Privacy Policy
Effective date: April 20, 2026
1. Introduction
Inventory Surplus ("we," "us," or "our") is a Shopify application that helps merchants identify, manage, and recover revenue from slow-moving and excess inventory. This Privacy Policy explains what information we access, how we use it, and the choices available to merchants who install our app.
Effective date: April 20, 2026
2. Information We Access
When you install Inventory Surplus, we access a limited set of data from your Shopify store via the Shopify API, strictly to provide the app's core functionality:
- Product and variant metadata (titles, SKUs, prices, tags)
- Inventory levels, locations, and stock movement history
- Order metadata used to calculate sell-through velocity (line items, quantities, dates)
- Return and refund metadata used to identify returned inventory
We do not access, collect, or store customer personal information.
This includes—but is not limited to—customer names, email addresses, shipping or billing addresses, phone numbers, IP addresses, and payment details. Order data we read is stripped of customer-identifying fields before it ever reaches our systems.
3. Information We Store
We store only non-PII operational data necessary to run the app:
- Your Shopify store domain (e.g., your-shop.myshopify.com)
- App configuration and preferences you set within Inventory Surplus
- Surplus detection results, workflow decisions, and routing actions you take
- Aggregated, anonymized usage metrics for product improvement
No customer personal information is ever persisted in our database.
4. How We Use Information
Information accessed and stored is used solely to provide the Inventory Surplus service: detecting surplus stock, surfacing decision workflows, routing inventory to the most effective channel, and reporting outcomes back to you within the app. We do not use your data for advertising, profiling, or any purpose unrelated to the app's functionality.
5. Data Sharing
We do not sell, rent, or trade your data. We do not share your data with third parties for their own marketing or analytics purposes.
We rely on a small number of sub-processors to operate the service, including a cloud hosting and database provider and a transactional email provider. These sub-processors process data only on our behalf, under contractual confidentiality and security obligations, and only to the extent necessary to deliver the service.
6. Data Retention
Operational data is retained for the duration of your app installation. When you uninstall Inventory Surplus, all stored configuration and operational data associated with your shop is deleted within 30 days, or sooner upon request.
7. Shopify Mandatory Webhooks (GDPR)
We honor the three GDPR-related webhooks required of all Shopify apps:
- customers/data_request — Because we do not store customer personal information, we have no customer data to return.
- customers/redact — Because we do not store customer personal information, no customer data exists to redact.
- shop/redact — Upon receipt, we permanently delete all stored merchant configuration and operational data associated with your shop.
8. Security
We follow industry-standard practices to protect the data we handle:
- All data in transit is encrypted using HTTPS/TLS
- Data at rest is encrypted on our infrastructure providers
- Shopify API access tokens are scoped to the minimum permissions required
- Access to production systems follows the principle of least privilege
- Regular review of dependencies and security advisories
No system is perfectly secure, but we work to apply reasonable safeguards appropriate to the limited, non-PII nature of the data we handle.
9. Merchant Rights and Choices
You can uninstall Inventory Surplus from your Shopify admin at any time. Uninstalling revokes our API access and triggers deletion of your stored data. For any privacy-related question or request, contact us through our support page.
10. Children's Privacy
Inventory Surplus is a business tool for Shopify merchants. It is not directed to children, and we do not knowingly collect information from anyone under the age of 16.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. For material changes, we will notify merchants through the app or via email to the address associated with the Shopify store.
12. Contact
Questions about this policy or our data practices? Reach us through our support page and we'll respond promptly.