StockBeacon Privacy Policy
StockBeacon Privacy Policy
Effective Date: 7th October 2026
Welcome to StockBeacon ("StockBeacon", "we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you install, access, or use the StockBeacon Shopify application (the "App") and any related services (collectively, the "Services").
StockBeacon lets Shopify merchants add a "notify me when available" form to out-of-stock product pages and automatically alert shoppers when the product is back in stock. Alerts are delivered either through Shopify Flow and Shopify Messaging (Shopify Email), or through a messaging platform the merchant connects, such as Klaviyo, Omnisend, CleverTap, MoEngage, a WhatsApp provider, or the merchant's own webhook endpoint. Depending on how you interact with the Services, you may be a Merchant (a store owner or staff member using the App inside Shopify Admin) or a Shopper (a person who signs up on a Merchant's store to be told when a product is back in stock).
We are committed to complying with global data-protection and privacy laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), the Singapore Personal Data Protection Act (PDPA), the India Digital Personal Data Protection Act 2023 (DPDP Act), the Australian Privacy Act 1988, and other applicable regional legislation across the United States, Europe (EU & UK), and Asia-Pacific.
If you have any questions or concerns, please contact us at apps@seventhtriangle.com.
1. Who We Are
StockBeacon is a Shopify application developed and maintained by Seventh Triangle Consulting. We act as a data processor when we process information on behalf of Merchants, including Shopper contact details, restock sign-ups, and notification records. We act as a data controller for information we collect about Merchants as our customers, about visitors to our marketing materials and prospective Merchants, and in our own operational and security logs.
Merchants remain responsible for their own privacy notices to Shoppers, for the wording and consent settings of the sign-up form on their storefront, for the content of the notifications they send, and for their agreements with any messaging platform they connect to StockBeacon.
2. Information We Collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Merchant Account Data | Store domain (myshopify.com), Shopify shop ID, store details Shopify shares with apps (such as store name and plan), granted access scopes, Shopify Admin API access and refresh tokens, and, for signed-in admin sessions, the basic staff profile Shopify provides for the person using the App | Shopify OAuth when the App is installed; Shopify webhooks |
|
| Merchant Configuration & Usage Data | Active notification destination; Shopify Messaging template design (style, colours, font, button style, button, heading, body and footer text, whether to show image, price and title); sending settings (batch size, interval, hourly cap, priority order, stock-aware sending); whether sending is paused; setup progress (Flow trigger, theme app embed status, whether a Shopify Flow workflow using the App is on, as reported by Shopify Flow, and the Merchant's confirmation that Shopify Messaging and Shopify Flow are installed); import and export job history; support communications | Merchant input in the App; Shopify Flow; Shopify Admin API |
|
| Destination & Credential Data | For a connected messaging platform (Klaviyo, Omnisend, CleverTap, MoEngage, a WhatsApp provider, or a custom endpoint): platform, endpoint URL, HTTP method, request headers (which may contain API keys or access tokens), request body template, platform-specific settings, and when the connection was last tested | Merchant input in the App |
|
| Shopper (Subscriber) Data | Email address; phone number (only if the Merchant's form asks for one); Shopify customer ID (if the Shopper is logged in, or a customer record is found or created); browser language; terms acceptance and marketing consent status with timestamp; the product and variant subscribed to; sign-up source (storefront or Merchant import); status (pending, sent, failed, cancelled) with timestamps; delivery error messages | Storefront sign-up form via Shopify App Proxy; files imported by the Merchant; Shopify Admin API |
|
| Data the App Writes to the Merchant's Shopify Store | A customer record (email address) for Shoppers who are not yet customers; email marketing consent set to "subscribed" (single opt-in); a customer tag beginning bisn|at| holding a snapshot of the restocked product (product handle, variant ID, price, currency, image path) |
Created by the App through the Shopify Admin API |
|
| Product, Inventory & Theme Data | Product and variant IDs, titles, handles, prices, currency and images; inventory item IDs and available quantity per location for variants that have subscribers; theme settings, read to check whether the App's theme embed is turned on | Shopify Admin API; Shopify inventory webhooks |
|
| Notification & Analytics Records | Restock batches (product variant, restock quantity, number of recipients, schedule, status and timing); aggregated counts shown on the dashboard | Generated by the App |
|
| Import & Export Files | CSV or Excel files the Merchant uploads (Shopper emails, phone numbers, products and sign-up times), files generated for the Merchant to download, and import result reports | Merchant uploads; generated by the App |
|
| Technical & Security Data | IP address of storefront form submissions (held briefly in memory for rate limiting, and written to logs only if the limit is exceeded); request metadata; error and operational logs, in which email addresses and phone numbers are masked and tokens, passwords, API keys and authorization headers are redacted | Collected automatically |
|
We do not sell or rent personal data, and we do not use Shopper data for our own marketing. Shoppers do not need an account with StockBeacon.
