Privacy Policy

Effective date: July 25, 2026

This policy describes what data Restock Rocket (“the App”), published by A.N. ADVISORY (“we”, “us”), processes when a merchant installs it from the Shopify App Store, and how we handle privacy requests. Unlike many apps in this category, Restock Rocket does process a small amount of buyer personal data — a subscriber's email address — because sending back-in-stock emails is the entire point of the App. This policy explains exactly what that means.

The short version

  • For each signup on the notify-me widget we store one email address and the product variant that person is waiting for. Nothing else about the person.
  • We record whether the alert email was sent, and whether its product link was clicked, to measure alert speed and effectiveness.
  • On the Pro plan, we check the shop's orders to attribute recovered sales: an order containing the awaited product placed within 72 hours of an alert click. We store the attribution result (order id, product, amount) — not the buyer's identity.
  • Emails are delivered by Resend, our email sub-processor.
  • Shopify's deletion webhooks are implemented for real: customer redaction requests delete subscriber data, and uninstalling deletes the shop's data.
  • We never sell data, never use subscriber emails for anything except the requested alert, and never add anyone to a marketing list.

1. Data we process

Merchant (shop-level) data

  • Shop identification: your myshopify.com domain and the API access token Shopify issues to the App, used solely to operate the App for your store.
  • Settings: widget colors and texts, email branding (logo, colors, from name), double opt-in toggle, and your selected plan.
  • Catalog and inventory data: product titles, variant names, images and inventory levels, read from Shopify to display the widget and compose alert emails. We do not copy your full catalog; we read what is needed for active subscriptions.
  • Support correspondence: if you email us, we keep the thread so we can help you.

Buyer (customer-level) data

  • Subscription records: the email address entered in the notify-me widget and the variant the person wants. If double opt-in is enabled, we also store the confirmation status and timestamp.
  • Alert delivery records: for each alert — when it was queued, when it was sent, the measured latency, and whether the product link in the email was clicked (via a tracking parameter on the link). We do not track anything else the person does on your store.
  • Attribution records Pro: when an order containing the awaited product is placed within 72 hours of an alert click, we store the order id, the product concerned, and the order amount attributable to it. This uses Shopify's read_orders access. We do not store the buyer's name, address, or payment details.
  • Anti-abuse data: the IP address of a widget submission is used transiently for rate limiting (to block bots and spam). Rate-limit counters are short-lived and are not linked to subscriber profiles.

2. Data we do not collect

  • No buyer names, phone numbers, or shipping/billing addresses
  • No payment or card data of any kind
  • No browsing history, fingerprints, or behavioral profiles
  • No cookies set by the widget on your storefront
  • No use of subscriber emails for marketing, newsletters, or resale — one restock alert per signup is the entire lifecycle

3. How we use the data

  • To send the back-in-stock email a subscriber explicitly requested.
  • To send the double opt-in confirmation email, if you enable that mode.
  • To show you, the merchant, your dashboard: signups per product/variant, alerts sent, click rate, measured latency, and (on Pro) recovered sales and revenue.
  • To build the Demand Report (aggregated counts of waiting subscribers per product — no email addresses appear in it).
  • To prevent abuse of the public widget endpoint (rate limiting, honeypot, email validation).
  • To provide support when you contact us.

We do not sell or rent any data. We do not use subscriber data for advertising or profiling. Legal basis under GDPR: performance of the service the subscriber requested (Art. 6(1)(b)) for alerts, and legitimate interest (Art. 6(1)(f)) for anti-abuse measures and merchant analytics.

4. Sub-processors and where data lives

  • Resend (resend.com) — email delivery. Resend receives the subscriber's email address and the content of the alert or confirmation email in order to deliver it, and provides us delivery status. Resend acts as a data processor under its own data processing agreement.
  • Cloud hosting provider — the App's production application and PostgreSQL database, where subscriptions, alert logs, and settings are stored. Access is limited to the App's developer and protected by authentication.
  • Shopify — catalog, inventory, and (on Pro) order data are read from your store via Shopify's APIs and remain inside Shopify's infrastructure; we read them, we don't replicate them wholesale.

5. GDPR and privacy requests

The App implements all three mandatory Shopify privacy webhooks, and they are honored automatically:

  • customers/data_request — a customer asks for their data. We export the subscription and alert records matching that customer's email for the requesting shop and provide them to the merchant to pass on.
  • customers/redact — a customer asks for deletion. We delete the subscription records, alert logs, and click records associated with that customer's email for the requesting shop.
  • shop/redact — sent by Shopify 48 hours after you uninstall the App. We permanently delete your shop's settings, access token, all subscriber records, alert logs, and attribution records within 30 days of receiving it.

Subscribers can also contact us directly at the address below to request access to or deletion of their data; we respond within 30 days. Merchants in the EU/EEA, UK, or similar jurisdictions may request access, correction, or deletion of shop-level data the same way.

6. Data retention

  • Pending subscriptions: kept until the alert is sent, or until the subscriber or merchant deletes them.
  • Sent-alert and click records: kept for 12 months for dashboard statistics and attribution, then deleted or anonymized (aggregate counts only).
  • Unconfirmed double opt-in signups: deleted after 30 days if never confirmed.
  • Attribution records: kept for 12 months, then reduced to aggregate revenue totals.
  • After uninstall: everything is deleted within 30 days via the shop/redact flow described above.
  • Support emails: retained for up to 24 months, then deleted.

7. Security

Data is transmitted over TLS and stored in a production database with authenticated, developer-only access. Webhook payloads from Shopify are verified with HMAC signatures. The public widget endpoint is protected by rate limiting, a honeypot field, and input validation.

8. Changes to this policy

If we change what the App collects — for example, if a future feature requires new data — we will update this page, change the effective date at the top, and summarize the change in the App's changelog before it takes effect.

9. Contact

Questions, or a privacy request? Email anadvisory.fr@gmail.com. We read everything and reply within one business day.