Privacy Policy

Last updated: September 24, 2026

Version: stockbeat-privacy-2026-09-24

StockBeat ("we", "our", or "the App") is a Shopify application developed by Noema Works that helps merchants monitor inventory levels, detect stockout risks, and recover cash tied in stagnant stock.

This Privacy Policy describes how we collect, use, and protect information when you install and use StockBeat, submit a message through the in-app Support page, or submit your contact information through the StockBeat early access page.

1. Information We Collect

When you install StockBeat, we access the following Shopify data through authorized API scopes:

Store & Product Data

  • Product catalog (titles, variants, SKUs, prices and available cost data)
  • Inventory levels, locations and inventory-transfer information
  • Order history (order IDs, line items, quantities, revenue amounts, dates)

Authentication Data

  • Shopify store domain
  • OAuth access tokens (required to communicate with the Shopify API on your behalf)

Merchant Identity

  • Store owner name and email (provided by Shopify during app installation)

Pre-Launch Contact Requests

  • Email address submitted through the StockBeat early access page
  • Optional Shopify store URL or store domain that you choose to share with us

Support & Feedback Data

  • Messages you choose to send through the in-app Support page
  • Optional one-to-five ratings for ease of use, features, and likelihood to recommend
  • The Shopify user ID and email available for the signed-in administrator who submits the message

Data We Do Not Request From Shopify

  • End-customer personally identifiable information (names, emails, phone numbers, or addresses)
  • Payment or credit card information
  • Customer browsing or behavioral data

Beat Agent and Optional Slack Integration

When Beat Agent is used, relevant product and variant labels, inventory and sales metrics, estimated exposure, screen context and conversation content may be sent to Google Gemini to generate an explanation. Do not enter customer personal data, passwords or other secrets in prompts. AI output is guidance and does not guarantee financial outcomes.

If you connect Slack, we store workspace/channel metadata and an encrypted incoming-webhook credential. Selected inventory alerts are delivered to the channel you authorize. Disconnecting removes the delivery credential; copies already delivered remain subject to your workspace retention settings.

2. How We Use Your Data

We use the collected data exclusively to:

  • Inventory Monitoring: Track stock levels across your locations and variants.
  • Stockout Risk Detection: Calculate sales velocity and predict when products may go out of stock.
  • Cash Recovery Analysis: Identify stagnant inventory tying up capital.
  • Dashboard & Reporting: Display insights, metrics, and recommendations within the App.
  • Notifications: Send inventory insight digests and plan-aware alert notifications to configured recipients.
  • Support: Respond to messages you submit, review optional product feedback, and notify our support team.
  • Early Access & Launch Updates: Review expressions of interest, follow up about potential early access, and notify interested merchants when StockBeat launches publicly.
  • Billing: Process subscription charges through Shopify's billing API.

We do not sell, rent, or share your data with third parties for marketing or advertising purposes.

3. Data Storage & Security

  • Infrastructure: Data is stored in a PostgreSQL database hosted on Supabase, with servers located in secure data centers.
  • Encryption in Transit: All data transmitted between your browser, Shopify, and our servers is encrypted using TLS/HTTPS with HSTS enforcement.
  • Encryption at Rest: Database storage is encrypted at the disk level by our infrastructure provider.
  • Access Control: API access is restricted via bearer token authentication with timing-safe cryptographic comparison.
  • Isolation: Each store's data is logically isolated by shop ID. No store can access another store's data.

4. Data Retention

  • Active stores: We retain the operational data required to provide StockBeat for as long as the App remains installed on your store.
  • After uninstallation: Access is revoked and durable background deletion of operational store data is queued. This includes products, inventory, sales facts, credentials, sessions, refresh metadata, notification settings and support messages/ratings. Deletion is not completed synchronously inside the uninstall webhook response.
  • Legal and audit records: We may retain the minimum records needed to evidence your acceptance of the StockBeat Terms of Use and acknowledgement of this Privacy Policy, including document versions, timestamps, shop identity, and related audit metadata. These records are retained only as needed to exercise or defend legal rights and are not used to operate the App after uninstallation.
  • GDPR shop redaction: Shopify sends a final redaction request 48 hours after uninstallation. We process this request and confirm operational store data has been purged, while preserving legal/audit records where retention is legally required or justified.
  • Exceptional orphaned records: If a technical failure prevents the normal uninstall purge flow, our operational policy is to remove orphaned tenant data within 30 days.

