Privacy Policy
For the Shopify app Stockwell Low Stock Alerts · Effective 9 August 2026 · Last updated 9 August 2026
The short version
- Stockwell has read only access to your products, inventory levels and locations. It cannot change anything in your store.
- Stockwell never accesses your customers, their personal details or your orders. It does not request those permissions from Shopify.
- The only personal information we hold is the email addresses you choose to receive alerts.
- We do not sell your information, we do not share it for advertising and we run no advertising or analytics trackers.
- Uninstall the app and everything we hold for your store is permanently deleted within 48 hours.
1. Who we are
Stockwell Low Stock Alerts ("Stockwell", "we", "us") is a Shopify app that watches your inventory levels and emails your team before a SKU runs out. This policy explains what information the app handles, why, who it is shared with and how long we keep it.
This policy covers the app itself and the sites
app.usestockwell.com and api.usestockwell.com.
It applies to merchants who install the app and to the people whose
addresses a merchant adds as alert recipients. Questions or requests go
to
fazeell.tanveer@gmail.com.
2. What Stockwell reads from your store
When you install the app you grant it three read permissions, and no others:
| Permission | What it is used for |
|---|---|
read_products |
Product and variant titles, SKUs and product images, so an alert can tell you which item is running low |
read_inventory |
Stock quantities per item per location, which is the signal the whole app is built on |
read_locations |
Location names, so an alert can say which warehouse or store is low rather than showing a numeric ID |
All three are read only. Stockwell holds no permission to create, edit or delete anything in your store.
3. What we store
Store and catalogue information
- Your shop domain and Shopify shop ID, the date you installed, the permissions you granted and, if it happens, the date you uninstalled
- Product details we have seen: product and variant name, SKU and image URL, cached so an alert can be assembled without calling Shopify again on every inventory change
- Inventory levels per item per location, plus whether an alert has already been sent for the current condition so you are not emailed twice about the same thing
- Location names and IDs, kept so alerts you received in the past stay readable even after a location is renamed or removed
- Your tracking choices: which products you monitor and any custom threshold you set on them
- Alert history: a record of each alert we sent, including the product, location, stock level at the time and whether it was low stock or out of stock. This is what the dashboard and history views read from.
Account and contact information
- The email addresses you enter as alert recipients. These are the only personal contact details the app holds and they are there because you typed them in.
- Your notification preferences: stock threshold, whether daily summaries are on, and the hour and time zone you want them sent
- Your plan status read back from Shopify: which plan is active, whether it is in trial, when the current period ends and whether a cancellation is pending. Stockwell never sees or stores your payment card. Shopify handles billing entirely.
- A Shopify session record containing the access token that lets the app call the Shopify API on your behalf. It is held on our servers only and is never exposed to a browser.
Operational information
- Webhook logs: the notifications Shopify sends us about inventory and product changes, retained so we can diagnose a missed or duplicated alert
- Delivery failures: if an address hard bounces or someone marks an alert as spam, we record that address so we stop emailing it. See section 8 for how long that record lasts.
- Error reports sent to our monitoring provider when something breaks. These are configured to strip personal data: shop domain, request signatures and similar identifiers are removed before the report leaves our servers, and the provider is instructed not to attach IP addresses, headers or cookies.
4. What we never collect
- Your customers. Names, email addresses, shipping addresses, phone numbers, orders, carts and payment details are all outside the permissions this app requests. We cannot read them and we hold none of them. When Shopify sends us the mandatory customer data request and customer redaction notices, we acknowledge them and there is nothing to return or erase.
- Payment information. Subscriptions are charged through Shopify Billing. We only read back which plan is active.
- Tracking across the web. No advertising pixels, no analytics scripts and no marketing cookies.
5. How the information is used
We use what is described above only to run the service:
- Compare stock levels against your threshold and decide when something counts as low stock or out of stock
- Send alert emails and daily summary emails to your recipients
- Show your dashboard, product list and alert history inside Shopify
- Apply the limits of your plan, such as how many SKUs are monitored and how many recipients are notified
- Answer your support requests and investigate faults
- Meet our legal and Shopify platform obligations
We do not use your data to train machine learning models, we do not build merchant profiles and we do not sell or rent anything to anyone.
