Privacy Policy — Incoming Stock Digest

Last updated: October 7, 2026

Incoming Stock Digest ("we", "us", "our") is a Shopify application built by Metigro that sends merchants a scheduled email report of inventory currently in transit to their locations. This policy explains what data the app accesses, what it stores, and how long it keeps it.

This app is installed and configured entirely by the Merchant. It has no storefront component and no interaction with the Merchant's customers or checkout.

Information we collect

Store and inventory data (from Shopify). Using the access scopes granted at install (read_products, read_inventory, read_locations), the app reads product and variant titles, SKUs, Shopify product/variant IDs, location names, and incoming inventory quantities per product variant and location. Only positions with a non-zero incoming quantity are stored. We do not read or store order data, customer data, checkout data, or payment information, and the app requests no scope that would grant access to them.

Recipient list. The Merchant configures a list of email addresses to receive the digest (for example, purchasing staff or suppliers). These are entered directly by the Merchant in the app's settings screen. The first recipient is pre-filled with the store owner's account email at install.

Automatically collected data. Standard web server logs (IP address, timestamps, request paths) are kept briefly for security and abuse prevention.

What we do not collect

We do not store data about the Merchant's customers. The app has no code path that reads customer records, and no customer-facing surface. If a recipient email happens to match a customer's email, that address is still treated purely as a mailing-list entry configured by the Merchant, not as customer data.

How we use information

We do not sell, rent, or use this data for advertising, and we do not share it with third parties except the subprocessors below.

Subprocessors

Data retention

Inventory snapshots: 21 days on the Free plan, 180 days on Pro, then deleted by a daily cleanup job. The two most recent completed snapshots are always kept, since the next digest is computed from them.

Recipient list: kept while the app is installed, until the Merchant removes an address, or a non-Shopify recipient unsubscribes via the link in the email footer (marked unsubscribed, not deleted).

Data security

Your rights / GDPR compliance

We implement Shopify's mandatory compliance webhooks. shop/redact (sent after uninstall) erases the store's recipient list and inventory snapshots. customers/data_request and customers/redact return an acknowledgement with no records, since we do not store customer data — a recipient address that happens to coincide with a customer's email is a Merchant setting, not customer data, and is not touched by customers/redact.

Merchants can add or remove recipients, or uninstall the app, at any time. Metigro acts as a data processor on behalf of the Merchant (the data controller) for any personal data configured in the app.

Children's privacy

This app is a business tool for Shopify merchants and is not directed at, or knowingly used to collect data from, individuals under 16.

Changes to this policy

We may update this policy from time to time. The date above reflects the most recent revision.

Contact us

Questions about this policy or a data request: [email protected]