Privacy Policy — Restock:ize ‑ Reorder & POs
Last updated: 16 July 2026
This Privacy Policy describes how Xeio Ltd ("we", "us") handles information when you install and use the Restock:ize Shopify app.
1. What data we access
To provide restocking recommendations and purchase orders, Restock:ize reads the following data from your Shopify store using the Shopify Admin API:
- Products and variants — titles, SKUs, inventory quantities, unit costs, and vendor names.
- Inventory levels — stock quantities per location.
- Locations — names and active status.
- Orders — line item quantities, dates, and refund quantities. We read this data solely to compute per-SKU sales velocity for reorder recommendations. We do not read, store, or display customer names, emails, addresses, or any other personally identifiable information (PII).
2. How we store your data
Your data never leaves your Shopify store. All derived data — settings, supplier lead times, purchase orders, and sales velocity aggregates — is stored exclusively in app-data metafields within your own Shopify store. These metafields are private to the app and are automatically deleted by Shopify when you uninstall the app.
Xeio Ltd does not operate a database or persistent server storage for merchant or customer data in v1 of this app.
3. Third-party services
- Cloudflare Workers — we operate a serverless function solely to receive and verify Shopify compliance webhooks (see Section 4). This function processes no personal data; it only confirms receipt and handles uninstall cleanup of any temporary server-side bookkeeping (none in v1).
- Shopify App Pricing — subscription billing is managed entirely by Shopify. We never receive your payment card details.
4. Shopify compliance webhooks
In compliance with Shopify's API Terms, we respond to the following webhooks:
- customers/data_request — We confirm that Restock:ize stores no customer PII. Order-derived aggregates (unit counts and dates) contain no personally identifiable information.
- customers/redact — No-op. We store no customer data to redact.
- shop/redact — On uninstall, all app-data metafields are automatically deleted by Shopify. Any temporary server-side bookkeeping is deleted within 30 days.
5. Data retention
App-data metafields are deleted automatically when you uninstall Restock:ize. Purchase orders, supplier settings, and velocity caches stored in your store's metafields are yours; you can export them before uninstalling.
6. Your rights
Because we do not store customer personal data on our infrastructure, data subject requests (access, deletion, portability) are fulfilled by Shopify, not by us. If you have questions about your merchant account data, please contact us using the email below.
7. Contact
Xeio Ltd
Email: info@xeio.com
Registered in England and Wales.