Privacy Policy — RestockIQ
Effective date: 2026-07-23 Last updated: 2026-07-23
RestockIQ ("RestockIQ", "we", "us") is an inventory-planning and demand-forecasting application for Shopify, operated by Aerel Systems. This policy explains what data we process, why, and how we protect it.
For personal data belonging to a merchant's customers, the merchant is the data controller and RestockIQ acts as a data processor on the merchant's behalf. Our processing of that data is also governed by our Data Processing Agreement.
1. Summary
- We process order line-item data only to forecast demand and plan inventory reordering for the merchant. This is the "Store management" purpose.
- We do not process customer-identifying fields — no name, email, phone, or address. We do not request these Shopify protected customer fields.
- We do not sell, rent, or share personal data, and we do not use it for advertising, marketing, or profiling of individuals.
- We retain data only while the app is installed and purge all of a shop's data within 30 days of uninstall.
2. Who we are
- App: RestockIQ (Shopify App Store).
- Operator / contact: Aerel Systems, 173 RUE de Courcelles, 75017 Paris, FRANCE.
- Privacy contact: contact@userestock.com.
3. What data we process
3.1 Merchant customers' data (we are a processor)
When a merchant installs RestockIQ, we read their order history via the Shopify Admin API to build demand forecasts. We import line items only:
- product variant, quantity, order date, cancellation status,
- point-of-sale location, and discounted unit price.
We do not import or store the customer object — no customer name, email, phone number, or shipping/billing address. Order line items are aggregated on import into per-day, per-SKU, per-location sales totals; our forecasting engine reads only those aggregates.
3.2 Merchant account & authentication data (we are a controller)
To operate the app we store the merchant's shop domain and an encrypted Shopify access token. If a merchant staff user authenticates with an online session, Shopify's session record may include that staff user's name and email (this is the person operating the store, never a customer).
3.3 Merchant business data
Products, inventory levels, locations, suppliers, purchase orders, and app settings. This is the merchant's operational business data and does not contain customer personal data.
3.4 Diagnostic data
If enabled, we use error-monitoring to capture technical diagnostics (stack traces, request metadata) to keep the service reliable. We configure it to avoid capturing personal data.
4. Why we process it (purposes and legal bases)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Demand forecasting & reorder planning ("Store management") | Aggregated order line items | Legitimate interests of the merchant / performance of our contract with the merchant |
| Authenticating and operating the app | Shop domain, access token, session | Performance of contract |
| Service reliability & security | Diagnostic data | Legitimate interests |
We limit our use of order data strictly to inventory forecasting and planning. We do not use it for any other purpose.
5. How we share data (sub-processors)
We do not sell or share personal data. We use the following sub-processors to run the service; each processes data only to provide infrastructure to us:
| Sub-processor | Purpose | Data |
|---|---|---|
| Shopify | Source platform / hosting of merchant data | Order & store data via Admin API |
| Neon (PostgreSQL) | Primary database | All stored app data |
| Upstash (Redis) | Job queue / cache | Transient job data |
| Fly.io | Application & worker hosting | Data in processing |
| Resend | Delivering scheduled reports to the merchant | Report contents (inventory aggregates), merchant recipient address |
| Sentry (if enabled) | Error diagnostics | Technical error data |
Confirm this list matches your deployed infrastructure and each provider's hosting region before publishing; update if you change providers.
A current sub-processor list is available on request. See the DPA for sub-processor terms.
6. Security
- In transit: all data is transmitted over TLS/HTTPS (Shopify Admin API, database connections, and the app UI).
- At rest — access tokens: Shopify access tokens are encrypted with AES-256-GCM at the application layer before storage (unique IV and authentication tag per token).
- At rest — database: all stored data resides in a managed PostgreSQL database that encrypts data at rest (AES-256 provided by the hosting provider).
- Access control: production credentials and the encryption key are held as managed secrets; staff access to production data is limited to those who need it to operate the service.
- Data minimization: we import line items only and aggregate them immediately, so no customer-identifying data is stored.
7. Data retention
- Aggregated sales history is retained while the app is installed — it is the merchant's forecasting history.
- On uninstall we flag the shop and purge all of its data within 30 days (automated). A merchant may request earlier deletion by contacting us.
8. Your rights
Depending on your location (e.g. GDPR, UK GDPR, CCPA/CPRA), individuals have rights to access, correct, delete, or restrict processing of their personal data, and to object to processing. Because RestockIQ is a processor acting for the merchant, such requests are normally directed to the merchant (the controller); we assist merchants in fulfilling them.
We honor Shopify's mandatory data-protection webhooks:
customers/data_request— we return no customer personal data because we store none.customers/redact— no action is required because we store no customer-identifying data.shop/redact— we delete the shop and all associated data.
We do not sell personal data and do not process it for cross-context behavioral advertising, so there is nothing to opt out of in that respect.
9. International transfers
Data may be processed in Europe. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses via our sub-processors.
10. Children
RestockIQ is a business tool not directed to children and does not knowingly process children's personal data.
11. Changes
We may update this policy; material changes will be reflected in the "Last updated" date and, where appropriate, communicated to merchants.
12. Contact
Questions or requests: contact@userestock.com.