StockFirst privacy policy
Last updated: 28 September 2026
This policy explains what data the StockFirst app takes from a Shopify store, why it needs the data, where the data is kept, and when it is deleted. It covers the StockFirst app for Shopify.
Summary
- StockFirst reads products, collections, stock and stock locations. It uses them to sort your collections.
- StockFirst does not read customers or orders. It has no permission to do so.
- StockFirst never sees payment details. Shopify handles all billing.
- We do not sell your data and we do not use it for advertising.
- After you uninstall, the app deletes your store's data when Shopify sends the deletion request. Shopify sends it 48 hours after the uninstall.
Who we are
StockFirst is made and run by Subtle Marketing.
| Item | Detail |
|---|---|
| Legal name | Subtle Technologies Pvt Limited |
| Registered address | Lahore, Pakistan |
| Country | Pakistan |
| Website | subtle-marketing.com |
| support@subtle-marketing.com |
In this policy, "we" means Subtle Marketing. "You" means the merchant who installs StockFirst. "The app" means StockFirst.
We decide how the data in this policy is used. Under the GDPR and the UK GDPR, this makes us the controller of that data.
What the app can access in your store
When you install the app, Shopify asks you to approve 4 permissions. The app has no other permission.
| Permission | What the app does with it |
|---|---|
| Read products | Reads your collections and the products in them |
| Write products | Sets a collection to manual order and changes the position of products in a collection. The app does not change the products themselves |
| Read inventory | Reads stock numbers to find out which products are sold out |
| Read locations | Reads your stock locations, so that you can choose which locations count |
The app does not ask for permission to read customers or orders. For the "best selling" order, the app uses the order that Shopify has already worked out. It does not read your orders.
Data the app stores
The app stores the data below in its own database.
| Data | What it contains | Why the app needs it |
|---|---|---|
| Store address | The store's myshopify.com domain | To know which store the data belongs to |
| Access tokens | The access token and refresh token from Shopify, their expiry dates and the list of approved permissions | To read and sort your collections through Shopify |
| Plan and status | Your plan, the install date, the uninstall date, whether setup is finished and whether sorting is paused | To apply the limits of your plan and to stop sorting when you pause or uninstall |
| Time zone | The store's time zone | To run the daily sort at the time you chose and to show times correctly |
| Settings | Your sold-out rule, the tags of products to leave in place, the chosen stock locations (Shopify identifiers), the base order, the restock option, the place for new products and the sort schedule | To sort the way you chose |
| Notification email address | One email address. At the start, the app copies the contact email of your store from Shopify. You can change it in Settings | To send you the emails you turned on |
| Email settings | Which emails are on, and when the app last sent each kind of email | To send only the emails you want and to avoid repeated emails |
| Collection list | For each collection: Shopify identifier, title, handle, sort setting and number of products | To show your collections in the app without delay |
| Collection rules | For each collection you set up: Shopify identifier, title, handle, whether sorting is on, your rule for this collection, the identifiers of pinned products, the number of products and sold-out products, and the time and result of the last sort | To sort each collection by its own rule and to show its status |
| Original order | The sort setting and the product order (product identifiers) from before the first sort | To restore the original order when you ask for it |
| Sort state | The product identifiers in the base order and the identifiers of the products that were sold out at the last sort | To return a product to its previous position when it is back in stock |
| Storefront check result | The result, the time and a short note. The note can contain the titles of 2 products | To warn you when your storefront shows a different order |
| Sort history | For each sort: collection identifier and title, what started the sort, the result, the number of products moved, up to 25 products that moved (identifier, title, old and new position), the product order before the sort (product identifiers), the error message and the start and end time | To show the Activity page and to restore an earlier order |
| Background job records | The store address and the identifier of a collection rule, a product or an inventory item | To run sorts and checks in the background |
| Server log | The store address and the name of each app or privacy notification that Shopify sends, and error messages | To find and fix errors |
If you write to our support address, we also receive your email address and your message. We use them to answer you.
Data the app reads but does not store
To work out the order of a collection, the app reads more product data from Shopify. It uses this data during the sort and does not save it.
- Product tags, creation date and lowest price
- Stock numbers, and whether a variant is tracked or keeps selling when out of stock
- Names of your stock locations
- Product handles
Shopify also sends the app a notification when a product, a stock level or a collection changes. The app uses only the identifier in the notification. It does not save the rest.
Data the app does not collect
- Customer data: no names, emails, addresses or phone numbers of your customers
- Orders
- Payment details
- Data about shoppers who visit your storefront. The app adds no code to your storefront
- Names and email addresses of your staff. The database has fields for them, but the app uses store-level access only, so these fields stay empty
The app has no analytics tools and no advertising tools.
The storefront check
After a sort, the app checks that your storefront shows the new order. To do this, the app opens the public page of the collection in your online store, the same page any visitor can open. The app does not log in and does not send cookies.
The app reads only the product links on that page and compares their order with the order it set. The app does not save the page. It saves only the result and a short note.
If your store is password protected, the app cannot read the page. The app then shows "Could not check".
Emails the app sends
The app sends 3 kinds of email to your notification email address. You can turn each one on or off in Settings.
| Default | What it contains | |
|---|---|---|
| A sort failed | On | The collection title and the reason |
| The storefront shows a different order | On | The collection title and a short note. The note can contain the titles of 2 products |
| Weekly summary | Off | The number of sorts, of products moved, of sorted collections and of failed sorts |
Each email has a link to the app in your Shopify admin. The link contains the name of your store.
