Privacy
What this app stores
When a shopper asks to be told that a sold-out product is back, the app stores that email address, the variant they asked about, the time, their chosen language, and whether they separately opted in to marketing. That is the whole record.
If the merchant connects Klaviyo or Omnisend, the app stores that provider API key encrypted and shows only its final four characters. A consented address can wait briefly in a durable sync queue; the address is erased from that queue as soon as the provider accepts, rejects, or has an unknown result.
For pre-orders the app stores order and line identifiers, the quantity, the fulfilment holds it placed, and the order's email address so it can tell whether an order followed one of its alerts.
The app does not store names, addresses, phone numbers, payment details, or browsing history.
Why
A restock alert is a transactional message the recipient asked for. Marketing consent is a separate, unticked option, and it is never assumed from a signup.
Order data is used to identify pre-order lines, hold their fulfilment, and report attributed orders to the merchant. It is not used for advertising or profiling.
Who can see it
Each merchant's data is isolated to their own store. It is never shared between stores, sold, or used to build a cross-merchant audience.
Email is delivered by a sending provider acting as a processor on the merchant's behalf.
When a shopper separately opts in to marketing and the merchant enabled an integration, their email address, chosen language, and consent time are sent to the merchant's own Klaviyo or Omnisend account. No address is sent to those providers from the transactional alert checkbox alone.
How long
A signup is kept while the shopper is waiting and for 18 months after the last activity on it, then deleted automatically.
Sent, cancelled, and suppressed messages are deleted after 90 days, and the address goes with the record. Restock history is kept for 180 days.
Marketing-sync records are deleted after 90 days. Terminal records contain no email address; they retain only an idempotency marker until deletion.
Addresses that bounced or reported a message as spam are the deliberate exception: they are remembered indefinitely, because forgetting one means emailing that person again.
On a Shopify `customers/redact` request the matching signups and any queued messages for that address are deleted. On `shop/redact` everything the app holds for that store is deleted.
A shopper can unsubscribe from any message with one click, which stops all mail from that store.
Access logging
Every time this app creates, uses, exports, or deletes a shopper's record, it writes an entry to an access log: what was done, to which of its own records, by the system or by the merchant, and when.
The log deliberately does not contain the email address involved, so it cannot become a second copy of the mailing list. It is kept for 90 days and the merchant can see a summary of it inside the app.
Security incidents
Suspected incidents are investigated immediately. Affected merchants are notified without undue delay with what is known, what was accessed, and what to do.
Report a concern to security@keelcroft.com.
Data processing terms
The app acts as a processor for the merchant. It processes personal data only on the merchant's instructions, keeps it confidential, assists with data-subject requests, and deletes it on request or through Shopify's mandatory redaction lifecycle after uninstall.
On uninstall, sending stops, queued marketing addresses and provider credentials are erased immediately, and Shopify's mandatory shop-redaction webhook removes the remaining store data after its platform retention window.