Payment and cardholder data: any charges for the App are billed through Shopify's PCI-DSS-compliant infrastructure. We do not receive or process payment card data.
3. Restock Sign-ups & Email Marketing Consent
This section explains what happens when a Shopper signs up for a restock alert, because the App makes changes in the Merchant's Shopify store as part of that sign-up.
- Out-of-stock check. The App confirms the selected product variant is out of stock. Sign-ups are only accepted for out-of-stock variants.
- Customer record. The App links the sign-up to a customer in the Merchant's Shopify store, using the Shopper's own account if they are logged in, an existing customer with the same email address, or, if neither exists, a new customer record created with that email address.
- Email marketing consent. Shopify Email only delivers to customers who are subscribed to email marketing. So that the restock alert can be delivered, the App sets the customer's email marketing consent to "subscribed" (single opt-in) if it is not already. The sign-up form tells the Shopper this at the point of submission: "By submitting, you agree to receive restock alerts plus news and offers. Unsubscribe anytime."
For Shoppers: because signing up subscribes you to the store's email marketing, you may also receive other marketing emails from that store. You can unsubscribe at any time using the unsubscribe link in the store's emails, or by contacting the store directly. Restock alerts sent through Shopify Messaging are only delivered while you remain subscribed.
- Terms checkbox. Merchants may add an optional or required checkbox linking to their own terms. Whether it was ticked is recorded with the sign-up.
- Imported subscribers. The App does not change marketing consent for subscribers a Merchant imports from a file. Through Shopify Messaging, imported subscribers are only reached if they match a customer who is already subscribed to email marketing. Merchants must have a lawful basis to contact anyone they import.
- Test notifications. When a Merchant sends a test through Shopify Messaging, the test email address must belong to an existing customer, and the App sets that customer's email marketing consent to "subscribed" so the test can be delivered. Merchants should use their own or a staff address for tests.
- Merchant responsibility. Merchants are responsible for ensuring that this sign-up flow, single opt-in, and the form's wording meet the laws that apply to their store and customers. Some jurisdictions require double opt-in or a separate, unticked consent for marketing.
4. Cookies & Similar Technologies
StockBeacon does not set its own cookies and does not use browser local storage or session storage, either in the admin App or in the storefront sign-up form.
- Merchants are authenticated into the embedded admin App using Shopify's session tokens and Shopify's own session mechanisms.
- The storefront sign-up form is a Shopify theme app extension served by Shopify. Sign-ups are submitted through Shopify's App Proxy.
- We do not use advertising cookies, tracking pixels, or third-party analytics in the App or the sign-up form.
Merchants remain responsible for their own storefront cookie notices and consent banners.
5. Legal Bases for Processing (GDPR / UK GDPR)
We rely on the following legal grounds:
- Contractual Necessity – to provide the Services the Merchant requests by installing the App, including recording restock sign-ups, detecting restocks, and sending alerts through the Merchant's chosen destination.
- Legitimate Interests – to secure and improve the Services, prevent abuse of the public sign-up form, provide sending history and reports to Merchants, and communicate with Merchants about the App.
