StockFirst privacy policy

Last updated: 28 September 2026

This policy explains what data the StockFirst app takes from a Shopify store, why it needs the data, where the data is kept, and when it is deleted. It covers the StockFirst app for Shopify.

Summary

Who we are

StockFirst is made and run by Subtle Marketing.

ItemDetail
Legal nameSubtle Technologies Pvt Limited
Registered addressLahore, Pakistan
CountryPakistan
Websitesubtle-marketing.com
Emailsupport@subtle-marketing.com

In this policy, "we" means Subtle Marketing. "You" means the merchant who installs StockFirst. "The app" means StockFirst.

We decide how the data in this policy is used. Under the GDPR and the UK GDPR, this makes us the controller of that data.

What the app can access in your store

When you install the app, Shopify asks you to approve 4 permissions. The app has no other permission.

PermissionWhat the app does with it
Read productsReads your collections and the products in them
Write productsSets a collection to manual order and changes the position of products in a collection. The app does not change the products themselves
Read inventoryReads stock numbers to find out which products are sold out
Read locationsReads your stock locations, so that you can choose which locations count

The app does not ask for permission to read customers or orders. For the "best selling" order, the app uses the order that Shopify has already worked out. It does not read your orders.

Data the app stores

The app stores the data below in its own database.

DataWhat it containsWhy the app needs it
Store addressThe store's myshopify.com domainTo know which store the data belongs to
Access tokensThe access token and refresh token from Shopify, their expiry dates and the list of approved permissionsTo read and sort your collections through Shopify
Plan and statusYour plan, the install date, the uninstall date, whether setup is finished and whether sorting is pausedTo apply the limits of your plan and to stop sorting when you pause or uninstall
Time zoneThe store's time zoneTo run the daily sort at the time you chose and to show times correctly
SettingsYour sold-out rule, the tags of products to leave in place, the chosen stock locations (Shopify identifiers), the base order, the restock option, the place for new products and the sort scheduleTo sort the way you chose
Notification email addressOne email address. At the start, the app copies the contact email of your store from Shopify. You can change it in SettingsTo send you the emails you turned on
Email settingsWhich emails are on, and when the app last sent each kind of emailTo send only the emails you want and to avoid repeated emails
Collection listFor each collection: Shopify identifier, title, handle, sort setting and number of productsTo show your collections in the app without delay
Collection rulesFor each collection you set up: Shopify identifier, title, handle, whether sorting is on, your rule for this collection, the identifiers of pinned products, the number of products and sold-out products, and the time and result of the last sortTo sort each collection by its own rule and to show its status
Original orderThe sort setting and the product order (product identifiers) from before the first sortTo restore the original order when you ask for it
Sort stateThe product identifiers in the base order and the identifiers of the products that were sold out at the last sortTo return a product to its previous position when it is back in stock
Storefront check resultThe result, the time and a short note. The note can contain the titles of 2 productsTo warn you when your storefront shows a different order
Sort historyFor each sort: collection identifier and title, what started the sort, the result, the number of products moved, up to 25 products that moved (identifier, title, old and new position), the product order before the sort (product identifiers), the error message and the start and end timeTo show the Activity page and to restore an earlier order
Background job recordsThe store address and the identifier of a collection rule, a product or an inventory itemTo run sorts and checks in the background
Server logThe store address and the name of each app or privacy notification that Shopify sends, and error messagesTo find and fix errors

If you write to our support address, we also receive your email address and your message. We use them to answer you.

Data the app reads but does not store

To work out the order of a collection, the app reads more product data from Shopify. It uses this data during the sort and does not save it.

Shopify also sends the app a notification when a product, a stock level or a collection changes. The app uses only the identifier in the notification. It does not save the rest.

Data the app does not collect

The app has no analytics tools and no advertising tools.

The storefront check

After a sort, the app checks that your storefront shows the new order. To do this, the app opens the public page of the collection in your online store, the same page any visitor can open. The app does not log in and does not send cookies.

The app reads only the product links on that page and compares their order with the order it set. The app does not save the page. It saves only the result and a short note.

If your store is password protected, the app cannot read the page. The app then shows "Could not check".

Emails the app sends

The app sends 3 kinds of email to your notification email address. You can turn each one on or off in Settings.

