SlothRocket ยท apps for Shopify

Privacy Policy

How our Shopify apps handle data โ€” plainly, and in line with GDPR and applicable US state privacy law.

Last updated: 20 July 2026

In short. Our apps help a store notify its shoppers when a sold-out product is back. We collect the minimum needed to do that โ€” a shopper's email and the item they're waiting for โ€” and we use it to send the restock alert (and, where the store enables it, one follow-up reminder about the same item). We never sell or share your data for advertising, and every email has a one-click unsubscribe.

1. Who we are

SlothRocket ("we", "us") builds apps for Shopify merchants. This policy covers our apps, including Back in Stock. For our apps, the merchant (the store that installs the app) is the data controller for their shoppers' data; we act as their data processor, under a Data Processing Agreement (Art. 28 GDPR) that forms part of our merchant terms. You can reach us at support@slothrocket.co.

Operator identity: SlothRocket is operated by [LEGAL NAME / ENTITY โ€” to be completed before commercial launch], based in Italy (EU). VAT / registration number: [to be added before commercial launch]. Registered address: Via Ferrini 11, 20037 Paderno Dugnano (MI), Italy. Privacy contact: support@slothrocket.co.

2. What we collect

DataFrom whomWhy
Shopper email addressShoppers (via the store's "Notify me" widget)To send the restock alert they asked for โ€” and, where the store enables it, one follow-up reminder about the same item
Product / variant, sign-up time, consent timestampShoppersTo know what to alert on, and for accountability
Store catalog data via Shopify (products, inventory, publications) โ€” read onlyMerchant's Shopify storeTo detect genuine restocks before sending
Order events via Shopify (buyer email + purchased variant IDs only) โ€” read onlyMerchant's Shopify storeTo stop alerting a shopper who already bought the item. We do not store order contents โ€” the event is processed in memory and discarded
Store files via Shopify โ€” read and writeMerchant's Shopify storeLimited to storing and serving the email logo the merchant uploads
Store name, contact email, timezone, addressMerchant's Shopify storeSender identity, digest scheduling, and the legally-required footer address

We do not collect payment details, and we do not build advertising profiles. Order data is Shopify "Protected Customer Data" and is handled in accordance with Shopify's Protected Customer Data requirements โ€” read transiently, never retained.

3. How we use it & legal basis

We never use shopper emails for our own marketing, and merchants are contractually prohibited from repurposing them.

4. Who processes data on our behalf (sub-processors)

ProviderPurposeRegion
Shopify Inc.App platform & store dataUS / global โ€” governed by Shopify's DPA and EU Standard Contractual Clauses / the EU-US Data Privacy Framework where applicable
ResendSending transactional emailEU
HostingerApplication hosting (server & database)EU

5. International transfers

Our own application data (waitlist entries, sign-ups) is stored on access-controlled infrastructure in the EU. Some data necessarily flows through Shopify (US / global) as the platform our apps run on. Where personal data is transferred outside the EU/EEA, it is protected by an adequacy decision, the EU-US Data Privacy Framework, or EU Standard Contractual Clauses.

6. How long we keep it

7. Your rights (EU / UK โ€” GDPR)

You may request access to your data, and its rectification, erasure, restriction of processing, and portability. Because your alert is sent on the basis of consent, you can withdraw that consent at any time โ€” for example via the one-click unsubscribe in every email โ€” without affecting processing already carried out.

Unsubscribing with one click stops all further emails immediately and marks your entry for deletion; it is fully erased within 30 days (or straight away on request). The quickest route for any request is the store you signed up with (the data controller); you can also contact us at support@slothrocket.co. We honor Shopify's data-request and erasure webhooks and respond within 30 days.

You also have the right to lodge a complaint with a data-protection supervisory authority. In Italy this is the Garante per la protezione dei dati personali (www.garanteprivacy.it); if you are in another EU/EEA country you may complain to your local authority. As the store you signed up with is the data controller, such complaints are usually best directed there first, and we will support the merchant in responding.

8. US state privacy rights

We do not "sell" your personal information and do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA โ€” and we have not done so in the preceding 12 months. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link; there is nothing to opt out of.

If you are a US resident, you may have rights to know/access, delete, and correct your data, to non-discrimination for exercising them, and (in some states) to appeal a decision. Because we act as a service provider to the store you signed up with, the quickest route is that store; you may also email support@slothrocket.co and we will assist the merchant. For California requests we generally respond within 45 days (extendable by a further 45 days with notice). We verify requests by matching the email address on file, and you may use an authorized agent (proof of authorization may be required). To appeal, reply to our decision email.

9. Children

Our apps are business tools for merchants and are not directed to children. We do not knowingly collect personal data from anyone under 16 (or the applicable age of digital consent in your country โ€” for example 14 in Italy), or under 13 for US visitors. If you believe a child provided an email, contact us and we will delete it.

10. Security

Data is transmitted over TLS and stored on access-controlled infrastructure; credentials are held in an encrypted secrets store. Access is limited on a need-to-know basis. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.

11. Cookies

The embedded merchant dashboard runs inside Shopify's admin and uses only the strictly-necessary session cookies required to keep you signed in. We set no advertising or tracking cookies.

12. Changes

We'll update this page when our practices change and revise the "last updated" date above.