Privacy policy
What StockDigest reads from your Shopify store, what it keeps and for how long, who helps us run it, and how your data gets deleted.
Who we are
StockDigest is a Shopify app made by Enki Studios, LLC. In this policy, “we” and “us” mean Enki Studios, and “you” means the Shopify merchant who installs StockDigest, unless we say otherwise.
This policy covers the StockDigest app, the StockDigest app for iPhone and iPad, the emails it sends, and this website, stockdigest.madebyenki.com. It explains what data we handle, why, and for how long.
For anything about privacy, email support@madebyenki.com.
The short version
- StockDigest reads your products, stock, locations and orders from Shopify. From orders, it keeps only the number of units of each product sold each day.
- It doesn’t store orders, and it never asks Shopify for your customers’ details.
- It keeps the email addresses you add to receive the digest. Each person must confirm before they get any digest or alert, and every digest and alert email has an unsubscribe link.
- The iPhone and iPad app (Pro) signs in with a one-time code, with no account or password. We keep a record of each signed-in device so we can send it notifications, but never the device’s name.
- Uninstalling the app deletes all of your store’s data from our database.
- We don’t sell data, use it for advertising, or use it to train AI models.
What StockDigest reads from your store
When you install StockDigest, you give it read-only access to four kinds of store data: products, inventory, orders and locations. It can’t change your products, stock, orders or locations. On the Pro plan, with instant alerts on, it also signs up for Shopify’s stock-change notifications, which is how instant alerts work.
The app reads:
- Products: product and variant titles, SKUs, the Vendor field (used as the supplier), product status, whether stock is tracked, links to product images, and when each variant was created.
- Inventory: how many units are available and how many are on the way (shipments in transit), for the whole store and, on Pro, per location.
- Locations: each location’s name, and whether it’s active and holds stock.
- Orders: for each order, only its ID, when it was placed, whether it was cancelled or a test order, the location it shipped from or was created at, and which product variants it contained, in what quantities. When you install, the app reads the last 60 days of orders. After that, it re-reads the last 7 days each day, so refunds and cancellations are counted. Upgrading to Pro re-reads the last 60 days.
- Store details: your store’s name, time zone, currency and Shopify ID.
- Your plan: we ask Shopify which StockDigest plan your store is on. Shopify handles payment, and we never see your payment details.
What we store
We keep only what StockDigest needs to work. For each store, that’s:
- Store details and settings: your store’s Shopify domain, name, Shopify ID, time zone and currency; your plan; your StockDigest settings (lead time, cover days, low-stock level, digest time, not-selling window, and whether instant alerts are on); and technical status, such as when sales were last imported and any import error.
- Login session: the access tokens Shopify issues so the app can read your store data, with the permissions granted and when they expire. The session belongs to the store, not to a person, so it contains no staff names or email addresses.
- Product settings you change: lead time, low-stock level, supplier and alert choice for the products you set them on, saved against Shopify’s ID for each product variant.
- Sales totals: the number of units sold per product variant per day, and monthly totals for older days. These totals aren’t linked to any order or customer.
- Sales per location (Pro, stores with 2 or more locations): units sold per product variant, per location, per day.
- Digests: a copy of each daily digest, so Digest history can show what it said. A digest includes product and variant names, supplier names, links to product thumbnails, stock figures, sales per day, days left, reorder amounts, the not-selling list and the AI highlights. On Pro, it also includes location names and transfer suggestions.
- Email recipients: the addresses you add; whether each is waiting for confirmation, confirmed or unsubscribed; when it was added, sent a confirmation and confirmed; and a random code used in its confirmation and unsubscribe links.
- Email send records: which recipient (by an internal number, not the address) was sent each day’s digest and each alert email, so a retry never sends the same email twice and alerts stay within the daily limit.
- Alert records (Pro): which products, and which products at which locations, have already sent an alert, and which stock items changed recently and are waiting to be checked.
- Locations you leave out: the IDs of locations you untick in Settings.
We don’t keep a copy of your inventory. The dashboard reads stock levels live from Shopify each time you open it. The only stock figures we keep are the ones in saved digests, showing what each morning’s digest said.
What we don’t collect or keep
- Your customers’ details. StockDigest doesn’t request any customer fields from Shopify. We haven’t asked Shopify for access to customer names, email addresses, phone numbers or postal addresses, and we hold no data about your customers.
- Orders. The app reads the order details listed above to count units sold, then keeps only the daily totals.
- Prices and revenue. The app doesn’t read prices, order totals or costs.
- Payment details. Shopify handles billing.
- Staff identities. We don’t store the names, email addresses or IDs of staff who use the app.
Email recipients
You choose who gets StockDigest emails by adding addresses in Settings: up to 3 on Growth and up to 10 on Pro. Recipients are usually your staff, but they can be anyone you add.
- Confirmation first. When you add an address, we send it one email asking the person to confirm. No digest or alert is sent until they open the link and press the confirm button. Opening the link alone doesn’t confirm it. A store can send at most 10 confirmation emails a day.
