their instructions, under our merchant agreement, and for no other purpose. We do not sell, rent, share or otherwise disclose subscriber data to anyone, we do not use it to build profiles, and we do not use it across merchants.
If you are a merchant: we are the controller for the limited account data we need in order to run the app for you.
What we collect, and why
Shopper data (you gave it to us on a storefront)
When you submit the “Notify me” form on an out-of-stock product page, we store:
- Your email address
- To send you the alert you asked for. Nothing else.
- The product variant you asked about
- A Shopify variant identifier — and the related inventory item identifier — so we know which restock concerns you.
- Your language / locale
- So the alert is written in the language you were browsing in.
- Timestamps and status
- When you subscribed, whether the alert has been sent, and whether the subscription came from the storefront widget or from a list the merchant imported. We also record when an alert was queued and sent.
What we deliberately do not collect. The app requests only two
read-only Shopify permissions: read_products and read_inventory.
It has no access to Shopify customer records, orders, or payment data, and no write
access to anything. If you happen to be logged into the store when you subscribe,
Shopify offers us your customer ID: we discard it, we never write it to the database,
and it is stripped from our logs. We do not track clicks or opens in the alerts we send.
Suppression data
If you unsubscribe, or if an email to you bounces or you report it as spam, we store your address together with the reason and the date on a suppression list. This exists precisely so we stop emailing you — see the retention section below for why we keep it rather than delete it.
Merchant account data
For each installed store we hold the store domain, the plan, install and uninstall timestamps, app settings, sender-domain configuration (the domain, the From address, DKIM verification state), and the authentication session Shopify issues at install — which includes the staff account’s name, email address and locale, and the access token. This is the standard Shopify session record and is what keeps you logged into the app.
Legal basis
The merchant, as controller, determines the basis. In practice a restock alert exists only because you actively asked for it: you typed your address into the form and pressed submit for one named product. We do not send anything you did not request, so processing is limited to fulfilling that request and to the legal obligation of honouring unsubscribes and complaints. Merchant account data is processed to perform our contract with the merchant.
How long we keep it
- Your subscription is kept until the alert has been sent and you no longer need it, or until you unsubscribe or ask for erasure, or the merchant deletes it, or the merchant uninstalls the app.
- Queued alerts that cannot be sent within 72 hours expire and are discarded rather than delivered stale.
- Suppression records — your address, the reason (unsubscribe, bounce or spam complaint) and the date — are kept for as long as the merchant uses the app, and we keep them even if you ask us to erase your data. Deleting the record of an unsubscribe or a complaint would let us email you again by mistake; keeping the address on a do-not-send list is the only way to guarantee we do not. This is the one case where erasing an address works against the very thing you asked for, so the GDPR lets us keep it (Article 17(3)(b): processing needed to comply with a legal obligation). Nothing else is stored alongside it, it is never used to send you anything, and it is deleted when the merchant’s store data is deleted. We will explain this if you ask.
- On uninstall we immediately deactivate the store, cancel queued jobs, stop all sending, and tear down that store’s sending identity. Store data is then erased through Shopify’s data-deletion flow, and in any case we action erasure requests received through Shopify’s mandatory privacy webhooks within 30 days.
Who else processes it
| Processor | What for | Where |
|---|---|---|
| Amazon Web Services — Amazon SES | Sending the alert emails; bounce and complaint handling. | eu-west-1 (Ireland) |
| Shopify | The store platform itself: it hosts the storefront widget and tells us about inventory changes. | Per Shopify’s own terms |
| Our application host and database | Running the app and storing the data described above (PostgreSQL). | Provider selection is being finalised; this page will name the provider and region before public launch. |
That is the complete list. We run no analytics provider, no advertising pixel, no CRM sync and no cross-site tracking, on this website or in the emails we send.
Security
Data is encrypted in transit (TLS) and at rest. Credentials live in the host environment, never in our source code. Requests from storefronts are verified with Shopify’s HMAC signature before we accept them, and the subscribe endpoint is rate-limited. We log store domains and record identifiers — not shopper email addresses.
Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction, portability, and you can object to processing.
- To stop the emails right now: click unsubscribe in any alert — it works in one click, with no login. See the unsubscribe help page.
- For access, correction or erasure: email support@restockrelay.app and tell us the store you subscribed on. Because the merchant is the controller, we may need to route your request through them; we will tell you if we do. You can also ask the merchant directly — Shopify gives them a channel to forward the request to us, and we action it within 30 days. An erasure request removes your subscriptions and any alerts we hold for you; the one thing it does not remove is a do-not-send record, for the reason given under retention above.
- You have the right to complain to your national data protection authority.
Changes
If this policy changes materially we will update the date at the top. Questions go to support@restockrelay.app.