You can change or remove the email address in Settings. When the field is empty, the app sends no emails and stores no address.
Who processes the data
We use the companies below to run the app. They get only the data they need for their task.
| Company | Task | Data |
|---|---|---|
| Shopify | The platform the app runs in. Shopify handles the install, the login and the billing | Your store's data is in Shopify already. The app reads it from Shopify and writes the collection order back |
| Hostinger | Hosts the server (VPS) with the app and its database. Server location: Germany (Frankfurt) | All data in the section "Data the app stores" |
| Resend | Sends the emails | Your notification email address and the subject and text of each email |
Resend is a company in the United States. Shopify works in several countries. This means your data can be processed outside your country.
We do not sell your data. We do not share it for advertising. We give data to an authority only when the law requires it.
How long the app keeps data
| Data | How long |
|---|---|
| Sort history | 90 days. The app deletes older records by itself, every 10 minutes |
| Scheduled and automatic sorts that moved nothing | Not kept. The app deletes the record at once |
| Access tokens | Until you uninstall. The app deletes them when Shopify reports the uninstall |
| Settings, notification email address, collection list, collection rules, original order, sort state and sort history | While the app is installed, and after the uninstall until Shopify sends the deletion request. Then the app deletes them |
| Data about a collection that you delete in Shopify | The app deletes the collection and its rule when Shopify reports it. Sort history of that collection stays for up to 90 days |
| Background job records | The job queue deletes them by itself, within about 3 weeks. The deletion request removes the records of your store at once |
| Database backups | 30 days |
| Server log | Until the log reaches 50 MB for each service. Older lines are then deleted |
| Emails you send to support | As long as we need them to help you. You can ask us to delete them |
What happens when you uninstall
- Shopify tells the app that you uninstalled it. The app deletes your access tokens at once and turns sorting off for all collections.
- Your collections stay in the order of the last sort. The app can no longer change them.
- The app keeps your settings, rules and history for a short time. If you install the app again in this time, they are still there.
- 48 hours after the uninstall, Shopify sends the app a deletion request (shop/redact). The app then deletes the record of your store and everything linked to it: settings, notification email address, collection list, collection rules, original order, sort state, sort history and any access tokens that remain.
The deletion request does not remove your data from database backups or from the server log. These are deleted after the periods in the table above.
Shopify's privacy requests
Shopify requires every app to answer 3 privacy requests. The app checks that each request really comes from Shopify before it acts.
| Request | When Shopify sends it | What the app does |
|---|---|---|
| customers/data_request | A customer asks a store for their data | Confirms the request. The app holds no customer data, so there is nothing to give |
| customers/redact | A store asks to delete the data of a customer | Confirms the request. The app holds no customer data, so there is nothing to delete |
| shop/redact | 48 hours after a store uninstalls the app | Deletes the store's data, as described above |
Your rights
If you are in the European Union or the United Kingdom
Under the GDPR and the UK GDPR you can:
- ask for a copy of your personal data
- ask us to correct it
- ask us to delete it
- ask us to limit how we use it
- object to how we use it
- ask for your data in a format that another service can read
- complain to the data protection authority in your country. In the United Kingdom, this is the Information Commissioner's Office (ICO)
We use your data on these legal grounds:
| Use | Legal ground |
|---|---|
| Running the app for your store and sending the emails you turned on | To carry out our contract with you |
| Server log, backups and security | Our legitimate interest in a safe and working service |
| Answering a request from an authority | A legal duty |
If you are in California
Under the CCPA you can ask what personal information we hold about you, ask us to correct it and ask us to delete it. We do not sell your personal information and we do not share it for advertising. We do not treat you differently when you use these rights.
How to use your rights
- Change your settings and your notification email address in the app, on the Settings page.
- To delete your store's data, uninstall the app. The section "What happens when you uninstall" explains the steps.
- For every other request, write to support@subtle-marketing.com. Include the address of your store. We can ask you to show that you own the store.
We answer within 30 days.
Your customers
The app holds no data about your customers. If a customer asks you for their data or asks you to delete it, the app has nothing to give and nothing to delete.
How we protect the data
- The app is reached over HTTPS only. The web server gets and renews the certificate by itself.
- The app checks the signature of every notification from Shopify and rejects a notification with a wrong signature.
- Every page of the app checks the Shopify login before it shows or changes data.
- The database cannot be reached from the internet. Only the app on the same server can connect to it.
- The firewall of the server opens only the ports for the web server and for server administration.
- The app asks for the smallest set of permissions it needs.
- The access tokens from Shopify expire and are renewed. The app deletes them when you uninstall.
- Passwords and keys are kept in a settings file on the server, not in the code.
No system is fully safe. We cannot promise that data is never lost or seen by someone without permission. If a data breach affects your personal data, we tell you and the authorities as the law requires.
Changes to this policy
We can change this policy, for example when the app gets a new feature. We publish the new text on this page and change the date at the top. If a change is important, we also tell you by email or in the app before it applies.
Contact
For questions about this policy or about your data, write to support@subtle-marketing.com.
Subtle Marketing, Subtle Technologies Pvt Limited, Lahore, Pakistan, Pakistan