privacy policy

Privacy policy

Last updated 31 August 2026 · applies to the Stockkeep Shopify app and to stockkeep.app

The short version.

  • Stockkeep never asks Shopify for access to your customers, orders, payments or checkout, so it cannot read them.
  • This website loads no analytics, no third-party fonts and no advertising, and sets no cookies.
  • Uninstalling deletes your data. Not anonymises it — deletes it.

Who we are, and who is responsible

Stockkeep is built and operated by Jaroslav Bílek, a sole trader (osoba samostatně výdělečně činná) registered in the Czech Republic, trading as Stockroom Labs.

  • Place of business: Italská 615/7, Vinohrady, 120 00 Praha 2, Czech Republic
  • Company identification number (IČO): 24436780
  • Registered in the Czech Trade Licensing Register (živnostenský rejstřík), kept by the municipal trade licensing office at that address.
  • Contact: support@stockkeep.app

That person is the data controller for the purposes described below. For anything in this policy, including a request to see or delete your data, use the address above.

Which hat we are wearing

Two different relationships are covered by this policy, and the law treats them differently.

  • Your store’s data — we are a processor. Products, inventory, costs, suppliers, purchase orders and stocktakes belong to you, the merchant. You decide why they are processed; we only act on your instructions, given through the app. If one of your own staff or suppliers asks to exercise a data-protection right over that data, the request belongs to you as controller, and we will help you answer it.
  • The installer’s name and email, and the form on this website — we are the controller. Those we hold for our own purpose, which is running and supporting the app.

Why we are allowed to hold it

  • Performance of a contract (GDPR Article 6(1)(b)) — everything needed to provide the app to the shop that installed it, including the access token, your app records and the installer’s contact details.
  • Consent (Article 6(1)(a)) — the install-request form on this website. You typed your address in to ask us something; withdraw it at any time and it is deleted.
  • Legitimate interests (Article 6(1)(f)) — keeping the service secure and working, which is why refused cross-shop attempts and application errors are recorded. We have weighed this against your interests and it is limited to operational records, never profiling.

What the app reads from your store

Stockkeep requests four Shopify access scopes and no others. They are shown to you on the install screen before you grant anything.

  • read_productsProducts and variants: title, SKU, barcode, price, weight. Used to build purchase-order lines, print barcode labels and price the stock you count.
  • read_locationsYour locations, so a purchase order or stocktake can be attached to one.
  • read_inventoryOn-hand quantity and unit cost per variant per location. This is the figure Stockkeep re-averages when you receive a delivery.
  • write_inventoryAdjusting inventory quantities and unit cost. If a product you are receiving or counting is not yet stocked at that location, Stockkeep also tells Shopify to stock it there, because otherwise the quantity has nowhere to land. Those are the only three things it writes, and only ever when you receive a purchase order or post a stocktake — never on a schedule, never in the background.

Customer records, orders, payments, checkout, discounts, marketing and staff accounts are not in that list, which means Shopify will not serve them to Stockkeep even if it asked.

What is stored on our server

  • Your shop domain and the Shopify access token that lets the app act on your behalf.
  • Suppliers you enter, including any supplier contact email you choose to type in.
  • Purchase orders and their line items, including costs, freight and receiving history.
  • Stocktakes and the counts recorded against them.
  • One inventory snapshot per location per day: variant, quantity, unit cost.
  • A log of cost changes, so a cost can be traced back to the delivery that caused it.
  • Your settings, such as whether you cost by weighted average or last cost.
  • The date the daily snapshot last ran for each of your locations, so it runs once a day and not twice.
  • Where Shopify includes it with the session, the name and email address of the store owner or staff member who installed the app.

Personal data, specifically

The only personal data Stockkeep holds is the name and email of the person who installed it, and any supplier contact details you enter yourself. No data about your customers passes through the app at any point. Nothing is used for profiling, advertising, or training any model.

The install request form on this site

The form on the front page sends two things: your email address, and optionally your Shopify store name. They are stored on the same server described below and emailed to us as a notification, so that we can reply to you. That is the whole purpose — there is no mailing list, no sequence, and the address is never passed to anyone else or used to advertise to you. Ask and it is deleted.

