Back in Stock
  • Features
  • Privacy
  • Terms
  • Install on Shopify

Privacy Policy

Effective date: August 7, 2026 · Last updated: August 7, 2026

This Privacy Policy explains how Back in Stock (“we”, “us”, or “our”) collects, uses, stores, and shares information when merchants install and use our Shopify application, and when shoppers interact with restock waitlist features on a merchant’s storefront. This policy is intended to satisfy Shopify App Store privacy disclosure expectations and applicable privacy laws.

If you do not agree with this policy, please do not install or use the App. For questions, contact us at

1. Who we are

Back in Stock is a Shopify application that helps merchants capture customer interest when products or variants are out of stock and notify those customers by email when inventory becomes available again.

Developer / data controller for the App: the operator of Back in Stock, reachable at ''.

When the App processes a shopper’s email on a merchant’s store, the merchant is typically the controller of that customer relationship, and we process that information on the merchant’s behalf to provide the restock notification service.

2. Scope

This policy covers:

  • Merchants who install, configure, or use the Back in Stock Shopify app (“Merchants”);
  • Shoppers who submit an email address to receive a back-in-stock or restock notification on a Merchant’s storefront (“Customers”); and
  • Visitors to this marketing website.

3. Information we collect through Shopify’s APIs

When a Merchant installs the App and grants permission, we access Shopify Admin API data required to operate restock alerts. Depending on configuration and authorized scopes, this may include:

  • Shop information: shop domain, shop name, Shopify shop ID, currency, timezone, and basic plan or locale settings needed to run the App.
  • Product and inventory data: product IDs, variant IDs, titles, handles, SKUs (if present), images used for notification context, and inventory quantities or availability signals.
  • App installation metadata: install and uninstall timestamps, granted access scopes, and webhook registration status.

We do not use Shopify APIs to export a Merchant’s full customer database for unrelated marketing. Customer emails are collected only when a shopper voluntarily joins a restock waitlist (see below), or as otherwise required to fulfill Shopify compliance webhooks.

4. Information we collect directly from Merchants

  • Account and contact details: email address associated with the Shopify store or provided for support, billing communication, or App configuration.
  • App settings: preferences such as which products show the waitlist widget, email copy defaults, and notification behavior.
  • Support communications: messages you send us, including any screenshots or store details you choose to share.
  • Usage and diagnostic logs: technical logs related to App performance, errors, authentication events, and webhook delivery, which may include IP address, user-agent, timestamps, and request identifiers.

5. Information we collect from Merchants’ customers

When a Customer requests a restock notification on a Merchant’s storefront, we collect:

  • Email address provided by the Customer;
  • Product and variant identifiers the Customer wants to be notified about (and related product title/options needed to send a meaningful email);
  • Shop domain associated with the subscription;
  • Timestamp of subscription and notification status (pending, sent, cancelled);
  • Optional technical metadata needed to prevent abuse (for example IP address, browser user-agent, and rate-limiting signals).

We do not intentionally collect government IDs, payment card numbers, or precise GPS location from Customers through the App. Payment processing for purchases occurs through Shopify and the Merchant’s checkout—not through Back in Stock.

Cookies and tracking on Merchant storefronts: the waitlist feature may use strictly necessary cookies or local storage to operate the form and reduce duplicate submissions. We do not use Customer waitlist data to run cross-store advertising networks.

This marketing website: may use essential cookies required for security and basic functionality. If we later add analytics, we will update this policy and, where required, obtain consent.

6. How we use the information

We use collected information to:

  • Provide, maintain, and improve the Back in Stock service;
  • Display waitlist options on sold-out products and store Customer subscriptions;
  • Detect inventory availability changes and send restock notification emails;
  • Authenticate Merchants, secure the App, and prevent fraud or abuse;
  • Provide Merchant support and respond to inquiries;
  • Comply with law and with Shopify’s mandatory compliance webhook requirements (customer data requests, customer redaction, and shop redaction);
  • Send service-related notices to Merchants (for example security or material App changes).

We do not sell personal information. We do not rent Customer waitlist emails to third parties for their own marketing. We do not use Customer emails for our own unrelated advertising.

