Privacy Policy

Last updated: August 28, 2026

Replenly ("the app", "we", "us") is a Shopify app that helps merchants manage replenishment, purchase orders, receiving, ingredients, and physical stocktakes. It is operated by an individual developer. This policy explains what data the app processes, why, and how it's protected.

What data we process

When a merchant installs Replenly, we process:

We do not deliberately collect, store, or retain your customers' names, emails, phone numbers, shipping/billing addresses, or payment details. Shopify webhook and API payloads can contain customer fields. We may transiently receive and process those payloads to authenticate and handle the Shopify request, but Replenly does not extract or persist those customer fields in its operational records. The order and order-line identifiers we retain exist only to compute how quickly a product sells and to deduplicate repeated webhook deliveries; they are never linked to who bought the item.

Why we process it

Every piece of data listed above is used to operate the app's replenishment, reorder suggestions, purchase-order, ingredient, and stocktake workflows. We do not use your data for advertising, we do not sell it or share it for advertising or independent commercial purposes, and we do not build profiles of your shoppers. We disclose data to service providers acting on our behalf as described below.

Storage and security

Data is stored in a managed PostgreSQL database. It's encrypted in transit (TLS) and at rest, and access is restricted to the systems that run the app. We don't grant broad third-party access to your shop data.

Service providers

We rely on Shopify for the platform integration and on a small number of infrastructure and delivery providers to run the app. The infrastructure and delivery providers act on our behalf and are bound by their own security and confidentiality obligations:

None of these providers is given access to your data beyond what's necessary for the purposes described above. Sentry is limited to the diagnostic telemetry described above, is not initialized on the public marketing, terms, or privacy pages, and is not used to process your shop records.

Data retention

Backups

We keep off-site database backups for disaster recovery and target pruning them after 30 days. Automated pruning runs nightly; if a provider or configuration failure prevents cleanup, older copies may remain until pruning succeeds and the failure is recorded for operator follow-up. Because of this, data you delete - including data removed by an uninstall or a redaction request - may persist in a backup beyond that target period. The supported restore process keeps deletion/redaction state separately from ordinary backups and reapplies that state after restoring, which is designed to prevent a restored backup from reactivating data that was already deleted or redacted. This protection depends on the deletion state having been durably recorded and on the supported restore process being used.

Shopify GDPR compliance webhooks

Replenly implements Shopify's three mandatory webhooks:

Billing

Subscription billing is handled entirely by Shopify's billing system. We never see or store your payment card details.

Changes to this policy

If this policy changes, we'll update the date at the top of this page. Continued use of the app after a change means you accept the updated policy.

Questions or a deletion request?

Email vkundar@gmail.com.