Privacy policy
Last updated: 24 August 2026
This policy describes how Scorestock (“we”) processes data when a merchant installs the Scorestock Shopify app. It is written for Shopify App Store review and for merchants. It is not legal advice.
Who we are
Scorestock is a Shopify app hosted at https://scorestock.fly.dev. Support contact is the email address shown on the Scorestock listing in the Shopify App Store.
What we collect
When a merchant installs Scorestock we process:
- Shop domain and Shopify offline session token (OAuth).
- Collection and product fields needed to sort sold-out products: collection IDs and titles, product IDs, inventory tracking, on-hand quantity, and inventory policy (deny / continue selling).
- App settings for that shop: whether auto-sort is on, and the last sort time and result summary.
- Merchant staff name and email only if Shopify includes them in the admin session. That is store staff, not store customers.
What we do not collect
Scorestock does not request Shopify customer or order scopes. We do not store shopper names, emails, phone numbers, addresses, payment details, or Shopify customer IDs.
Why we process this data
- Move sold-out products to the bottom of manual collections, and keep in-stock products in their relative order.
- Re-sort collections when inventory changes, if the merchant is on Pro and leaves auto-sort on.
- Operate and secure the app (authentication, uninstall).
Where data is stored
App data is stored on Fly.io (Amsterdam) in a database we operate. Authentication runs through Shopify. We do not sell merchant or shopper data.
Retention and deletion
We keep shop data while the app is installed. When the merchant uninstalls, we delete sessions and shop settings. Shopify also sends a shop/redact webhook about 48 hours after uninstall; we delete any remaining shop data then. Customer data request and customer redaction webhooks are implemented; because we do not store customer records, there is nothing to export or erase for a shopper.
Your rights
Merchants and their customers can use Shopify’s privacy tools (including GDPR/CPRA flows). Those requests reach Scorestock through Shopify’s mandatory compliance webhooks. Merchants can also uninstall the app to stop processing and trigger deletion.
Contact
Privacy questions: use the support email on the Scorestock Shopify App Store listing, or open the app from Shopify Admin → Apps → Scorestock.