Privacy policy
Last updated: August 3, 2026
StockPulse analyzes inventory. It keeps a picture of your merchandise, and never reads who your customers are.
In one paragraph
When you install StockPulse, it reads your products, stock levels, unit prices and the last 30 days of order line items through the Shopify API, computes your stockout risk, and shows it to you. We never read and never store your customers' data — no name, no email address, no phone number, no postal address, no order total. What we do keep is a picture of your merchandise: which variants exist, how many units are in stock, their unit price, and how many units of each were sold on each day. Shopify cannot hand over a full catalogue inside a single page load, so that reading runs in the background and is refreshed at least once a day. All of it is deleted when you uninstall. We never sell or share anything.
Who is responsible
Trussfy publishes StockPulse and operates this website. For store data processed through the app, the merchant is the data controller and Trussfy acts as a processor on the merchant's behalf — see the Data Processing Addendum. Contact: contact@trussfy.com.
What the app reads from your store
Read through the Shopify Admin API. The kept column says, field by field, what survives the request and what does not.
| Data | Why | Retention |
|---|---|---|
| Active products and their variants — id, title, SKU, created date, featured image preview, available inventory quantity, unit price | List what you sell, how much stock remains, and how much revenue a stockout would put at risk | Stored as an inventory snapshot, replaced by the next reading and deleted when you uninstall |
| Orders processed in the last 30 days — processed date, cancelled status, and per line item: variant id and quantity | Compute sales velocity and estimate stockout dates | Only the resulting daily unit counts per variant are kept. The orders themselves are never stored — no order id, no order total, no customer |
| Shop — name, currency, timezone | Display your figures in your own currency and local time | Never written to our database — read at each page load |
Reading a full catalogue takes Shopify several minutes, so it happens in the background and the result is stored as a snapshot, refreshed at least once a day. Between two refreshes your dashboard reads that snapshot rather than querying Shopify again. “Re-run analysis” forces a fresh direct reading straight away.
Order line items are considered protected customer data by Shopify, which is why StockPulse requests that access. We request the base level only, and none of the optional customer fields (name, email, phone, address) — the app has no use for them and never receives them.
What the app stores
| Data | Why | Retention |
|---|---|---|
| Shopify OAuth session — access token, shop domain, granted scopes, token expiry | Authenticate the app against your store, as required by Shopify | Until you uninstall the app, then deleted |
| App settings — risk thresholds, supplier lead time, daily-report preference, onboarding flag, creation and update timestamps | Remember your own configuration between visits | Until you uninstall the app, then deleted |
| Inventory snapshot — per variant: id, product title, SKU, image URL, units in stock, unit price, product creation date, and units sold per calendar day over the last 30 days | Shopify cannot return a full catalogue inside a single web request. The complete reading runs in the background and is stored so your dashboard can open instantly and be correct on stores of any size | Replaced by each new reading (at least daily); deleted when you uninstall |
That is the entire list. When you uninstall the app, the app/uninstalled webhook deletes both records immediately; the same happens on a shop/redact request from Shopify. Because we store no customer data at all, a customers/redact or customers/data_request has nothing to act on — we hold nothing about your customers.
What the app writes to your store
Nothing. StockPulse holds read permissions for products, inventory and orders. It never changes stock, never places or edits an order, and never suggests quantities — every restocking decision stays yours.
This website
Separate from the app: the marketing site sets no analytics or advertising cookies, loads no third-party trackers, and self-hosts its fonts (no request to Google Fonts).
| Data | Why | Retention |
|---|---|---|
| Email address and the catalogue size you selected on the early-access form | Email you once when StockPulse opens on the Shopify App Store | Until launch or until you ask us to remove it |
| Salted SHA-256 hash of your IP address | Abuse prevention (rate limiting) — the address itself is never stored | Hash stored with the signup; rate-limit counters purged after 2 hours |
Where data is stored, and who else touches it
Our database runs in the European Union (Paris region). We use these subprocessors, and no others:
- Supabase — Database hosting (OAuth token and app settings). European Union — Paris (eu-west-3).
- Vercel — Application and website hosting. European Union region for the marketing site.
- Shopify — Source of all store data; the app runs inside Shopify Admin. Per Shopify's own terms.
Data is encrypted in transit (HTTPS) and at rest. Server logs record error messages and the shop domain only — never store data or customer data.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your data, and object to its processing. Uninstalling the app deletes everything we hold about your store. For anything else — including removal from the early-access list — write to contact@trussfy.com and we will act within 30 days. You may also lodge a complaint with your local supervisory authority.
Changes
If we change what StockPulse reads or stores, this page changes first and its date is updated. Material changes affecting merchants are announced by email to the address on the Shopify account.