Privacy policy
Last updated: 15 August 2026
StorePulse monitors a Shopify store and tells the merchant what needs attention. This page describes exactly which personal data the app reads, why it needs it, and how long it keeps it. It is written to match what the application actually does.
Who this covers
StorePulse is installed by a Shopify merchant on their own store. The merchant is the data controller for their customers' personal data; StorePulse acts as a data processor on the merchant's behalf and processes personal data only to provide the monitoring and alerting features described below.
What personal data we process
StorePulse reads exactly two protected customer fields from the Shopify Admin API:
- Customer name — shown on delayed-order alerts and in the orders list so the merchant knows who is waiting on an order.
- Customer email — shown alongside the order, and used to distinguish new from returning customers in daily metrics.
We do not read customer phone numbers, shipping addresses, billing addresses, payment details, or browsing behaviour. We do not use tracking pixels or third-party analytics inside the app.
We also process non-personal store data: products, variants, inventory levels, order totals, fulfillment and financial status, refund amounts, and the shop's currency and timezone.
Why we process it
Solely to generate alerts and reports for the merchant who installed the app: unexpected sold-out products, low stock, orders left unfulfilled, refund spikes, sales drops and product performance changes, plus the daily and weekly summaries of that information.
We do not sell personal data, share it with advertisers, use it to train machine-learning models, or use it for any purpose other than operating StorePulse for the merchant.
Where it is stored
Data is stored in a PostgreSQL database hosted by Neon, and the application runs on Vercel. Emails are delivered by Resend. All three are subprocessors acting under contract. Data is encrypted in transit (TLS) and at rest, including backups.
How long we keep it
- Orders are synchronised on a rolling 60-day window.
- When the app is uninstalled, the access token is destroyed immediately and processing stops.
- When Shopify sends the
shop/redactrequest (48 hours after uninstall), the store record and every related row — orders, products, alerts, metrics, logs — is permanently deleted. - When Shopify sends
customers/redactfor an individual, that customer's name and email are erased from our records while anonymous order totals remain for the merchant's reporting.
Access logging
Every read of customer name or email is recorded in an internal access log, including what was accessed, how many records, and whether it was a merchant viewing a screen or an automated sync. The log records the fact of access, never the personal data itself. Merchants can view their own log in the app under Notifications → Data access log.
Individual rights
Requests from a customer should be made to the merchant who operates the store. Shopify forwards those requests to us automatically, and StorePulse responds to customers/data_request, customers/redact and shop/redact without manual intervention.
Contact
Questions about this policy or about data StorePulse holds: contact the app developer through the Shopify App Store listing, or at the support address given there.