Privacy Policy
Restockly for Shopify. Last updated: 14 September 2026.
Restockly is provided by RVDH Interim Management B.V., established in Veenendaal, the Netherlands. This policy describes what the app reads from your Shopify store, what it keeps, and for how long.
The app reads your orders, but not your customers. To work out how fast a product sells it reads order lines — the date, the quantity and which variant was sold. It does not request customer names, email addresses, phone numbers, shipping or billing addresses, or any price, and it holds the read_orders permission rather than read_all_orders, so its view stops at 60 days.
1. What the app reads from your store
- Order lines from the last 60 days: the date of the order, the quantity sold, and the product variant. Test orders and cancelled orders are ignored. Nothing else about the order is requested.
- Product titles, inventory levels and locations, to know what is on the shelf and where.
- Your store's domain, so settings and plans belong to the right shop.
- For the person signed in to the app: name, email address, locale and whether the account is the store owner. Shopify supplies these with the session.
2. What is stored, and why
| Stored | Why |
|---|---|
| Daily demand: for each variant, the number of units sold on a given day | This is the sales rate the reorder advice is built on. It is a total per day, with no order number, no customer and no amount attached, so a stored row cannot be traced back to a person or to a purchase. |
| Suppliers you enter: name, contact email, lead time in days | To group purchase suggestions per supplier and to know how early to order |
| Product-to-supplier links, case size and minimum order quantity | To turn a suggestion into an order a supplier will actually accept |
| Planning settings: desired days of coverage, which locations to count | To calculate for your store the way you want it calculated |
| Store domain and access token | To call the Shopify API on your behalf when the planner refreshes |
| Installation record: plan, subscription id, install and uninstall dates | To apply the plan you are on |
The supplier email address is one you type in yourself and belongs to your supplier, not to a customer. No customer email address is ever read or stored.
3. Who else sees it
- Shopify — the source of the order, product and inventory data, under your own agreement with Shopify.
There is no other recipient. Order data is not sent to an analytics provider, an AI service or any other external system, and nothing is sold, rented or used for advertising.
4. How long it is kept
Daily demand is kept for 60 days — the same window the app is allowed to read — and older rows are deleted every time the planner refreshes. Everything else is kept while the app is installed.
When you uninstall, Shopify sends a shop/redact request 48 hours later and the app then deletes everything it holds for your shop: demand history, suppliers, settings, installation record and session.
The app also answers Shopify's two customer-data requests. Because it stores no personal customer data at all, a customers/data_request has nothing to disclose, and a customers/redact has nothing about that customer to erase.
5. Where it is stored, and how it is protected
On a server in the European Union, in a database that is not shared with any other party. Traffic to the app runs over HTTPS.
The database sits on an encrypted volume — a LUKS2 container using AES-XTS. No key for that volume is kept on the server: after every restart the volume stays locked until we unlock it by hand with a passphrase, and the app does not run until then. A copy of the server's disk therefore does not contain what is needed to read the database.
To be clear about the limits of that: the encryption protects the data on the storage medium. It does not protect against someone who gains access to the running server, because the volume is unlocked while the app is running. What that would expose is what section 2 lists — daily unit totals per variant, the suppliers you entered, and session tokens — and no customer names, addresses, email addresses, phone numbers or amounts, because the app never receives them.
6. Your rights
You can ask what is held about you, ask for it to be corrected, or ask for it to be deleted — uninstalling the app triggers that deletion automatically. For anything else, write to info@getcompliant.online and you will get an answer within two business days.
7. If something goes wrong
If a security incident affects data held by this app, affected merchants are notified by email at the address Shopify has on file for the store, and the Dutch Data Protection Authority within 72 hours where the law requires it.
8. Changes to this policy
If this policy changes, the date at the top changes with it. Material changes will be announced in the app before they take effect.