Legal
Privacy Policy
StockSightAI (“StockSightAI”, “we”, “us”) is operated by AiShopUp. This Privacy Policy explains how we collect, use, store, and delete information when merchants install and use our Shopify app at stocksight.aishopup.com.
We design StockSightAI as a read-only inventory forecasting and purchase-order drafting tool. We do not sell merchant data.
1. Who this policy covers
This policy applies to Shopify merchants (and their staff) who install StockSightAI, and to visitors of our public website. End customers of those merchants are generally not our direct users; we process limited order-line data only as needed for demand forecasting (see below).
2. Data we process
2.1 From Shopify (via OAuth)
After you install the app, Shopify grants access using OAuth. Our requested scopes are:
read_productsread_ordersread_inventory
We do not request write scopes (including write_inventory). We never change stock levels in Shopify through the app.
- Shop identity — shop domain, installation status, timezone/currency as provided by Shopify, subscription / plan status.
- Catalog & inventory — products, variants, SKUs, titles, and inventory quantities needed for reorder logic.
- Orders (demand history) — order identifiers, dates, and line-item quantities / prices used to forecast demand. We do not use order data for advertising to your customers, and we do not request customer email/phone as a core product feature.
- Offline access token — stored securely so the app can sync data and run nightly jobs while you are not in Admin.
2.2 App-generated data
- Forecasts, reorder points, and urgency classifications
- Purchase-order drafts you create in StockSightAI
- Supplier lead-time estimates derived from PO sent/received dates
- Alert preferences and delivery logs for digests you enable
2.3 Information you provide
- Digest contacts — email (and optional SMS/WhatsApp numbers if you enable those channels) for stock alerts
- Support emails — if you contact [email protected]
2.4 Website visitors
Our public site may receive standard server/CDN logs (IP address, user agent, pages requested) for security and reliability. We do not run advertising pixels on the StockSightAI landing page as part of the core product.
3. How we use data
- Provide forecasting, reorder recommendations, and PO drafts
- Run backfills, nightly forecasts, and inventory snapshots
- Send digests/alerts you configure
- Bill through Shopify App Billing / Managed Pricing
- Secure the service, prevent abuse, and meet legal obligations
- Respond to support requests
We do not sell personal or shop data. We do not use Shopify data to build advertising profiles about your store’s customers.
4. Legal bases (where applicable)
Depending on your location, we process data to perform our contract with you (providing the app), for legitimate interests (security, product improvement in aggregate form), and where required to comply with law (including Shopify’s mandatory compliance webhooks).
5. Processors & subprocessors
We use trusted providers solely to operate the app. Categories include:
- Hosting / infrastructure — cloud VPS and TLS termination for
stocksight.aishopup.com - Database — Postgres for app and shop data
- Email delivery — transactional SMTP (e.g. Brevo) for digests you enable
- Optional SMS / WhatsApp — only if you configure Twilio (or similar) credentials; otherwise unused
- Shopify — platform that authenticates installs and provides Admin API data
Processors act on our instructions and are not permitted to use your shop data for their own marketing.
6. International transfers
Servers may be located outside your country (including regions such as Singapore / EU / US depending on deployment). Where required, we use appropriate safeguards for cross-border transfers.
7. Retention & deletion
- While installed — we retain data needed to run forecasts, POs, and alerts.
- On uninstall — we mark the shop inactive, cancel pending jobs, and delete OAuth sessions. Shopify may later send
shop/redact, after which we delete the shop record and cascaded business data. - Customer data requests / redaction — we honor Shopify mandatory webhooks (
customers/data_request,customers/redact,shop/redact). Because we primarily store demand quantities rather than customer contact PII, many customer requests result in confirmation that no customer contact PII is retained. - Backups — encrypted/operational backups may persist for a limited window, then expire per our backup retention settings.
8. Security
We transmit data over HTTPS/TLS, restrict server access, and store session tokens in our database for offline Admin API access. No method of transmission or storage is 100% secure; please contact us if you suspect unauthorized access.
9. Your choices & rights
- Uninstall StockSightAI from Shopify Admin at any time
- Update or clear digest email/SMS settings in the app
- Contact us to ask what shop data we hold, or to request deletion where applicable
If you are in the EEA/UK or similar jurisdictions, you may have rights to access, rectification, erasure, restriction, and objection. Contact [email protected]. You may also have the right to lodge a complaint with a supervisory authority.
10. Children
StockSightAI is a B2B Shopify merchant tool and is not directed to children under 16.
11. Changes
We may update this policy. The “Last updated” date will change when we do. Material changes may also be noted in the app or by email to the merchant contact on file.
12. Contact
AiShopUp — StockSightAI
Email: [email protected]
Web: stocksight.aishopup.com