- Consent – the Shopper's request to be notified, and email marketing consent given at sign-up as described in Section 3. The Merchant, as the store operator and sender, is responsible for obtaining and documenting any consent required for messages to Shoppers.
- Legal Obligation – to comply with applicable law, tax, accounting and regulatory requirements, including Shopify's mandatory privacy webhooks.
6. How We Use Your Information
- To display the sign-up form on out-of-stock products and record Shoppers' restock requests.
- To confirm a product is out of stock at sign-up and to monitor inventory changes for products that have subscribers.
- To create or link a Shopify customer record and set email marketing consent so that alerts can be delivered (see Section 3).
- To send restock alerts in paced batches according to the Merchant's settings, through Shopify Flow and Shopify Messaging or through the Merchant's connected platform.
- To show Merchants their subscribers, scheduled, sent, failed and cancelled notifications, in-demand products, and dashboard statistics.
- To import and export subscriber lists at the Merchant's request.
- To authenticate Merchants, secure the Services, and prevent spam and abuse of the sign-up form.
- To answer support requests and resolve delivery or configuration issues.
- To comply with legal obligations, respond to data subject requests, and enforce our Terms of Service.
We do not combine Shopper data across different Merchants' stores.
7. How We Share Information
We do not sell personal data. We only share information:
- Within Seventh Triangle Consulting and its subsidiaries, on a need-to-know basis;
- With Service Providers acting on our behalf under appropriate safeguards, including:
- Shopify – the embedded admin experience, OAuth, Admin API, App Proxy, theme app extensions, webhooks, Shopify Flow, and Shopify Messaging / Shopify Email, which delivers the email when the Merchant uses that destination;
- MongoDB Atlas – database hosting for Merchant settings, destination credentials, Shopper sign-ups and notification records;
- Amazon Web Services (AWS) – delivery of Shopify webhook events through Amazon EventBridge;
- Application hosting providers used to run the StockBeacon backend;
- With Merchant-chosen messaging platforms – when a Merchant connects Klaviyo, Omnisend, CleverTap, MoEngage, a WhatsApp provider (for example Twilio or Gupshup), or a custom endpoint, we send that platform the fields the Merchant's request template uses. These can include the Shopper's email address, phone number, browser language, Shopify customer ID, marketing consent status, sign-up and alert times, the product and variant details, product URL, and store domain. How that platform handles the data is governed by the Merchant's own agreement with it;
- With the Merchant whose store generated the data – Merchants can view and export their subscribers, notification history and reports in the App;
- For Legal Reasons, such as responding to lawful requests from regulators or to protect our rights, property, or users.
Where data is transferred outside the EEA or UK, we rely on approved transfer mechanisms such as Standard Contractual Clauses (SCCs) or an adequacy decision, and we require our sub-processors (and expect Merchants' chosen platforms) to maintain appropriate safeguards.
8. International Data Transfers
StockBeacon is operated by Seventh Triangle Consulting in India. Application data is stored in MongoDB Atlas and processed on our application servers. Shopify and any messaging platform a Merchant connects may process data in the regions where they operate. Depending on your location, personal data may therefore be transferred to and processed in countries other than your own. We implement safeguards including:
- Encryption in transit (TLS / HTTPS) between browsers, Shopify, our Services, our database, and connected platforms.
- An additional layer of encryption on requests sent from the admin App to our servers.
- Encryption at rest provided by our database hosting provider.
- Access controls limiting internal access to production systems.
9. Data Subject & Consumer Rights
Depending on where you live, you may have rights to:
- Access, correct, or delete your personal data;
- Object to or restrict processing;
- Data portability;
- Opt out of marketing communications;
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- Lodge a complaint with a supervisory authority (for example the ICO in the UK, the data protection authority in your EU member state, or your local privacy regulator).
Shoppers should contact the store they signed up with first, since that Merchant controls their data. Shoppers can stop marketing emails at any time using the unsubscribe link in the store's emails. Merchants may forward requests to us at apps@seventhtriangle.com. We will respond within the deadlines set by applicable law (for example, one month under GDPR).
