Stocked
Privacy Policy
This Privacy Policy explains how Mage2 (“we”, “us”, “our”) collects, uses, shares, and protects personal information when you or your customers use Stocked, our back-in-stock notification app for Shopify (the “App”). It applies to merchants who install Stocked from the Shopify App Store and to the shoppers who sign up for back-in-stock alerts through a store that uses Stocked.
Stocked is published by Mage2 and operated from our infrastructure on Amazon Web Services. If you have any questions about this policy or our practices, contact us at [email protected].
1. Our role
Under data-protection laws such as the EU/UK GDPR and the California Privacy Rights Act (CPRA), our role depends on whose data we are handling:
- Shopper personal data (email addresses and the products a shopper asks to be notified about) is provided to us by the merchant whose store the shopper visited. The merchant decides why and how this data is processed and is the data controller. We process this data only on the merchant’s behalf as a data processor, in accordance with our agreement with the merchant and this policy.
- Merchant and installation data (the shop’s domain, the App’s configuration, billing usage and similar) is processed by us as a data controller for the purpose of providing the App.
2. Information we collect
| Category | What we collect | Why | Retention |
|---|---|---|---|
| Shopper subscriptions | Email address; the product and variant the shopper asked to be notified about (product ID, variant ID, title, handle); the time of the request and the time we sent a notification. | To send the back-in-stock email the shopper requested. | Until the merchant uninstalls the App, the shopper or merchant requests deletion, or for up to 24 months after the last activity — whichever comes first. |
| Merchant account | Shop domain (e.g. example.myshopify.com) and the Shopify-issued OAuth access token used to call the Shopify Admin API on your store’s behalf. | To authenticate the App with your store and operate the App. | For as long as the App is installed; deleted within 30 days of uninstall. |
| App settings | Your back-in-stock email template (subject, heading, body, button), your sending identity (sender name, sender email and domain, the email provider’s domain reference, DNS records, verification status). | To send notifications from your verified domain using the wording you chose. | For as long as the App is installed; deleted within 30 days of uninstall. |
| Usage counters | The number of back-in-stock emails sent per shop per calendar month. | To enforce the monthly email limit of your subscription plan. | For as long as the App is installed; deleted within 30 days of uninstall. |
| Shopify webhooks | Inventory update events on your store (inventory_levels/update) and compliance events (customers/data_request, customers/redact, shop/redact). | To detect restocks so we can send pending notifications, and to comply with data-subject requests. | Processed in memory; not stored beyond what is required to act on the event. |
| Server logs | Minimal request/error logs (timestamps, status codes, error stack traces). We do not log shopper email addresses or the contents of notifications. | To detect abuse, diagnose errors, and keep the service reliable. | Up to 30 days, then rotated/overwritten. |
We do not collect a shopper’s name, address, phone number, or payment information through Stocked, and we do not use the App’s data for advertising, profiling, automated decision-making with legal effects, or training machine-learning models.
3. How a shopper’s email is collected
When a shopper visits a sold-out product on a store that uses Stocked, the store may display a “Notify me when back in stock” form. If the shopper enters their email address and submits the form, the data is sent through the Shopify App Proxy and stored by us so that the App can email the shopper when the merchant restocks the item. The shopper consents to this single, transactional email by submitting the form. We do not send marketing emails through Stocked.
4. Legal bases (EU/UK GDPR)
- Contract — to provide the App to the merchant under our terms of service.
- Legitimate interests — to keep the service reliable, secure, and free of abuse.
- Consent — when a shopper submits their email address to receive a back-in-stock notification.
- Legal obligation — to respond to data-subject requests and comply with applicable laws.
5. Sharing and subprocessors
We do not sell or rent personal information. We share data only with the following service providers (“subprocessors”), and only to the extent necessary to provide the App:
- Shopify Inc. — the platform the App is built on. Authentication, webhooks, and the in-admin interface run through Shopify. See Shopify’s privacy policy.
- A third-party transactional email delivery provider — sends the back-in-stock emails on the merchant’s behalf, from the merchant’s verified sending domain. It processes recipient email addresses solely to deliver the message.
- Amazon Web Services, Inc. — provides the server and storage on which the App runs (AWS Lightsail). See AWS’s privacy notice.
We may also disclose information if required by law, regulation, court order, or to protect the rights, property, or safety of Mage2, our merchants, or others.
6. International data transfers
We operate the App from Australia. Our subprocessors process data in the regions where they operate, which may include the United States, the European Economic Area, and other jurisdictions. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on the recipient’s appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) and on the protections those subprocessors publish in their own privacy notices.
7. Data retention and deletion
We keep personal information only for as long as is necessary for the purposes set out in section 2, then we delete or anonymise it. In particular:
- Shop uninstall. When a merchant uninstalls the App, Shopify sends us a shop/redact webhook 48 hours later. We delete the shop’s data — including its shoppers’ subscription records — within 30 days of receiving that webhook, and we also remove the shop’s sender-domain registration (and its DKIM key) from our email-provider account at the same time.
- Customer redaction. When Shopify sends a customers/redact webhook for a specific shopper, we delete that shopper’s subscription records for the relevant shop within 30 days.
- Customer data request. When Shopify sends a customers/data_request webhook, we record the request and make the personal data we hold about that shopper available to the merchant inside the Stocked admin app, so the merchant can fulfil the request.
8. Security
We protect personal information using industry-standard measures:
- All traffic to and from the App is encrypted with TLS.
- Data is stored on a private server with restricted access.
- Per-shop data is logically isolated and queried by the authenticated shop only.
- Access to production systems is limited to authorised Mage2 personnel and requires strong authentication.
No system is perfectly secure. If we ever become aware of a breach affecting your data, we will notify the merchant and applicable authorities as required by law.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal information, as well as the right to data portability. Residents of California and certain other US states additionally have rights to know what we collect, to delete it, to correct it, and to opt out of any “sale” or “sharing” — we do not sell or share personal information as those terms are defined under California law.
Shoppers: the merchant whose store collected your email is the controller of that data. Please contact the merchant first, or email us at [email protected] and we will forward your request to the merchant and assist them in fulfilling it.
Merchants: contact us at [email protected] to exercise any rights about your own account data, or to issue a data-subject request on a shopper’s behalf.
If you are in the EEA, UK, or Switzerland and believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority.
10. Cookies
Stocked does not set its own tracking or advertising cookies. The embedded admin interface uses session tokens managed by Shopify App Bridge so we can authenticate API calls — this works without third-party cookies.
11. Children
Stocked is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information through the App, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated through the App or by emailing the merchant’s contact on file.
13. Contact us
Mage2
Email: [email protected]
Website: mage2.com.au