Privacy Policy
Last updated: September 24, 2026
Version: stockbeat-privacy-2026-09-24
StockBeat ("we", "our", or "the App") is a Shopify application developed by Noema Works that helps merchants monitor inventory levels, detect stockout risks, and recover cash tied in stagnant stock.
This Privacy Policy describes how we collect, use, and protect information when you install and use StockBeat, submit a message through the in-app Support page, or submit your contact information through the StockBeat early access page.
1. Information We Collect
When you install StockBeat, we access the following Shopify data through authorized API scopes:
Store & Product Data
- Product catalog (titles, variants, SKUs, prices and available cost data)
- Inventory levels, locations and inventory-transfer information
- Order history (order IDs, line items, quantities, revenue amounts, dates)
Authentication Data
- Shopify store domain
- OAuth access tokens (required to communicate with the Shopify API on your behalf)
Merchant Identity
- Store owner name and email (provided by Shopify during app installation)
Pre-Launch Contact Requests
- Email address submitted through the StockBeat early access page
- Optional Shopify store URL or store domain that you choose to share with us
Support & Feedback Data
- Messages you choose to send through the in-app Support page
- Optional one-to-five ratings for ease of use, features, and likelihood to recommend
- The Shopify user ID and email available for the signed-in administrator who submits the message
Data We Do Not Request From Shopify
- End-customer personally identifiable information (names, emails, phone numbers, or addresses)
- Payment or credit card information
- Customer browsing or behavioral data
Beat Agent and Optional Slack Integration
When Beat Agent is used, relevant product and variant labels, inventory and sales metrics, estimated exposure, screen context and conversation content may be sent to Google Gemini to generate an explanation. Do not enter customer personal data, passwords or other secrets in prompts. AI output is guidance and does not guarantee financial outcomes.
If you connect Slack, we store workspace/channel metadata and an encrypted incoming-webhook credential. Selected inventory alerts are delivered to the channel you authorize. Disconnecting removes the delivery credential; copies already delivered remain subject to your workspace retention settings.
2. How We Use Your Data
We use the collected data exclusively to:
- Inventory Monitoring: Track stock levels across your locations and variants.
- Stockout Risk Detection: Calculate sales velocity and predict when products may go out of stock.
- Cash Recovery Analysis: Identify stagnant inventory tying up capital.
- Dashboard & Reporting: Display insights, metrics, and recommendations within the App.
- Notifications: Send inventory insight digests and plan-aware alert notifications to configured recipients.
- Support: Respond to messages you submit, review optional product feedback, and notify our support team.
- Early Access & Launch Updates: Review expressions of interest, follow up about potential early access, and notify interested merchants when StockBeat launches publicly.
- Billing: Process subscription charges through Shopify's billing API.
We do not sell, rent, or share your data with third parties for marketing or advertising purposes.
3. Data Storage & Security
- Infrastructure: Data is stored in a PostgreSQL database hosted on Supabase, with servers located in secure data centers.
- Encryption in Transit: All data transmitted between your browser, Shopify, and our servers is encrypted using TLS/HTTPS with HSTS enforcement.
- Encryption at Rest: Database storage is encrypted at the disk level by our infrastructure provider.
- Access Control: API access is restricted via bearer token authentication with timing-safe cryptographic comparison.
- Isolation: Each store's data is logically isolated by shop ID. No store can access another store's data.
4. Data Retention
- Active stores: We retain the operational data required to provide StockBeat for as long as the App remains installed on your store.
- After uninstallation: Access is revoked and durable background deletion of operational store data is queued. This includes products, inventory, sales facts, credentials, sessions, refresh metadata, notification settings and support messages/ratings. Deletion is not completed synchronously inside the uninstall webhook response.
- Legal and audit records: We may retain the minimum records needed to evidence your acceptance of the StockBeat Terms of Use and acknowledgement of this Privacy Policy, including document versions, timestamps, shop identity, and related audit metadata. These records are retained only as needed to exercise or defend legal rights and are not used to operate the App after uninstallation.
