Last updated: 6 October 2026
Privacy Policy for the Shopify App "RestockTrue"
This is an English translation of the German "Datenschutzerklärung". Only the German version is legally binding. If the two versions differ, the German version prevails.
This privacy policy is for merchants who use our app in their Shopify store and for their staff. It explains which personal data we process in connection with the app, for what purpose and on which legal basis. It is also the privacy policy for the app's listing in the Shopify App Store.
1. Controller and contact
Iller Labs, owner Robert Hampusch (sole proprietorship)
Rudolf-Kurz-Str. 2c
89257 Illertissen
Germany
Email: support@restocktrue.com
For privacy questions, please use the contact details above.
2. What the app does
The app helps merchants reorder. It measures on which days an item was actually in stock (in-stock days), calculates sales per in-stock day, shows how long the current stock is likely to last and makes reorder suggestions. Depending on the plan, it manages suppliers and order lists, explains suggestions with AI, imports data from Excel/CSV files and PDF invoices and, if the merchant wishes, can be connected to the app ExpiryLot by the same provider. Through a "Back in stock" theme block, the merchant's customers can sign up to be notified when a sold-out item is back in stock.
The app works exclusively through Shopify's interfaces. It does not order anything by itself, does not send anything to suppliers by itself and does not change stock levels or prices in Shopify. If a customer has consented to the newsletter via the theme block and confirmed the sign-up, the app creates or updates that person as a customer in Shopify and stores the consent there (see section 5.6).
3. Our roles
Our role under data protection law depends on the type of data:
| Data | Our role | What applies |
|---|---|---|
| Stock, sales, supplier and order data of your store and the data of your customers from the "Back in stock" theme block | Processor (Art. 28 GDPR) | You, the merchant, are the controller. Our Data Processing Agreement (DPA) applies. |
| Data on installation, the contract, use of the app by you and your staff, questions to the help assistant, and support requests | Controller | This privacy policy applies. |
The merchant informs its own customers in its own privacy policy. For transparency, we still briefly describe the processing on behalf of the merchant in section 5.
4. Data for which we are the controller
4.1 Installation, contract and billing
When you install the app, we process:
- your store's domain, the time of installation and the store's time zone,
- a time-limited access token with a refresh token for the Shopify Admin API, which the app uses to work on behalf of your store,
- information Shopify provides to us as app developer, such as the selected plan and billing status. The app reads the subscription status through the Shopify Partner API.
Billing runs entirely through Shopify. We do not receive payment data such as card or bank details.
The purpose is to provide the app and perform the contract. The legal basis is Art. 6(1)(b) GDPR. Where we process data of persons who are not themselves our contracting party, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the proper performance of the contract with the merchant.
4.2 Using the app in the Shopify admin
The app is displayed inside the Shopify admin. When it is opened, Shopify sends a session token. We use it to verify that the request comes from a user of your store, and take the store domain and the Shopify user ID of the logged-in person (a number, not a name) from it. We use the user ID only at the moment of the request; it is stored only together with questions to the help assistant (section 4.3). We do not store names or email addresses of your staff.
We store settings (for example location, lead time, target coverage) for your store. We do not use tracking cookies.
The legal basis towards the merchant is Art. 6(1)(b) GDPR. For the merchant's staff, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is providing the app securely to our customer.
4.3 Help assistant "Lotti"
On the Help page, users of the app can ask questions about how to use it. The assistant only knows the app's fixed knowledge about its features; it has no access to your shop data. To answer, the question and the app's fixed knowledge are sent to Anthropic's Claude API, but no shop data (see sections 6 and 7). Do not enter personal data in a question; the assistant does not need it.
We store questions and answers together with the Shopify user ID of the person asking for 180 days. We use questions the assistant could not answer to improve the app's fixed knowledge. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is making the app understandable and improving the assistant. Use is voluntary.
For the AI features, we count the number of requests and the tokens processed per store and month to limit costs (Art. 6(1)(b) GDPR).
4.4 Technical logs at our hosting provider
The app runs on Cloudflare. Every request to the app, whether from Shopify's servers, from an admin user's browser or for a sign-up through the theme block, generates technical data, in particular IP addresses and timestamps. The app's logs (Cloudflare Workers Observability) are kept for 7 days. We use them only for troubleshooting and to defend against attacks.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the app.
