How our Shopify apps handle data โ plainly, and in line with GDPR and applicable US state privacy law.
Last updated: 20 July 2026
SlothRocket ("we", "us") builds apps for Shopify merchants. This policy covers our apps, including Back in Stock. For our apps, the merchant (the store that installs the app) is the data controller for their shoppers' data; we act as their data processor, under a Data Processing Agreement (Art. 28 GDPR) that forms part of our merchant terms. You can reach us at support@slothrocket.co.
Operator identity: SlothRocket is operated by [LEGAL NAME / ENTITY โ to be completed before commercial launch], based in Italy (EU). VAT / registration number: [to be added before commercial launch]. Registered address: Via Ferrini 11, 20037 Paderno Dugnano (MI), Italy. Privacy contact: support@slothrocket.co.
| Data | From whom | Why |
|---|---|---|
| Shopper email address | Shoppers (via the store's "Notify me" widget) | To send the restock alert they asked for โ and, where the store enables it, one follow-up reminder about the same item |
| Product / variant, sign-up time, consent timestamp | Shoppers | To know what to alert on, and for accountability |
| Store catalog data via Shopify (products, inventory, publications) โ read only | Merchant's Shopify store | To detect genuine restocks before sending |
| Order events via Shopify (buyer email + purchased variant IDs only) โ read only | Merchant's Shopify store | To stop alerting a shopper who already bought the item. We do not store order contents โ the event is processed in memory and discarded |
| Store files via Shopify โ read and write | Merchant's Shopify store | Limited to storing and serving the email logo the merchant uploads |
| Store name, contact email, timezone, address | Merchant's Shopify store | Sender identity, digest scheduling, and the legally-required footer address |
We do not collect payment details, and we do not build advertising profiles. Order data is Shopify "Protected Customer Data" and is handled in accordance with Shopify's Protected Customer Data requirements โ read transiently, never retained.
We never use shopper emails for our own marketing, and merchants are contractually prohibited from repurposing them.
| Provider | Purpose | Region |
|---|---|---|
| Shopify Inc. | App platform & store data | US / global โ governed by Shopify's DPA and EU Standard Contractual Clauses / the EU-US Data Privacy Framework where applicable |
| Resend | Sending transactional email | EU |
| Hostinger | Application hosting (server & database) | EU |
Our own application data (waitlist entries, sign-ups) is stored on access-controlled infrastructure in the EU. Some data necessarily flows through Shopify (US / global) as the platform our apps run on. Where personal data is transferred outside the EU/EEA, it is protected by an adequacy decision, the EU-US Data Privacy Framework, or EU Standard Contractual Clauses.
You may request access to your data, and its rectification, erasure, restriction of processing, and portability. Because your alert is sent on the basis of consent, you can withdraw that consent at any time โ for example via the one-click unsubscribe in every email โ without affecting processing already carried out.
Unsubscribing with one click stops all further emails immediately and marks your entry for deletion; it is fully erased within 30 days (or straight away on request). The quickest route for any request is the store you signed up with (the data controller); you can also contact us at support@slothrocket.co. We honor Shopify's data-request and erasure webhooks and respond within 30 days.
You also have the right to lodge a complaint with a data-protection supervisory authority. In Italy this is the Garante per la protezione dei dati personali (www.garanteprivacy.it); if you are in another EU/EEA country you may complain to your local authority. As the store you signed up with is the data controller, such complaints are usually best directed there first, and we will support the merchant in responding.
We do not "sell" your personal information and do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA โ and we have not done so in the preceding 12 months. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link; there is nothing to opt out of.
If you are a US resident, you may have rights to know/access, delete, and correct your data, to non-discrimination for exercising them, and (in some states) to appeal a decision. Because we act as a service provider to the store you signed up with, the quickest route is that store; you may also email support@slothrocket.co and we will assist the merchant. For California requests we generally respond within 45 days (extendable by a further 45 days with notice). We verify requests by matching the email address on file, and you may use an authorized agent (proof of authorization may be required). To appeal, reply to our decision email.
Our apps are business tools for merchants and are not directed to children. We do not knowingly collect personal data from anyone under 16 (or the applicable age of digital consent in your country โ for example 14 in Italy), or under 13 for US visitors. If you believe a child provided an email, contact us and we will delete it.
Data is transmitted over TLS and stored on access-controlled infrastructure; credentials are held in an encrypted secrets store. Access is limited on a need-to-know basis. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.
The embedded merchant dashboard runs inside Shopify's admin and uses only the strictly-necessary session cookies required to keep you signed in. We set no advertising or tracking cookies.
We'll update this page when our practices change and revise the "last updated" date above.