Effective date: June 11, 2026
StockPilot ("the app") provides low-stock alerts and restock planning to merchants who use Shopify. This policy describes what information the app collects, why, and how it is handled. The app is operated by Eric Mollenthiel, 103 Avenue Lacassagne, 69003 Lyon, France ("we", "us").
StockPilot is deliberately minimal. When you install the app, we receive and store:
| Data | Why |
|---|---|
| Your .myshopify.com domain and an API access token (encrypted at rest) | To authenticate the app with your store |
| Product titles, variant titles, SKUs, vendor names and product status | To show readable alerts and group the restock list by vendor |
| Location names and inventory quantities | To evaluate your alert rules — this is the core of the app |
| Daily sales quantities per product variant (a number per day, from order webhooks) | To compute sales velocity for days-of-cover thresholds and restock suggestions |
| Your alert settings, including the notification email address you choose | To send your alerts and digests where you asked |
| Your subscription plan and billing status (via the Shopify Billing API) | To enable the features of your plan; we never see a payment method |
We do not collect or store any data about your customers. No names, no emails, no addresses, no payment details. Order webhooks are used only to increment per-product daily sales counters; the order payload itself is not retained.
Exclusively to provide the service: evaluating your alert rules, sending you alert emails and digests, and building your restock list. We do not sell, rent or share your data with third parties for marketing. We do not use your data to train machine-learning models.
Data is stored on our servers hosted in the European Union (OVHcloud, France), encrypted in transit (TLS) and, for access tokens, encrypted at rest. Alert emails are delivered through a transactional email provider acting as a processor on our behalf.
shop/redact request (48 hours
after uninstall), every record related to your store is
permanently deleted.data_request and redact requests are
acknowledged with an empty result, and we keep an audit trail of
having honored them.Under the GDPR and similar laws you may request access to, correction of, or deletion of the data we hold about your store at any time — email us and we will respond within 30 days. You can also simply uninstall the app: deletion then happens automatically as described above.
If this policy changes materially, we will post the new version at this address and update the effective date.
Questions or requests: support@shipanvil.com