- GDPR shop redaction: Shopify sends a final redaction request 48 hours after uninstallation. We process this request and confirm operational store data has been purged, while preserving legal/audit records where retention is legally required or justified.
- Exceptional orphaned records: If a technical failure prevents the normal uninstall purge flow, our operational policy is to remove orphaned tenant data within 30 days.
5. Data Sharing
We use the following third-party services to operate the App:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting | Store/product data, merchant/admin identity, credentials and legal/support records |
| Shopify | Platform & billing | OAuth tokens, billing events |
| Resend | Transactional email delivery for inventory alerts, early access contact requests, and in-app Support messages | Alert content; submitted contact email and optional store URL; Support message, ratings, store identity, and sender email when available for replies |
| Railway | Application and background-job hosting | Operational application data and sanitized service logs |
| Cloudflare | Public website delivery and early-access form processing | Web requests and information submitted through the early-access form |
| Google Gemini API | AI-assisted inventory explanations in Beat Agent | Product/variant labels, inventory and sales metrics, estimated exposure, screen context and conversation content |
| Slack (optional) | Merchant-authorized channel notifications | Selected alert content, workspace/channel metadata and delivery credential |
We use these services to provide StockBeat, not to sell merchant data for advertising. Data sent to an optional integration is also subject to your settings and the provider's applicable terms.
6. Your Rights
As a merchant, you have the right to:
- Access: Request a copy of the data we store about your shop.
- Deletion: Uninstall the App at any time to start deletion of operational app data.
- Legal records: Legal/audit records may be retained after deletion of operational app data when necessary to exercise or defend legal rights.
- Portability: Request an export of your data in a machine-readable format.
- Correction: Contact us to correct any inaccurate data.
End-Customer Rights (GDPR / CCPA)
StockBeat does not request end-customer contact fields from Shopify for inventory analysis. We process Shopify's mandatory GDPR webhooks:
- Customer Data Request: We securely queue Shopify's request and make the retained order-line records for the specified orders available as a JSON export to an authenticated administrator of the requesting store, under Customer privacy requests in the App. The merchant is responsible for providing that file to the requesting customer. Downloadable files expire after 30 days.
- Customer Redaction: We securely queue deletion of the specified order records, remove their identifiable contributions from our sales facts and existing export files, and rebuild affected analytics. We retain a store-scoped hash of each deleted order identifier to prevent it from being imported again while the App remains installed. These suppression records are pseudonymized, not anonymous, and are deleted with the store's operational data.
- Shop Redaction: We permanently delete operational store data, subject to legally required or justified retention of legal/audit records.
If an end-customer contacts you regarding their data, please note that StockBeat uses order and order-line identifiers, dates, product quantities and revenue for inventory analysis without requesting customer contact fields. Please do not include customer personal information in support messages or Beat Agent prompts.
Historical product/day aggregates for which no order association is retained cannot be attributed to an individual customer. Processing is asynchronous; a successful webhook acknowledgement means the request was queued, not that deletion is already complete. Request status is available in the App. If processing needs attention or you need assistance fulfilling a request, contact us at contact@noemaworks.com. Infrastructure backups may retain deleted records for the provider's backup window; they are not served by the App during normal operation.
7. Cookies & Tracking
StockBeat is an embedded Shopify app and does not use cookies, tracking pixels, or third-party analytics on your storefront. The App operates entirely within the Shopify Admin interface.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Each published version has a unique version identifier and effective date so StockBeat can record which version was acknowledged when you accept the App's legal terms.
If we make material changes, we will notify you through the App or via email and may require a new acknowledgement before continued use of StockBeat.
9. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Noema Works
Email: contact@noemaworks.com
10. Shopify App Store
StockBeat is being prepared for public distribution through the Shopify App Store. Use of Shopify APIs is subject to Shopify's API Terms of Service and Shopify's Partner Program Agreement.