Privacy Policy

Last updated: July 24, 2026

1. Introduction

RestockBolt ("we," "our," or "us") provides a Shopify application that captures customer email addresses on sold-out product variants, and sends transactional back-in-stock notifications by email when inventory returns. This Privacy Policy describes what information we collect, how we use it, and how we protect it.

By installing or using RestockBolt, you agree to the practices described in this policy.

2. Information We Collect

2.1 Store Information

When you install RestockBolt, we receive and store basic information about your Shopify store, including:

  • Your Shopify store domain
  • Store name and contact information
  • Shopify access tokens required for API communication

2.2 Subscriber Information

When a customer signs up on a sold-out variant in your store, we store:

  • The customer's email address
  • The Shopify variant ID they signed up for
  • The timestamp of the subscription
  • Notification status (pending, notified, when they were contacted, and whether they have unsubscribed)

We do not collect names, IP addresses for marketing, behavioral tracking pixels, or any other customer PII beyond what is voluntarily entered into the back-in-stock form.

2.3 Inventory and Product Data

We receive inventory level events from Shopify webhooks to determine when to send notifications. We store minimal product and variant metadata (titles, variant IDs, inventory quantities) necessary to match subscribers to the correct restock events.

2.4 Activity Logs

We maintain operational logs of webhook deliveries, notification sends, and admin actions with timestamps for troubleshooting and support.

2.5 Billing Information

Subscription and billing are managed entirely through Shopify. We store your plan name and billing cycle dates but do not process or store payment card information.

3. How We Use Your Information

We use the collected information to:

  • Deliver back-in-stock notifications by email to customers who signed up on sold-out variants
  • Detect inventory changes and match restocks to the correct pending subscribers
  • Display pending and notified subscribers in your Shopify admin dashboard
  • Honor unsubscribes, and keep a record that consent was given and later withdrawn
  • Manage your subscription and plan allocation
  • Troubleshoot issues and provide customer support

4. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. Your data is only shared with:

  • Shopify — through their Admin API and webhooks to read inventory, verify storefront requests, and display admin dashboards
  • Resend — our transactional email provider, which delivers restock notifications on our behalf and handles bounces and delivery tracking
  • Klaviyo only if you, the merchant, connect your Klaviyo account. When connected, subscribers are synced to the Klaviyo list you choose so you can market to them from your own account. This integration is off by default and entirely under your control; it is your responsibility to ensure you have the appropriate consent for any marketing you send through it.

These integrations are essential to the core functionality of RestockBolt and only transmit data necessary for sending notifications.

5. Data Security

We take the security of your data seriously:

  • All storefront form submissions are HMAC-verified through Shopify's App Proxy before any data is written
  • All data is transmitted over HTTPS encrypted connections
  • Database access is restricted and secured
  • Email addresses are redacted in our application logs
  • We follow security best practices for application development and deployment

6. Data Retention and Deletion

We retain your data only as long as RestockBolt is installed on your Shopify store. When you uninstall RestockBolt:

  • All your data — including your store information, subscribers, their email addresses, and activity logs — is permanently deleted within 48 hours
  • We listen for Shopify's app/uninstalled webhook and begin automated deletion immediately

We also honor Shopify's mandatory privacy webhooks. When a store owner or customer requests erasure through Shopify, we delete the matching subscriber records — matched on email address — for that store.

7. Your Rights

7.1 Merchants

You have the right to:

  • Access the data we hold about your store and subscribers
  • Delete individual subscribers from the admin dashboard
  • Delete all your data by uninstalling RestockBolt from your Shopify store
  • Request a copy of your stored data by contacting us

7.2 Customers

If you signed up to be notified about a product, you have the right to:

  • Stop emails at any time using the unsubscribe link in any message we send you
  • Request access to, or deletion of, the email address we hold for you — either through the store you signed up on, or by contacting us directly at the address below

8. Cookies, Analytics, and Error Reporting

RestockBolt does not use cookies for advertising, and does not use behavioral tracking pixels or advertising networks. Session cookies required by Shopify for authentication are managed by the Shopify platform.

We use Mixpanel for product analytics and Sentry for error reporting, so we can understand how merchants use the app and fix faults. These are merchant-level tools: analytics events are identified by store, not by customer. We do not send customer email addresses to them. Where an event needs to distinguish one subscriber from another, we send a one-way keyed hash that cannot be reversed back into a contact detail.

9. Children's Privacy

RestockBolt is a business tool intended for use by Shopify store owners. We do not knowingly collect information from children under the age of 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the app or by other appropriate means. Your continued use of RestockBolt after any changes indicates your acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at:

support@restockbolt.com