- What they receive. At most one digest a day. On Pro, with instant alerts on, they also get alert emails. Emails include your store’s name, product names and pictures, stock figures and a link to the app.
- Unsubscribing. Every digest and alert email has an unsubscribe link, which also works with the one-click unsubscribe button in mail apps. Unsubscribing stops all StockDigest emails to that address from that store.
- No other use. We use these addresses only to send StockDigest emails for the store that added them. We don’t send them marketing, and we don’t share them with anyone except Cloudflare, which delivers our emails.
- No tracking. Our emails contain no tracking pixels, and we don’t track whether they’re opened or which links are clicked. Product pictures in the emails load from Shopify’s image servers when the email is opened.
An address stays on the store’s list, even if it’s unconfirmed or unsubscribed, until the store removes it or uninstalls the app. We keep unsubscribed addresses so that emails stay stopped: if the store adds the address again, the person has to confirm again.
If you’re a recipient and want your address deleted rather than just unsubscribed, ask the store to remove it, or email us.
The iPhone and iPad app (Pro)
On the Pro plan, you can follow your store in the StockDigest app for iPhone and iPad. It shows the same stock figures and digests as the Shopify app, and sends notifications for instant alerts and the morning digest.
Signing in. In StockDigest in your Shopify admin, you create a sign-in code. Each code works once, for 10 minutes. There’s no account, password or email address in the app. For each code we store only a scrambled copy (a hash), which store it belongs to, and when it was created, expires and was used.
What we store for each signed-in iPhone or iPad:
- the store it’s signed in to;
- a scrambled copy of the device’s sign-in key (the key itself stays on the device);
- the type of device (“iPhone” or “iPad”) and the app version, so you can tell your devices apart in Settings;
- when it signed in and when it was last used;
- the push tokens Apple gives the app for notifications and widget updates, and whether the app is a test build;
- whether instant alerts and the morning digest notification are on.
We never store the device’s name, and the app doesn’t ask for your name, email address, contacts, photos or location.
Alerts in the app. So the app can list recent alerts, we keep a copy of what each instant alert said (product names, stock figures and reorder advice) for 7 days.
Notifications. Notifications are delivered through Apple’s push notification service. They contain your store’s name, product names and stock figures, so Apple handles that text to deliver it.
On your device. The app keeps the latest digest and stock figures on your device so it opens quickly and widgets can show them. Deleting the app removes them. The camera is used only to scan a sign-in QR code, if you choose to; images aren’t saved or sent anywhere.
No tracking. The app has no ads, no analytics and no tracking, and it doesn’t share data with other companies for advertising.
Signing out. “Disconnect this iPhone” in the app, or “Remove” next to a device in Settings, deletes that device’s record. Devices not used for 180 days are deleted automatically, and uninstalling StockDigest deletes them all.
How we use data
We use the data above only to run StockDigest:
- to work out sales speed, days left and reorder amounts, using plain math (no AI);
- to build and send the daily digest and, on Pro, instant alerts;
- to show your dashboard, digest history and settings, and on Pro, to show them in the iPhone and iPad app and send its notifications;
- to write the AI highlights described below;
- to check your plan and turn on the features it includes;
- to find and fix problems, and to keep the service secure.
We don’t sell data, share it for advertising, or use it to train AI models.
AI highlights
A digest can start with a few short highlights written by AI. To write them, we send a short list of facts to an AI model (currently Google’s Gemma) that Cloudflare runs on its own Workers AI service. The facts go to Cloudflare, not to Google. They contain:
- product and variant names;
- supplier names;
- location names (Pro, stores with 2 or more locations);
- the day’s numbers: stock, sales per day, days left, lead times, reorder amounts and stock on the way.
We don’t send customer data, order details, prices, or your store’s name or web address. On days when there’s nothing to add to the digest’s lists, no AI request is made.
Before highlights are used, we check them: every number and every bold product name must appear in the facts we sent, and percentages aren’t allowed. If the check fails or the AI is unavailable, the digest goes out without highlights. Forecasts and reorder amounts never use AI.
How long we keep data
| Data | How long we keep it |
|---|---|
| Daily sales totals | 120 days, then added to monthly totals |
| Monthly sales totals | While the app is installed |
| Sales per location (Pro) | 120 days |
| Digests | 90 days on Growth, 1 year on Pro |
| Store details, settings and login session | While the app is installed |
| Product settings and locations you leave out | Until you change them, or uninstall |
| Email recipients | Until the store removes them, or uninstalls |
| Digest send records | Deleted nightly once older than 7 days |
| Alert send records | Deleted nightly once older than 2 days |
| Stock changes waiting for an alert check | Until the check runs, usually within minutes; leftovers are deleted within 2 days |
| Alert records | Until the product no longer needs attention |
| Signed-in iPhones and iPads (Pro) | Until signed out or removed, or 180 days without use |
| Sign-in codes | Deleted a day after they expire (codes expire after 10 minutes) |
| What each instant alert said (Pro) | 7 days |
A nightly cleanup applies these limits. Digests are kept according to your current plan, so if you move from Pro to Growth, digests older than 90 days are deleted at the next cleanup. A store without an active plan keeps 90 days.