7. Legal bases (where applicable)

Where GDPR or similar laws apply, we rely on one or more of the following:

  • Performance of a contract — to provide the App to Merchants and to send restock emails Customers requested;
  • Legitimate interests — to secure, debug, and improve the service in ways that do not override individual rights;
  • Consent — where a Customer opts in to receive a restock notification, or where consent is otherwise required;
  • Legal obligation — to meet applicable legal and platform requirements.

8. How we share information

We may share information with:

  • Service providers who help us host the App, store data, send transactional emails, monitor uptime, or provide support tooling. These providers are permitted to process data only to perform services for us and under appropriate confidentiality and security obligations.
  • Shopify, as needed to operate within the Shopify platform and respond to platform requirements.
  • The Merchant, who can access waitlist and notification-related data for their own store through the App.
  • Authorities or professional advisors when required by law, valid legal process, or to protect rights, safety, and security.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections and notice where required.

9. International data transfers

We may store and process information on servers located outside your country of residence, including outside the European Economic Area (EEA), United Kingdom, or Switzerland. Where required, we use appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms offered by our infrastructure providers).

10. Data retention

  • Active waitlist subscriptions: retained until a notification is sent, the Customer unsubscribes or the subscription is otherwise cancelled, the Merchant deletes the data, or retention limits described below apply.
  • After a restock email is sent: we may retain limited records (for example delivery status and timestamps) for a reasonable period to prevent duplicate sends, handle support issues, and maintain security logs—typically no longer than 24 months unless a longer period is required for legal compliance.
  • Merchant account data: retained for as long as the App remains installed and for a limited period afterward as needed for backups, billing disputes, or legal obligations.
  • Shop uninstall / shop redact: when Shopify sends a shop/redact compliance webhook (or when we complete uninstall cleanup), we delete or anonymize personal data we store for that shop within the timelines Shopify and applicable law expect, except where retention is required by law.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including encrypted transit (HTTPS/TLS), access controls, least-privilege practices for production systems, and verification of Shopify webhook authenticity (HMAC) before processing compliance or App webhooks.

No method of transmission or storage is 100% secure. If you believe your account or data has been compromised, contact us immediately at ''.

12. Shopify mandatory compliance webhooks

For App Store distribution, Back in Stock is designed to subscribe to and process Shopify’s mandatory compliance topics:

  • customers/data_request — we locate personal data we hold about the requested customer for that shop and provide it to the Merchant (or as Shopify’s process requires) so the Merchant can respond to the data subject.
  • customers/redact — we delete or anonymize personal data we store about the specified customer for that shop, except where we must retain information for legal reasons.
  • shop/redact — after uninstall and the applicable delay, we delete or anonymize personal data stored for that shop.

Invalid webhook signatures are rejected. Merchants remain responsible for responding to their own customers through Shopify’s privacy tools where Shopify routes requests to the Merchant.

13. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data, to object to certain processing, and to withdraw consent where processing is consent-based.

  • Customers: you can use unsubscribe links in restock emails where provided. You may also contact the Merchant’s store privacy contact, or email us at '' with enough detail to identify the shop and your email address. We may need to coordinate with the Merchant.
  • Merchants: you may request access to or deletion of Merchant account data by emailing us, uninstalling the App, and/or using Shopify’s data request flows.

You may also have the right to lodge a complaint with a supervisory authority in your jurisdiction.

14. Children’s privacy

The App is intended for Merchants operating commercial Shopify stores and is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal data through the App, contact us and we will take appropriate steps to delete it.

15. Third-party services and Merchant responsibility

Merchants are responsible for providing their own storefront privacy disclosures to Customers, obtaining any consents required for restock marketing or notification emails in their jurisdictions, and configuring the App in a lawful manner. Shopify’s own privacy practices are governed by Shopify’s policies—not this document.

16. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we may provide additional notice through the App or by email where appropriate. Continued use of the App after an update constitutes acceptance of the revised policy to the extent permitted by law.

17. Contact

For privacy questions, data requests, or concerns:

Email: ''
App: Back in Stock (Shopify)
Website: this Back in Stock landing site

If a physical mailing address is required for your jurisdiction or becomes available for our operating entity, we will add it to this section.

Back in Stock

Restock alerts for Shopify merchants.

Contact: ''

  • Home
  • Privacy Policy
  • Terms of Service
  • Support