Privacy Policy
Last updated 28 September 2026
Inventory Guard is a Shopify app that looks at a store’s inventory and open orders, finds problems that cost sales, and explains them. This page says exactly what it reads, what it keeps, and for how long. Plain language, no surprises.
The short version
- The app has read-only access. It never changes your products or stock.
- It does not read, store or receive your customers’ names, email addresses, phone numbers or shipping addresses.
- We do not sell data, and we do not use it to train AI models.
- Scan results older than 90 days are deleted automatically.
- Uninstall the app and everything we hold about your store is deleted.
Who we are
Inventory Guard is operated by Sooperstack Studio (“we”, “us”), a sole proprietorship based in Bangladesh. For anything on this page, email support@sooperstack.com.
For merchants in the EU, UK and similar regimes: you are the data controller for your store’s data, and we act as your data processor. We only process it to run the features you installed the app for.
What the app reads from your store
When you install Inventory Guard you grant four read-only permissions: read_products, read_inventory, read_locations and read_orders. We use them for this and nothing else:
| Permission | What we do with it |
|---|---|
| Products & variants | Title, variant, SKU, price, cost, vendor, status and the “continue selling when out of stock” setting — to spot oversold, mispriced-risk and mis-set items and to value what is at risk. |
| Inventory & locations | Available, committed, on-hand and incoming units per location — to find negative stock, sold-out-but-live items, stock sitting at the wrong location, and to forecast when you will run out. |
| Orders | Order number, creation time, order total, fulfillment status, refunded line items and quantities — to flag orders past your handling time, refunds that were never put back into stock, and to measure sales pace for the forecast. |
We do not request or receive customer-identifying fields. From an order we take the order number, its timestamps, its total and its line quantities — not who placed it.
What we store
- Your store — shop domain, store name, currency, timezone and the access token Shopify issues so scans can run in the background.
- Your settings — the email address you want alerts sent to (your store’s contact address by default), alert and digest preferences, handling time, supplier lead time and stock cover targets, and your plan.
- Scan results — the issues we found, their severity, the money at risk, and references to the products, variants and order numbers involved, so the app can show you the list and notice when something is fixed.
- Stock and sales figures — per-variant stock totals and sales counts from the last 30 days, used for the forecast.
- Scan history — when each scan ran and whether it succeeded.
Data is stored in an encrypted database. Access tokens are held only for the stores that have the app installed and are removed on uninstall.
How long we keep it
- Issues, scan history and stock figures: deleted after 90 days.
- Everything about your store, settings included: deleted when you uninstall the app. Shopify notifies us, and our uninstall handler removes the records.
- Shopify’s shop-redaction request (sent about 48 hours after uninstall) is also handled, as a second sweep.
Because we hold no customer personal data, a customer data request or customer redaction request from Shopify finds nothing to return or erase. We still handle both, and confirm that back to Shopify.
Who else touches the data
| Service | Why |
|---|---|
| Shopify | The source of the data, and how the app is billed. |
| Our hosting provider | Runs the app server and its database. |
| Resend | Delivers alert and digest emails. It receives the recipient address and the email’s contents (issue titles and amounts). |
These are the only third parties involved. No advertising networks, no analytics trackers, no data brokers. Nothing is used to train AI models.
Your rights
You can see everything we hold inside the app. You can change or clear the alert email in Settings at any time. To get an export or an early deletion, email support@sooperstack.com from your store’s contact address and we will answer within 30 days.
Depending on where you are, you may have rights to access, correct, delete or port your data, and to object to processing. Uninstalling the app deletes it all, which is usually the fastest route.
Where data is processed
Your store’s data is stored on servers in the European Union (Amsterdam, Netherlands), whichever country your store sells in. Emails are sent through Resend, which operates in the EU and the United States.
We are based in Bangladesh, so our own administrative access to those servers — for support and maintenance — happens from outside the EU. For transfers out of the EEA and the UK we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, and we will sign a data processing agreement on request.
Security
All traffic is over HTTPS. The database is encrypted at rest and reachable only by the app server. Requests from Shopify are verified by signature before anything is processed, and every page inside the app requires a valid Shopify session.
Children
Inventory Guard is a business tool. It is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change what we collect or who processes it, we update this page and its date, and email installed merchants before the change takes effect.