How long it is kept

  • Store data and the access token — for as long as the app is installed, then deleted as described under Deletion below. Shopify’s API Terms require every copy to be gone within 30 days of uninstall, and ours are gone within 48 hours.
  • Install-request emails from the form on this site — kept until we have answered you and for no more than 12 months after that, then deleted.
  • Operational records (application errors, refused cross-shop attempts) — kept no longer than 90 days. They never contain access tokens.
  • Backups — we keep no scheduled backups of the application database. If a copy is ever taken to move or repair the server, it is deleted as soon as that work is finished and never outlives the data it came from.

Where it is stored

On a single server in Helsinki, Finland, rented from Hetzner Online GmbH. Traffic to it is encrypted with TLS. The database file is readable only by the application account on that machine.

Who else touches it

  • ShopifyThe platform the app runs inside. Shopify's own privacy terms cover your store data.
  • HetznerHosting, in Finland. They hold the disk, not the keys to your Shopify account.

That is the complete list. There is no analytics provider, no error-tracking service, no email marketing platform, no advertising network and no AI provider in the path.

Logs

The web server keeps no access log, so your IP address is not recorded when you browse this site or use the app. The application writes operational records only: an error if something fails, and a line if a request tries to reach another shop’s records so that we can see it was refused. Shopify access tokens are never written to any log, and that is enforced by an automated test.

Transfers outside Europe

None. The server is in Finland and the data stays there. Hetzner processes it only as our hosting provider, under their data processing agreement and the GDPR, and has no right to use it for anything else. Shopify holds your store data under its own terms with you, which is a separate relationship from this one.

Cookies

Stockkeep sets no cookies. It authenticates every request with a short-lived session token handed to it by the Shopify admin, so there is nothing to store on your machine — the running app returns no Set-Cookie header on any route. The Shopify admin page around the app sets its own cookies; those are Shopify's, under Shopify's terms, and Stockkeep cannot read them. This website — the pages you are reading now — sets no cookies either, and makes no requests to any other domain, including for its fonts.

Deletion

Three things happen, without you having to ask:

  • When you uninstall, Shopify notifies the app and the access token and session are deleted at once. The app can no longer reach your store from that moment.
  • Shopify then sends a shop-redact request 48 hours later. On receiving it, Stockkeep deletes your suppliers, purchase orders, line items, stocktakes, counts, inventory snapshots, cost-change history, snapshot timestamps and settings for that shop.
  • Shopify's customer data-request and customer-redact notifications are answered with the fact that no customer data is held, because none is.

You can also ask for deletion at any time, installed or not, at support@stockkeep.app.

Your rights

Under the GDPR you may ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask for it in a portable format, object to how it is handled, or withdraw consent where that is what we relied on. Write to support@stockkeep.app and you will get an answer without undue delay and within one month, which the law lets us extend by two further months for a complicated request — we will tell you if that happens.

Where we hold something as your processor rather than as controller — your store’s products, costs, suppliers and counts — send the request to the merchant who owns that store, and we will help them answer it.

You may also complain to a supervisory authority: yours where you live or work, or ours, the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů, uoou.cz).

Security

  • Every database query is scoped to the shop that made the request. The app carries automated tests that fail the build if a route can be made to read another shop's records, and any attempt to reach across shops is refused and logged.
  • Shopify access tokens are never written to logs. That is enforced by a test, not by a convention.
  • Webhooks from Shopify are rejected unless their signature verifies.
  • The database file holding access tokens is not readable by other accounts on the server.

If you need a data processing agreement

Because we process your store’s data on your behalf, Article 28 of the GDPR expects a written agreement between us. This policy sets out the subject matter, duration, nature and purpose of the processing, the kinds of data and the obligations above, and installing the app accepts it as those terms. If your own compliance process needs a separate signed document, ask at support@stockkeep.app and you will get one.

Children

Stockkeep is a tool for running a business and is not directed at children. We do not knowingly hold data about anyone under 16.

Changes to this policy

If this policy changes, the date at the top changes with it. Material changes affecting installed shops will be sent by email to the address on the install.