Uninstalling deletes all of it from our database right away (see “Deleting your data” below). Two kinds of copies follow their own schedules:
- Technical logs. Cloudflare keeps logs of the app’s activity for us, so we can find and fix problems. They include which store a background job ran for, and error messages, which can include an email address if sending to it failed. When an AI highlight fails our check, the facts we sent and the AI’s answer are logged too. Logs are kept for 7 days.
- Backups. Deleted data can remain in our database provider’s recovery history for up to 30 days.
Service providers
We share data only with these providers, and only as needed to run StockDigest:
- Shopify: the platform StockDigest runs on. Shopify provides your store data to the app and handles billing for your plan.
- Cloudflare: hosts the app and this website, stores our database, runs background jobs, runs the AI model for highlights (Workers AI), and sends our emails.
- Apple: delivers notifications to the iPhone and iPad app (Pro), and distributes the app through the App Store.
If you email us, your message is stored by our email provider. Each provider handles data under its own terms and privacy policy.
We may also disclose data if the law requires it. If Enki Studios or StockDigest is sold or merged, data may pass to the new owner, and this policy will keep applying to it.
Where data is processed
StockDigest runs on Cloudflare’s global network. Requests, background jobs, AI highlights and emails can be processed in Cloudflare data centers in different countries, so your data may be processed outside the country where you or your store are based. Our database is stored in North America.
Deleting your data
- When you uninstall. As soon as Shopify tells us you’ve uninstalled StockDigest, we delete all of your store’s data from our database: settings, login session, product settings, sales totals, digests, email recipients, send records, alert records, and signed-in iPhones and iPads. Uninstalling also cancels your subscription. If you reinstall later, the app starts fresh and imports the last 60 days of sales again.
- When Shopify asks. Shopify can send us a request to erase a store’s data. When it does, we delete everything we hold for that store.
- At any time. You can remove recipients and product settings in Settings. To ask us to delete other data, email us.
Copies in technical logs and backups expire on the schedule described above.
Requests about your customers
StockDigest holds no data about your customers. Sales are stored only as totals per product per day, which aren’t linked to any order or person. When Shopify forwards a customer’s request to see or delete their data, there’s nothing for us to return or delete. Shopify’s request includes details that identify the customer. We don’t store them.
Your choices and rights
Merchants can see and change their settings, recipients and digest history in the app, and delete everything by uninstalling. To get a copy of the data we hold for your store, or to have it corrected or deleted, email us.
Recipients can unsubscribe from any digest or alert email, ask the store to remove their address, or email us to have it deleted.
Depending on where you live, you may have rights over your personal data, such as the right to access it, correct it, delete it, get a copy of it, or object to or restrict how it’s used. To use any of these rights, email us. We may need to confirm that you’re the store owner, or the owner of the email address, before we act. We’ll reply as soon as we can, and within the time the law requires. You can also complain to your local data protection authority.
Security
- Encrypted connections. The app, the links in our emails and the app’s requests to Shopify use HTTPS.
- Access through Shopify. The dashboard and settings open only inside your Shopify admin, and the app checks a token signed by Shopify on every request, so only people signed in to your store can use them.
- Checked messages. Before acting on a message from Shopify, such as an uninstall notice, the app checks Shopify’s signature on it.
- Read-only access. StockDigest can’t change your products, inventory, orders or locations.
- Less data to protect. We don’t store orders or customer data.
- Hard-to-guess links. Confirmation and unsubscribe links use long random codes.
- Limited access. Access to our Cloudflare account and database is limited to the people at Enki Studios who run StockDigest.
No system is perfectly secure. If we learn of a security incident that affects your data, we’ll tell you as the law requires.
This website
stockdigest.madebyenki.com has no accounts and no ads. It sets no cookies of its own, and it doesn’t load scripts, fonts or images from other websites.
The reorder calculator works entirely in your browser. The numbers you type aren’t sent to us or saved.
Cloudflare hosts the site. Like any web host, it receives technical details such as your IP address and browser type when you visit, in order to deliver the pages.
The “Add to Shopify” buttons link to the Shopify App Store. The links include tags that show which page of our site the click came from. Shopify’s privacy policy covers your visit to the App Store.
If you email us, we use your address and message only to reply and to keep a record of the conversation.
Children
StockDigest is a tool for businesses and isn’t meant for children. We don’t knowingly collect personal data from anyone under 16. If you believe a child’s email address was added as a recipient, email us and we’ll delete it.
Changes to this policy
We’ll update this policy when the way StockDigest handles data changes, and change the date at the top of this page. If a change significantly affects how we handle your data, we’ll post it on this page at least 30 days before it takes effect.
Contact
- Email: support@madebyenki.com