5. Data Sharing

We use the following third-party services to operate the App:

Service Purpose Data Shared
Supabase Database hosting Store/product data, merchant/admin identity, credentials and legal/support records
Shopify Platform & billing OAuth tokens, billing events
Resend Transactional email delivery for inventory alerts, early access contact requests, and in-app Support messages Alert content; submitted contact email and optional store URL; Support message, ratings, store identity, and sender email when available for replies
RailwayApplication and background-job hostingOperational application data and sanitized service logs
CloudflarePublic website delivery and early-access form processingWeb requests and information submitted through the early-access form
Google Gemini APIAI-assisted inventory explanations in Beat AgentProduct/variant labels, inventory and sales metrics, estimated exposure, screen context and conversation content
Slack (optional)Merchant-authorized channel notificationsSelected alert content, workspace/channel metadata and delivery credential

We use these services to provide StockBeat, not to sell merchant data for advertising. Data sent to an optional integration is also subject to your settings and the provider's applicable terms.

6. Your Rights

As a merchant, you have the right to:

  • Access: Request a copy of the data we store about your shop.
  • Deletion: Uninstall the App at any time to start deletion of operational app data.
  • Legal records: Legal/audit records may be retained after deletion of operational app data when necessary to exercise or defend legal rights.
  • Portability: Request an export of your data in a machine-readable format.
  • Correction: Contact us to correct any inaccurate data.

End-Customer Rights (GDPR / CCPA)

StockBeat does not request end-customer contact fields from Shopify for inventory analysis. We process Shopify's mandatory GDPR webhooks:

  • Customer Data Request: We securely queue Shopify's request and make the retained order-line records for the specified orders available as a JSON export to an authenticated administrator of the requesting store, under Customer privacy requests in the App. The merchant is responsible for providing that file to the requesting customer. Downloadable files expire after 30 days.
  • Customer Redaction: We securely queue deletion of the specified order records, remove their identifiable contributions from our sales facts and existing export files, and rebuild affected analytics. We retain a store-scoped hash of each deleted order identifier to prevent it from being imported again while the App remains installed. These suppression records are pseudonymized, not anonymous, and are deleted with the store's operational data.
  • Shop Redaction: We permanently delete operational store data, subject to legally required or justified retention of legal/audit records.

If an end-customer contacts you regarding their data, please note that StockBeat uses order and order-line identifiers, dates, product quantities and revenue for inventory analysis without requesting customer contact fields. Please do not include customer personal information in support messages or Beat Agent prompts.

Historical product/day aggregates for which no order association is retained cannot be attributed to an individual customer. Processing is asynchronous; a successful webhook acknowledgement means the request was queued, not that deletion is already complete. Request status is available in the App. If processing needs attention or you need assistance fulfilling a request, contact us at contact@noemaworks.com. Infrastructure backups may retain deleted records for the provider's backup window; they are not served by the App during normal operation.

7. Cookies & Tracking

StockBeat is an embedded Shopify app and does not use cookies, tracking pixels, or third-party analytics on your storefront. The App operates entirely within the Shopify Admin interface.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Each published version has a unique version identifier and effective date so StockBeat can record which version was acknowledged when you accept the App's legal terms.

If we make material changes, we will notify you through the App or via email and may require a new acknowledgement before continued use of StockBeat.

9. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Noema Works

Email: contact@noemaworks.com

10. Shopify App Store

StockBeat is being prepared for public distribution through the Shopify App Store. Use of Shopify APIs is subject to Shopify's API Terms of Service and Shopify's Partner Program Agreement.