Legal

Data & GDPR

Last updated: June 6, 2026 · Effective immediately

On this page

  1. Data processing roles
  2. What data we process
  3. Shopify Protected Customer Data
  4. Legal bases (GDPR)
  5. Your rights (GDPR & CCPA)
  6. Mandatory privacy webhooks
  7. Requesting deletion
  8. Subprocessors
  9. International transfers
  10. Cookies
  11. Data Processing Agreement
  12. Contact & DPO

1. Data processing roles

Under the GDPR, the merchant is the data controller for their store's data, and StockUrgify acts as a data processor, processing data only to provide the Service on the merchant's instructions. For our own account and billing records, StockUrgify is the controller. This page complements our Privacy Policy and Terms of Service.

2. What data we process

CategoryExamplesSource
Shop identityShop domain, name, email, plan, country, currency, timezoneShopify OAuth
Catalog & inventoryProduct titles, variants, IDs, images, stock levelsShopify Admin API
App configurationThresholds, messages, colors, rules, alert channelsMerchant input
Badge telemetryAnonymous impression/click events, product, timestampStorefront script

We do not collect storefront shoppers' names, emails, addresses, or payment data. Badge analytics are aggregate.

3. Shopify Protected Customer Data

StockUrgify is built to require no access to Protected Customer Data. We do not request customer PII scopes, and our storefront telemetry is anonymous. We follow Shopify's Protected Customer Data requirements: minimizing data access, encrypting data in transit and at rest, limiting retention, and maintaining staff data-handling practices.

If a future feature ever required customer data, we would request the minimum scope, disclose it clearly, and obtain merchant consent before processing.

5. Your rights (GDPR & CCPA)

Subject to applicable law, you may have the right to:

To exercise a right, email privacy@stockurgify.com. We respond within the timeframes required by law (generally 30 days under GDPR, 45 days under CCPA).

6. Mandatory privacy webhooks

As required for all Shopify apps, StockUrgify implements the three GDPR/privacy webhooks. Shopify sends these and we act on them automatically:

WebhookWhat we do
customers/data_requestWe hold no storefront customer PII, so we return a record confirming none is stored. Any merchant-facing data is provided on request.
customers/redactWe delete any data associated with the identified customer (none is typically held).
shop/redactSent ~48 hours after uninstall. We erase the shop's settings, cached products, and telemetry from our systems.

7. Requesting deletion

The fastest way to delete your data is to uninstall StockUrgify from your Shopify admin — this triggers Shopify's shop/redact webhook and your data is erased (typically within 48 hours, and no later than 30 days). To request deletion without uninstalling, or to confirm erasure, email privacy@stockurgify.com.

8. Subprocessors

We use a small set of vetted subprocessors under data protection agreements:

SubprocessorPurposeLocation
ShopifyPlatform, OAuth, billing, webhooks, Admin APIGlobal
Cloud hostingApplication servers & databaseEU / US
Email providerTransactional & digest emailEU / US
Slack / DiscordOptional alert delivery (merchant-configured)US

We provide notice of material changes to this list. Request the current version at privacy@stockurgify.com.

9. International transfers

Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and equivalent mechanisms offered by our subprocessors.

10. Cookies

The embedded admin uses only the session tokens needed for Shopify authentication. The storefront badge script does not set advertising or cross-site tracking cookies; impression and click events are anonymous and used solely for merchant analytics.

11. Data Processing Agreement

For merchants who require a signed Data Processing Agreement (DPA), we offer one incorporating the GDPR Article 28 terms and the Standard Contractual Clauses. Request a copy at privacy@stockurgify.com.

12. Contact & DPO

For any data protection or GDPR/CCPA matter, contact our privacy team at privacy@stockurgify.com. You also have the right to lodge a complaint with your local supervisory authority. See our Privacy Policy and Terms of Service for related information.