EmailDefaultWhat it contains
A sort failedOnThe collection title and the reason
The storefront shows a different orderOnThe collection title and a short note. The note can contain the titles of 2 products
Weekly summaryOffThe number of sorts, of products moved, of sorted collections and of failed sorts

Each email has a link to the app in your Shopify admin. The link contains the name of your store.

You can change or remove the email address in Settings. When the field is empty, the app sends no emails and stores no address.

Who processes the data

We use the companies below to run the app. They get only the data they need for their task.

CompanyTaskData
ShopifyThe platform the app runs in. Shopify handles the install, the login and the billingYour store's data is in Shopify already. The app reads it from Shopify and writes the collection order back
HostingerHosts the server (VPS) with the app and its database. Server location: Germany (Frankfurt)All data in the section "Data the app stores"
ResendSends the emailsYour notification email address and the subject and text of each email

Resend is a company in the United States. Shopify works in several countries. This means your data can be processed outside your country.

We do not sell your data. We do not share it for advertising. We give data to an authority only when the law requires it.

How long the app keeps data

DataHow long
Sort history90 days. The app deletes older records by itself, every 10 minutes
Scheduled and automatic sorts that moved nothingNot kept. The app deletes the record at once
Access tokensUntil you uninstall. The app deletes them when Shopify reports the uninstall
Settings, notification email address, collection list, collection rules, original order, sort state and sort historyWhile the app is installed, and after the uninstall until Shopify sends the deletion request. Then the app deletes them
Data about a collection that you delete in ShopifyThe app deletes the collection and its rule when Shopify reports it. Sort history of that collection stays for up to 90 days
Background job recordsThe job queue deletes them by itself, within about 3 weeks. The deletion request removes the records of your store at once
Database backups30 days
Server logUntil the log reaches 50 MB for each service. Older lines are then deleted
Emails you send to supportAs long as we need them to help you. You can ask us to delete them

What happens when you uninstall

  1. Shopify tells the app that you uninstalled it. The app deletes your access tokens at once and turns sorting off for all collections.
  2. Your collections stay in the order of the last sort. The app can no longer change them.
  3. The app keeps your settings, rules and history for a short time. If you install the app again in this time, they are still there.
  4. 48 hours after the uninstall, Shopify sends the app a deletion request (shop/redact). The app then deletes the record of your store and everything linked to it: settings, notification email address, collection list, collection rules, original order, sort state, sort history and any access tokens that remain.

The deletion request does not remove your data from database backups or from the server log. These are deleted after the periods in the table above.

Shopify's privacy requests

Shopify requires every app to answer 3 privacy requests. The app checks that each request really comes from Shopify before it acts.

RequestWhen Shopify sends itWhat the app does
customers/data_requestA customer asks a store for their dataConfirms the request. The app holds no customer data, so there is nothing to give
customers/redactA store asks to delete the data of a customerConfirms the request. The app holds no customer data, so there is nothing to delete
shop/redact48 hours after a store uninstalls the appDeletes the store's data, as described above

Your rights

If you are in the European Union or the United Kingdom

Under the GDPR and the UK GDPR you can:

We use your data on these legal grounds:

UseLegal ground
Running the app for your store and sending the emails you turned onTo carry out our contract with you
Server log, backups and securityOur legitimate interest in a safe and working service
Answering a request from an authorityA legal duty

If you are in California

Under the CCPA you can ask what personal information we hold about you, ask us to correct it and ask us to delete it. We do not sell your personal information and we do not share it for advertising. We do not treat you differently when you use these rights.

How to use your rights

We answer within 30 days.

Your customers

The app holds no data about your customers. If a customer asks you for their data or asks you to delete it, the app has nothing to give and nothing to delete.

How we protect the data

No system is fully safe. We cannot promise that data is never lost or seen by someone without permission. If a data breach affects your personal data, we tell you and the authorities as the law requires.

Changes to this policy

We can change this policy, for example when the app gets a new feature. We publish the new text on this page and change the date at the top. If a change is important, we also tell you by email or in the app before it applies.

Contact

For questions about this policy or about your data, write to support@subtle-marketing.com.

Subtle Marketing, Subtle Technologies Pvt Limited, Lahore, Pakistan, Pakistan