Privacy Policy
Last updated: September 24, 2026
SupplyKit is a Shopify app that helps a merchant decide what stock to reorder, create purchase orders for their suppliers, and receive the stock into Shopify. This policy explains what data the app processes, why, and how it is protected.
SupplyKit stores no customer (buyer) personal data. It requests read_products, read_inventory, write_inventory (to receive purchase-order stock and, on Pro, update cost per item), read_locations and read_orders. Orders are read only for each line's product variant and quantity (plus whether the order was cancelled or a test), to count how many of each product sold. It never reads a customer's name, email, phone or address, and it stores nothing per order — only a total of units sold per product variant.
1. What We Process
1.1 Merchant / Store Data
The store's myshopify.com domain, an expiring Shopify access token, the subscription plan tier, and install status — the data needed to run the app for the store and bill it through Shopify. The store's name, contact email, currency and address are read to fill in purchase orders. Shopify's session data for a signed-in staff member may include that staff member's name, email address, and admin language, as provided by Shopify.
1.2 Catalog, Inventory and Sales Totals
Product and variant titles, SKUs, vendors, cost per item, stock levels per location, and the store's locations, refreshed while the app is in use; older copies are deleted after each refresh. From orders, only a total of units sold per variant over the last 30 or 56 days.
1.3 Suppliers and Purchase Orders
What the merchant enters: supplier names and business contact details (contact name, email, phone, address), supplier SKUs, prices, pack sizes and minimum orders, and purchase orders with their items, costs, dates and notes, plus records of stock received.
We process the minimum data needed to provide the app's value and use it only for that purpose. We do not sell data, and we do not use it for advertising or automated decision-making.
2. How We Collect It
- From Shopify, when a merchant installs the app and grants access, and through the Admin API for the store's products, inventory, locations and orders.
- From the merchant, when staff add suppliers, import price lists, and create or receive purchase orders in the embedded admin.
3. How We Protect It
- All traffic is served over TLS 1.2+.
- Data is stored on a DigitalOcean server; production access is SSH-key-only and limited to the operator, and the host runs standard hardening. Development and production data are kept separate.
- Access tokens are stored server-side only and are never exposed to the browser.
- Because SupplyKit holds no buyer personal data, there is no customer name, address, or payment information at rest to expose.
- We maintain a security incident-response process and will notify affected merchants of a confirmed data breach within 72 hours.
4. How Long We Keep It
- Suppliers, purchase orders and settings are kept while the app is installed. Catalog and sales snapshots are replaced on each refresh.
- When a merchant uninstalls, access tokens are deleted immediately and the store's data held by the app is deleted in response to Shopify's shop-redaction request, in all cases within 30 days of uninstall.
5. Who We Share It With
We use a small number of sub-processors, only as needed to run the service:
- DigitalOcean — server and database hosting (United States).
- Shopify — the platform the app runs on.
- Mailgun — delivers the purchase-order emails a merchant chooses to send to their supplier (from support@nerdlabs.us, with the merchant as reply-to).
We do not share data with anyone else, and we never sell it.
6. Data Subject Rights (Shopify Privacy Webhooks / GDPR)
SupplyKit implements Shopify's mandatory privacy webhooks in full. Because the app stores no customer personal data:
- A customer data request returns no customer records, because SupplyKit holds none.
- A customer redaction has no customer data to remove.
- A shop redaction deletes all of the store's data held by the app (suppliers, purchase orders, receipts, catalog and sales snapshots, settings, plan and install records, and sessions).
These support the merchant's obligations under the GDPR, the CCPA/CPRA, and similar laws. Merchants agree to SupplyKit's terms and this policy when they install the app.
7. Changes
We will update this page when our practices change and revise the date at the top.
8. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
NerdLabs (operated by Joren Winge)
Email: support@nerdlabs.us
Website: nerdlabs.us