Privacy Policy

Stockaro – Shopify App

Deutsch  |  English

This is a translation provided for your convenience. The German version of this privacy policy is the authoritative one; in the event of any discrepancy, the German text prevails. Use the language switch above to read it.

1. Controller and roles

Responsible for these app pages:
Manuel Heithus
Im Mühlengarten 12a
33428 Harsewinkel
Deutschland
Email: info@stockaro.de

Stockaro is a B2B app for Shopify merchants. In WMS operation we process order and inventory data on behalf of the respective merchant (processing under Art. 28 GDPR). The merchant is the controller for their customers' data. For enquiries about end-customer data, please contact the respective merchant.

2. What data we process

  • Shop data: Shopify domain, app access token (transmitted via TLS, stored in the encrypted hosting database at Railway/Postgres), subscription status
  • Order data: order number, customer name (first/last), delivery address (address lines 1+2, postal code, city, country, optionally company), order line items (SKU, title, quantity), order status, optional order note
  • Product data: product and variant titles, SKUs, variant IDs
  • Inventory data: stock quantities, booking history (inbound/outbound), timestamps
  • App log: error and warning messages (SKU and reference ID, no personal reference)
  • Support and feedback data: reply email address entered by the merchant, message type, subject, message, ticket number, technical context (hub route, browser/user agent, language, timestamp, app version) and optionally selected error-log excerpts

Purpose of end-customer data: name for the picking list and packing workflow, delivery address solely for the delivery note.

Not stored from Shopify end-customer data: email addresses, end-customer phone numbers, billing addresses, payment data, credit card information, camera images. Merchant email addresses may be processed for notifications and support replies.

3. Purpose of processing and legal bases

All data is used exclusively for warehouse management (inventory control, order handling, statistics), for operating the app, and for handling the merchant's support and feedback enquiries. There is no use for advertising purposes, no profiling and no cross-merchant analysis.

End-customer data is processed exclusively on behalf of the merchant; the legal basis for it is the responsibility of the merchant as controller (Art. 28 GDPR).

For processing carried out under our own responsibility:

  • Shop data, access token, subscription status — Art. 6(1)(b) GDPR (performance of the usage contract with the merchant)
  • Support and feedback data — Art. 6(1)(b) GDPR (handling the enquiry) and (f) GDPR (improvement and secure operation of the app)
  • App log (error and warning messages) — Art. 6(1)(f) GDPR (operational security and error analysis)

3a. Source of the data

We do not receive end-customer data from the data subject themselves, but from the merchant's order data, which Shopify transmits to the app by webhook (Art. 14 GDPR). The controller for this data is the respective merchant; please address data subject requests to them.

4. Data storage and hosting

Data is stored in a PostgreSQL database at Railway Corp. Hosting of the application and database data takes place in the region EU-West (Amsterdam, Netherlands) within the EU/EEA; no third-country transfer is envisaged for hosting. Railway is SOC 2 Type II certified. Transactional emails and support ticket notifications are processed via Resend, Inc. (USA); this transfer is based on the EU Standard Contractual Clauses (SCC) pursuant to the Resend DPA.

5. Deletion and retention

Deletion is triggered by Shopify's GDPR webhooks; Shopify determines when they are sent, while the deletion itself takes place at our end without undue delay after receipt of the respective webhook.

  • Uninstalling the app: immediate deactivation and token revocation. All shop data is deleted without undue delay after receipt of the shop/redact webhook, which Shopify typically sends around 48 hours after uninstallation.
  • Deletion of individual end-customer data: without undue delay after receipt of the customers/redact webhook. The name and raw record of the affected orders are removed.
  • Support and feedback data: retained for handling and traceability of the enquiry and removed at the latest when the shop is deleted; no separate period applies.
  • Database backups are overwritten in the hosting provider's regular cycle; the longest retention is one month. Only after that are deleted records no longer present there either.

Data export (CSV) available on request.
Enquiries: info@stockaro.de

6. Your rights (GDPR)

  • Access to stored data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17) — by uninstalling or by written request
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) — CSV export available

Contact: info@stockaro.de

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which we base on Art. 6(1)(f) GDPR (support and feedback data, app log). We will then no longer process that data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms (Art. 21(1) GDPR).

You also have the right to lodge a complaint with the competent supervisory authority; for us this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.

7. Cookies

The app sets one strictly necessary session cookie (lagerwms_session) for authentication. No tracking, analytics or marketing cookies are used.

8. Data Processing Agreement (DPA)

A DPA pursuant to Art. 28 GDPR is in place with every merchant: view the Data Processing Agreement. Annexes: Technical and organisational measures · Sub-processors


Last updated: 2026-08-12

Legal notice  |  Terms  |  DPA  |  Help  |  ← Back to the app