Legal bases, if you are in the EEA or the UK
We rely on performance of a contract for everything needed to deliver alerts you asked for, and on legitimate interests for keeping the service secure, diagnosing faults and preventing email abuse. Where a legal obligation applies, such as responding to a data subject request, we rely on compliance with a legal obligation.
6. Who we share it with
We use a small number of service providers to run Stockwell. Each processes data only on our instructions and only to provide their part of the service.
| Provider | Role |
|---|---|
| Shopify | The platform the app runs on, the source of your store data and the processor of all subscription charges |
| Amazon Web Services | Application hosting, database storage and content delivery |
| Amazon Simple Email Service | Delivery of alert and summary emails |
| Sentry | Error monitoring, with personal data scrubbed beforehand |
Beyond these, we disclose information only when the law requires it, or where it is necessary to establish or defend a legal claim. If Stockwell is ever acquired, we will tell affected merchants before their data moves to a new owner.
7. Where it is stored
Stockwell runs on Amazon Web Services infrastructure in the United States. If you are in the EEA or the UK, that means your information is transferred outside your region. Those transfers rely on the European Commission's Standard Contractual Clauses, which our infrastructure providers incorporate into their terms.
8. How long we keep it, and how it is deleted
- While the app is installed, we keep the information described in section 3 so the service works and your alert history stays available.
- When you uninstall, the app immediately stops monitoring your store and your cached plan record is cleared.
- 48 hours after you uninstall, Shopify sends us a shop redaction request and we permanently delete everything we hold for your store in a single operation: sessions and access tokens, webhook logs, alert history, inventory state, tracking choices, product and location caches, your notification settings including every recipient address, your plan record and the store record itself. Nothing is kept in a recycle bin and nothing is archived.
- One deliberate exception. If an address hard bounced or reported one of our emails as spam, that address stays on a suppression list after deletion. Keeping it is what stops us emailing a dead or unwilling mailbox again if the app is reinstalled. The record holds the address, the reason and the date, nothing else. Write to us if you want an address removed from it.
- Error reports held by our monitoring provider expire on that provider's own retention schedule, typically within 90 days.
You do not have to wait for an uninstall. Email us and we will delete your data on request.
9. Your rights
Depending on where you live, you may have the right to access the information we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. You can exercise any of these by emailing fazeell.tanveer@gmail.com. We will respond within 30 days and we will not charge you or treat you differently for asking.
We do not sell personal information and we do not share it for cross context behavioural advertising, as those terms are defined under California law. If you are in the EEA or the UK and you are unhappy with how we have handled a request, you have the right to complain to your local data protection authority.
If you were added as an alert recipient by a merchant and want to stop receiving emails, contact the merchant who added you or write to us and we will remove your address.
10. Security
- All traffic to and from the app travels over encrypted connections
- The database is encrypted at rest and is not reachable from the public internet
- Shopify access tokens are stored server side, are never sent to a browser and are scoped to the three read permissions in section 2
- Every webhook from Shopify is signature verified before it is processed
- Access to production systems is limited to people who need it
No system is perfectly secure, but if a breach ever affects your information we will notify you and the relevant authorities as the law requires.
11. Cookies
Stockwell sets only what is needed to keep you signed in to the embedded app inside your Shopify admin. There are no advertising cookies, no analytics cookies and no third party trackers, so there is nothing here to opt out of.
12. Children
Stockwell is a business tool sold to merchants. It is not directed at children and we do not knowingly collect information from anyone under 16.
13. Changes to this policy
If we change how we handle information, we will update this page and move the "last updated" date at the top. For changes that materially affect you we will also notify you in the app or by email before they take effect.
14. Contact us
Email fazeell.tanveer@gmail.com for anything in this policy, including access and deletion requests. We read every message and aim to reply within two business days.