StockBeacon supports Shopify's mandatory privacy webhooks:
-
customers/data_request– we locate the sign-up records we hold for that customer (product, channel, contact details, status, consent, and dates) so the request can be fulfilled. -
customers/redact– we cancel the customer's pending alerts and permanently remove their email address, phone number and Shopify customer ID from all our records. The remaining anonymised records are deleted automatically within 30 days. -
shop/redact– we delete all remaining data for the store (see Section 11).
Customer records, consent status and tags the App created in the Merchant's Shopify store (Section 3) form part of the Merchant's Shopify data and are handled through Shopify's own privacy processes.
10. Security Measures
- TLS encryption (HTTPS) for all App traffic and API communications.
- Shopify OAuth and session tokens for Merchant authentication, with expiring, refreshed Shopify access tokens.
- Storefront sign-ups are only accepted through Shopify's App Proxy with a verified signature, and are rate-limited per IP address. Shopify webhooks and Shopify Flow callbacks are signature-verified.
- Requests the App makes to Merchant-configured endpoints are restricted to public internet addresses.
- Logs mask email addresses and phone numbers and redact tokens, passwords, API keys and authorization headers.
- Shopify access tokens are deleted as soon as the App is uninstalled. Destination credentials are used only to deliver the Merchant's notifications and are deleted on uninstall.
- Principle of least privilege and role-based access controls for internal systems.
Although we implement industry-standard safeguards, no system is 100% secure. Merchants should keep their Shopify credentials and messaging-platform API keys confidential, rotate keys if they may have been exposed, and notify us of any security incident at apps@seventhtriangle.com.
11. Data Retention
| Data | How long we keep it |
|---|---|
| Merchant account, settings, destination configuration and credentials | While the App is installed; deleted when the App is uninstalled |
| Shopify access tokens and sessions | Deleted as soon as the App is uninstalled |
| Pending restock sign-ups | Until the alert is sent, the Merchant removes the subscriber, the customer's data is redacted, or the App is uninstalled |
| Sent, failed and cancelled sign-up records | Deleted automatically 30 days after they reach that status |
| Restock batch records | Deleted automatically 30 days after the batch completes or is cancelled |
| Import and export job records | Deleted automatically after 24 hours |
| Uploaded import files and generated export files | Deleted automatically after about 24 hours; import result reports and any remaining files are deleted when the App is uninstalled |
| Inventory tracking for subscribed products | While needed to detect restocks; deleted when the App is uninstalled |
| Operational and security logs | For a limited period, for security and troubleshooting, with contact details masked |
On uninstall, we immediately cancel any scheduled alerts and delete the store's sessions, settings, destination credentials, Shopper sign-ups, notification records, inventory tracking data, and import/export files. Shopify's shop/redact webhook, sent 48 hours after uninstall, triggers the same deletion again so that no residual store data remains.
Customer records, email marketing consent and bisn|at| customer tags written to the Merchant's Shopify store remain in that store under the Merchant's control after uninstall. Merchants can remove the tags from their customers at any time. Data sent to a Merchant's connected messaging platform is retained according to that platform's policies.
12. Children's Privacy
Our Services are not directed to children under 16. We do not knowingly collect personal data from minors through the App. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version with an updated "Effective Date" and, where required, provide notice (for example, in the App dashboard or by email). Continued use of the Services after such changes constitutes acceptance.
14. Contact Us
If you have any questions, requests, or complaints about this Privacy Policy or our privacy practices, please contact:
Privacy Team
StockBeacon / Seventh Triangle Consulting
Second Floor, The Berry Coworks, Plot No 15, Sector-142, Noida, Uttar Pradesh - 201304, India
Email: apps@seventhtriangle.com
Data Protection Officer (EU/UK): Sushant Gupta, sushant@seventhtriangle.com
© 2026 Seventh Triangle Consulting. All rights reserved.