Privacy Policy
Last updated 3 August 2026
This policy explains what data the Restock app for Shopify accesses, what we store, who we share it with, and how long we keep it. It applies to the Restock app and to the pages on this site. It is written to be read by the merchants who install Restock, not by lawyers.
The short version. Restock reads your product, inventory and order data so it can forecast demand and draft purchase orders. It does not collect, store or transmit any of your customers' personal data. Not their names, not their email addresses, not their shipping addresses. Our sales records hold quantities and timestamps only.
1. Who we are
Restock is operated by Rel8 CX Ltd, a company registered in England and Wales under company number 10154735, with its registered office at 124 City Road, London, EC1V 2NX, United Kingdom. We are registered with the Information Commissioner's Office under registration number ZC028999.
For any question about this policy or about your data, contact privacy@rel8.cx.
2. Our role and yours
For the store data that Restock reads from your Shopify account, you are the data controller and Rel8 CX Ltd acts as your data processor. We process that data only to provide the service to you, and only on your instructions, which you give by installing and configuring the app.
For your own account details, billing records and any support correspondence you send us, we act as the data controller.
3. What Restock reads from your store
Restock requests only the Shopify access scopes it needs to do its job. Through the Shopify Admin API it reads:
- Products and variants, including titles, SKUs, product types, tags and vendor names
- Inventory levels for each variant at each of your locations
- Your store locations
- Order line items, specifically which variant was sold, how many units, at what time, and the Shopify order and line item identifiers
Restock reads up to 12 months of order history when you install it, then keeps the picture current through Shopify webhooks and a nightly reconciliation pass.
Restock writes back to your store in exactly one situation. When you record a delivery against a purchase order, and only if you have turned on inventory updates in your settings, it adds the units you received to your Shopify stock at the location concerned. It changes nothing else in your store: not your products, not your prices, not your orders, not your customers.
4. What we store
| Category | What it contains | Why we hold it |
|---|---|---|
| Catalogue data | Products, variants, SKUs, product types, tags, locations, inventory levels | Forecasting demand per variant and per location |
| Sales history | Variant, location, quantity, time of sale, and Shopify's order and line item identifiers | Calculating demand patterns and seasonality |
| Store account | Store domain, currency, timezone, your alert thresholds and digest preferences, and an encrypted Shopify access token | Running the app and keeping it authenticated to your store |
| Supplier records | Supplier name, contact email address, lead time and minimum order value | Grouping reorder suggestions and sending purchase orders |
| Email settings | Your SMTP host, port, username, an encrypted password, and your sender and reply addresses | Sending purchase orders and digests from your own address |
| Deliveries | What you received against each purchase order, when, and whether we updated your Shopify stock for it | Tracking partial deliveries and giving you an audit trail |
| App output | Forecasts, reorder recommendations, purchase orders and a timestamped record of every status change | Showing you the app and giving you an audit trail |
5. What we deliberately do not collect
Restock is built so that customer personal data never enters our systems. We do not collect or store:
- Customer names, email addresses or phone numbers
- Shipping or billing addresses
- Payment details, card numbers or any financial instrument data
- Customer accounts, marketing consents or browsing behaviour
Our sales history table records a variant, a location, a quantity, a timestamp and Shopify's own opaque order identifiers. There is no field anywhere in our database that holds a customer's personal data. When Shopify sends us a customer data request or a customer deletion request on your behalf, we log it and confirm that we hold no personal data for that individual, because we do not.
6. Artificial intelligence and what we send to it
Restock uses a large language model from Anthropic for two narrow tasks: writing the plain English explanation attached to each reorder recommendation, and drafting the body of a purchase order email for you to review. All forecasting mathematics runs on our own servers and never involves a language model.
What we send
- For a recommendation explanation: the variant title, SKU, units on hand, forecast daily demand, lead time, safety stock, reorder point, days of cover, a confidence score, the suggested quantity, any minimum order quantity, the supplier name and the unit and estimated cost
- For a purchase order draft: your store name, the supplier name, the currency, and for each line the variant title, SKU, quantity and unit cost, plus the order total
What we never send
- Customer data of any kind, since we hold none
- Supplier email addresses, which are removed before the request is made
- Your SMTP credentials or your Shopify access token
Under Anthropic's commercial terms, data submitted through their API is not used to train their models. If you would rather not use these features, Restock works without them: it falls back to a fixed template for purchase order emails and shows the underlying numbers for recommendations. Contact us and we will disable the AI features for your store.
7. Who else processes your data
We use a small number of sub-processors to run the service.
| Provider | Purpose | Processing location |
|---|---|---|
| Fly.io | Application hosting and the PostgreSQL database | London, United Kingdom |
| Upstash | Redis, used as the background job queue | London, United Kingdom |
| Anthropic | Language model for the two features described in section 6 | United States |
Purchase order and digest emails are sent through the SMTP provider that you configure and control. We do not route your outbound mail through our own servers.
We do not sell your data, share it with advertisers, or use it to build profiles across merchants. Your data is used to serve your store and nothing else.
8. International transfers
Your application data and database are hosted in London. The only routine transfer outside the United Kingdom is to Anthropic in the United States, for the two features described in section 6. Where personal data is transferred outside the UK, the transfer is covered by appropriate safeguards, including standard contractual clauses together with the UK International Data Transfer Addendum where required.
9. How we protect your data
- All traffic between your browser, Shopify and our servers is encrypted in transit
- Your Shopify access token and your SMTP password are encrypted at rest using AES-256-GCM with a key that is not stored alongside the data
- Credentials are never written to application logs
- Access to production systems is limited to named individuals who need it
- Every webhook we receive is verified against Shopify's signature before it is accepted
10. How long we keep it
We hold your data for as long as Restock is installed on your store. When you uninstall the app, every record belonging to your store is deleted automatically within 30 seconds, which includes suppliers, purchase orders, forecasts, recommendations and your stored SMTP credentials. When Shopify notifies us that a store has been closed, we purge that store's data immediately rather than waiting for the 48 hour window Shopify allows.
Deletion is permanent. We do not retain a shadow copy for analytics or any other purpose.
11. Your rights
Under UK data protection law you have the right to access, correct, delete, restrict or object to our processing of your personal data, and the right to receive a copy in a portable format. To exercise any of these, write to privacy@rel8.cx and we will respond within one month.
Because you are the controller of your store data, requests from your own customers should come to you first. If you need our help answering one, we will support you, although as set out in section 5 we will almost always be confirming that we hold nothing.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.
12. Changes to this policy
If we change how we handle data in a way that materially affects you, we will update this page and change the date at the top. Where the change is significant we will also notify you inside the app or by email before it takes effect.
13. Contact
Rel8 CX Ltd, 124 City Road, London, EC1V 2NX, United Kingdom.
Privacy enquiries: privacy@rel8.cx
Product support: support@rel8.cx