Privacy policy
Last updated 17 September 2026. Applies to the Reshelf app for Shopify, made by Scorptek LLC.
Who this covers
Merchants who install the app on their Shopify store, and shoppers who ask to be notified when a product is back in stock. Merchants are the data controllers for their shoppers’ data; Scorptek LLC processes it on their behalf.
What we collect and why
| Data | From | Why |
|---|---|---|
| Shopper email address (stored encrypted), the product and variant they asked about, the time, and whether they ticked the newsletter box | The “Notify me” form | To send the alert they asked for and let the merchant see demand |
| Delivery events for each alert email or text: sent, delivered, delayed, bounced, complained, failed | Our email and SMS providers | To show merchants whether alerts arrived and to stop contacting addresses and numbers that bounce, complain or opt out |
| Shopper mobile number (stored encrypted), the time they ticked the SMS consent box, and any STOP reply | The “Notify me” form, and replies to our texts | To send the one text they asked for, and to honour opt-outs. Only collected when the merchant turns the phone field on. |
| The price a shopper saw when asking for a price-drop alert | The “Notify me” form | To know when the price has dropped below it |
| Order number, order total, currency and the item bought | Shopify order webhooks | To attribute a purchase to an alert (within 14 days) so merchants can see recovered revenue. We don’t receive the buyer’s name, address or payment details. |
| Store domain, chosen plan, email wording and sending rules, product and inventory data | The merchant and the Shopify API | To run the app for that store |
| Shopper IP address (in memory only, not stored) | The “Notify me” form | To limit abusive signups |
The storefront form sets no cookies. It keeps a single flag in the browser’s session storage so it reports that it is installed only once per visit.
How long we keep it
- A request that is still waiting is deleted after 90 days.
- A request that has been alerted, cancelled or expired is deleted 35 days later.
- Alert log entries are kept for 90 days; once the request is deleted, the entry no longer contains the email address.
- Order attribution records are kept while the merchant uses the app.
- When a merchant uninstalls the app, sending stops immediately; Shopify sends us an erasure notice 48 hours later and the store’s data is deleted then.
Who else handles it
We use a small number of providers to run the service. Each only receives what it needs:
- Shopify (platform, billing, and the webhooks that tell us about inventory and orders).
- Railway (hosting and database, United States).
- Resend (sending the alert emails and reporting delivery).
- Twilio (sending alert texts and reporting delivery). Texts sent from Reshelf’s shared number pass the shopper’s mobile number and the message to Twilio under our account. With a dedicated number, the merchant’s business details are also sent to Twilio and carriers for the verification they require. A merchant using their own Twilio account has their own agreement with Twilio.
- Klaviyo, only for merchants who connect their Klaviyo account: request and alert events, and newsletter opt-ins, are sent to that merchant’s Klaviyo account under Klaviyo’s terms.
We don’t sell personal data, and we don’t use shopper emails for our own marketing.
Shoppers’ rights
Every alert email has a one-click unsubscribe link, and replying STOP to a text cancels text requests with that store. Shoppers can also ask the store to delete their request, which the merchant can do from the app. Requests for access or erasure that a shopper makes through Shopify are passed to us automatically and honoured within 30 days. Depending on where you live (for example under the GDPR or the CCPA), you may have further rights to access, correct, delete or restrict use of your data; contact the store you bought from, or us at [email protected].
Merchants’ responsibilities
Merchants decide what the form says and whether it offers a newsletter opt-in. If you enable the opt-in and export those addresses, you are responsible for using them lawfully.
Security
Shopper emails and mobile numbers, and merchants’ Twilio and Klaviyo credentials, are encrypted at rest with a key that lives outside the database. All traffic uses HTTPS. Storefront requests are verified as coming through Shopify before they are accepted.
Changes and contact
If this policy changes in a way that matters, the date at the top changes and merchants are told in the app. Questions: [email protected].