4.5 Support requests
If you contact us at support@restocktrue.com, we process your contact details and the content of your message to answer your request. Emails to this address are forwarded via Cloudflare Email Routing to a Gmail mailbox at Google and handled there. The legal basis is Art. 6(1)(b) GDPR where the request concerns the contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
5. Data we process on behalf of the merchant
5.1 Items, stock and sales
On behalf of the merchant as controller, the app stores:
- items and variants: ID, stock per location and "incoming", from the Admin API and the "inventory_levels/update" event,
- sales: order lines with variant, quantity and day, cancellations, and refunds with restock, from the events "orders/create", "orders/cancelled" and "refunds/create" and, at the start, from a look-back of up to 60 days; with several measured locations (Pro+ plan) also the location each line was shipped from or sold at,
- settings per item and the merchant's decisions (for example on unusual weeks).
For order events, Shopify sends full order data. This includes personal data of the merchant's customers, such as name, email address and addresses. The app trims the content to order lines, quantities and timestamps before storing it. It does not store customer data from orders (name, address, email address).
5.2 Suppliers and order lists
Depending on the plan, the app stores suppliers (name, email address for orders, language, lead time, note) and order lists. This information may include personal data of suppliers' contact persons. The app does not send anything to suppliers: "Email to supplier" opens the merchant's own email program with a template.
5.3 Data import from Excel and CSV files
The file is read in the browser. Only the mapped columns (SKU, barcode, name, supplier, email, lead time, pack, minimum quantity) are sent to our server. Only the imported settings are stored. The import report is created in the browser.
5.4 Data import from PDF invoices
When a user uploads a PDF invoice for data import, the entire PDF is sent to Anthropic and read there (see section 6). The PDF may contain anything that is on the invoice, for example names, addresses and bank details. Only the supplier, the supplier's email address and the line items (name, SKU, barcode, pack size) come back and are stored; these results are kept in Cloudflare KV for 30 days.
5.5 AI explanation "Why this suggestion?"
To explain a suggestion, only figures calculated by the app and the product name are sent to Anthropic, no personal data. The result is cached for 1 day.
5.6 "Back in stock" theme block (notifications for customers)
The app processes data of the merchant's customers only if the merchant uses the theme block in its store:
- email address, variant, language, timestamps and a random token, to notify the person when the item is back in stock. Sign-up uses double opt-in: the person receives a confirmation email; the sign-up only counts once it is confirmed. We store the time of confirmation as proof.
- a newsletter consent only if the person ticked the separate, unticked checkbox. After confirmation, the app creates or updates the person as a customer in Shopify with the email marketing consent (status "subscribed", confirmed opt-in). The consent then lies with the merchant in Shopify.
The app sends the emails via Cloudflare Email Service from noreply@restocktrue.com with the store's name as sender name; depending on the plan, replies go to the merchant's address. Every email contains an unsubscribe link. The theme block sets no cookies.
5.7 Connection to ExpiryLot
Depending on the plan, the merchant can switch on the connection to ExpiryLot, an app by the same provider for batches and best-before dates. RestockTrue then reads goods receipts and batches from ExpiryLot through a non-public connection within Cloudflare (Service Binding): variant ID, date, quantity, best-before date and location. No customer data is transferred. Batches are cached for 15 minutes. The data in ExpiryLot itself is governed by ExpiryLot's privacy policy and DPA.
The DPA sets out the details.
6. Recipients
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, provides our hosting (Cloudflare Workers, the Cloudflare D1 database and Cloudflare KV storage), sends the emails to the merchant's customers (Cloudflare Email Service) and forwards emails to our support address (Cloudflare Email Routing). Cloudflare is our processor; Cloudflare's data processing addendum, including the EU Standard Contractual Clauses, applies.
- Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland (contracting entity for customers in the EEA; parent company Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA; processing in the USA), model Claude Haiku 4.5, for the AI explanation of suggestions (only calculated figures and the product name), for data import from PDF invoices (the entire PDF, see section 5.4) and for the help assistant "Lotti" (the question and the app's fixed knowledge, see section 4.3). Anthropic is our (sub)processor. Under Anthropic's Commercial Terms of Service (section on customer content), API inputs and outputs are not used to train models.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Workspace), for the mailbox to which emails to support@restocktrue.com are forwarded. Google is our processor; Google's Cloud Data Processing Addendum, including the EU Standard Contractual Clauses, applies.
- Shopify: The app only works through Shopify. The contracting party for merchants in Europe is Shopify International Limited, Ireland. Shopify is not our processor but the platform through which you use the app. Shopify processes data under its own terms and privacy policy.
- Authorities receive data only if we are legally obliged to disclose it.
We do not pass on data to any other third parties. We do not sell data and do not use it for advertising.
7. Transfers to third countries
Cloudflare, Inc. is based in the USA and is certified under the EU-U.S. Data Privacy Framework. For certified companies, an adequacy decision of the European Commission applies (Implementing Decision (EU) 2023/1795 of 10 July 2023, Art. 45 GDPR). In addition, Cloudflare's data processing addendum includes the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
For the AI features, PDF invoices, calculated figures with product names and the questions to the help assistant are transferred to Anthropic in the USA. This is based on the EU Standard Contractual Clauses (Module 2 or Module 3) contained in Anthropic's Data Processing Addendum (Art. 46(2)(c) GDPR). According to Anthropic, API inputs and outputs are deleted within 30 days and are not used to train models.
For the support mailbox (Google Workspace), data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR); in addition, Google's Cloud Data Processing Addendum contains the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Cloudflare Workers run on Cloudflare's global network, so requests may also be processed in data centres outside the EU. The database is stored in the EU (Cloudflare "EU jurisdiction" setting: the database is stored and processed only in the EU). Access tokens and cached data (for example the results of PDF imports) are kept in Cloudflare KV and may be stored and cached across Cloudflare's global network.
8. Retention
| Data | Deletion |
|---|---|
| Access token | when the app is uninstalled |
| Store domain, installation time, time zone | when Shopify's "shop/redact" event arrives (48 hours after uninstallation) |
| All other store data (items, stock, sales, suppliers, settings, order lists, AI counters) | until uninstallation; deleted at the latest when "shop/redact" arrives (48 hours after uninstallation) |
| Sign-ups through the "Back in stock" theme block | unconfirmed: after 7 days; notified: 30 days after the notification; confirmed and still waiting: on notification, unsubscribe, deletion request ("customers/redact") or uninstallation |
| Newsletter consent | after confirmation it lies with the merchant in Shopify; the merchant's deletion rules apply there |
| Excel and CSV files | not sent to our server; only the imported settings are stored |
| PDF invoices | the app does not store the PDF itself; imported results (supplier, supplier email, line items) after 30 days; at Anthropic according to Anthropic's rules (according to Anthropic, API inputs and outputs are deleted within 30 days; up to 2 years if Anthropic's systems flag a usage-policy violation) |
| AI explanations | cache after 1 day |
| Batches from ExpiryLot | cache after 15 minutes |
| Questions to the help assistant (question, answer, user ID) | after 180 days |
| Technical logs at Cloudflare | after 7 days |
| Support requests | once no longer needed to handle the request, subject to statutory retention duties |
| Billing records | after the statutory retention periods under commercial and tax law |
9. Your rights
You have the right to
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR),
- lodge a complaint with a supervisory authority (Art. 77 GDPR).
Customers of a merchant should first contact the merchant, as the merchant is responsible for their data. We support the merchant in this. They can unsubscribe from "Back in stock" notifications at any time using the link in every email.
There is no automated decision-making within the meaning of Art. 22 GDPR.
10. Competent supervisory authority
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA, Bavarian Data Protection Authority)
Promenade 18
91522 Ansbach, Germany
https://www.lda.bayern.de
You may also contact any other data protection supervisory authority.
11. Obligation to provide data
The app cannot work without the store domain and the access token. There is no legal obligation to provide them, but they are required to use the app.
12. Changes
We update this privacy policy when the app or the legal situation changes. The version published here applies.