OneShelf Privacy Policy

Effective date: 2026-10-06

Overview

OneShelf ("the App", "we", "us") is a Shopify app that helps merchants track a shared base stock — one physical count of raw material or component — across every product listing that draws from it, and keeps Shopify's own inventory numbers and storefronts in sync automatically as orders come in. OneShelf is operated by Wilson Chen, an individual developer (sole proprietor), who is the data controller for the processing described here. This policy explains what information the App collects when a merchant installs and uses it, why, and what happens to it. It is written for merchants who install OneShelf, and covers, where relevant, the merchant's own customers.

Information we collect

From Shopify, through the Admin API and webhooks. When a merchant installs OneShelf, Shopify grants it these access scopes: read_products, write_products, read_inventory, write_inventory, read_orders, read_locations, and read_validations — the minimum the app's sync engine needs. What we store: base stock records (name, optional SKU, location, quantity, backorder setting); links between product variants and base stocks (variant/product IDs and titles, how many units each sale uses); an append-only activity ledger of every stock change (order IDs, order names, line-item IDs, refund IDs, and signed quantity changes — never a customer name, email, address, or phone number); and internal bookkeeping that lets the app recognize its own inventory writes. None of these records contain customer personal data — the app's job is to move a stock count, not to know who bought what.

Order webhook payloads, in transit. Shopify's order and refund webhooks carry a full order object, which can include the buyer's name, email, phone, and addresses. OneShelf extracts only the order identifiers and line items — order ID, order name, order date, and line-item IDs, variant IDs, and quantities — at the moment the webhook arrives, and writes only that minimal record to its internal job queue. The customer fields exist only in the HTTP request itself, in transit; they are never stored. When a job reaches a terminal state — finished successfully or permanently failed — even that minimal payload is overwritten with an empty object, and the job record itself is deleted within 7 days.

From the merchant, directly. When a staff account authorizes the app, we store that staff user's basic profile as provided by Shopify (name, email, locale, account-owner flag) with the store's access token, to run the authenticated admin session. We also store the merchant's own settings in the app (preview mode, deduction trigger, low-stock buffer, billing tier).

From merchants' customers, directly. OneShelf ships one storefront component: the optional "Checkout stock check" app embed. When the merchant enables it in the theme editor, a small script loads on storefront pages. At the checkout click it sends the cart's variant IDs and quantities to OneShelf through Shopify's app proxy, to check the cart against shared stock. The script reads Shopify's own cart endpoints only (/cart.js, /cart/change.js) and contacts no third party. It stores one short-lived note in the browser's sessionStorage (about 45 seconds) when it adjusts a cart quantity, so the cart page can say what changed. It sets no cookies and does no tracking or fingerprinting. OneShelf's server keeps nothing from these requests: the cart lines are checked and discarded, and the logged-in-customer identifier Shopify attaches to app-proxy requests is ignored. The app's other buyer-facing surface, the checkout validation function, runs entirely inside Shopify's sandboxed runtime and sends no data to OneShelf's servers. We collect no payment card details (Shopify handles all billing) and use no analytics or telemetry libraries.

How we use the information

Only to operate the app's core function: detecting a sale, refund, or manual edit; updating the affected base stock; and pushing the resulting available-to-sell quantity back to every linked listing. Staff account information authenticates admin sessions. We do not use any of this information for advertising, do not sell it, and do not share it with anyone except the infrastructure providers below.

Storage, security, and retention

The app and its database run on Railway in the Amsterdam (Netherlands, EU) region. The production database uses Railway Point-in-Time Recovery — continuous write-ahead-log archiving to a Railway storage bucket, with a weekly full backup and daily incremental backups, giving a restore window of roughly four weeks. All API and webhook traffic uses HTTPS/TLS. Webhook payloads are scrubbed and purged as described above. Operational records (base stocks, links, ledger, settings) are retained for as long as the app is installed, so merchants keep their full audit trail. When a store uninstalls the app, Shopify sends the shop/redact webhook about 48 hours later. OneShelf then holds the store's operational records for 30 days after the uninstall, so a store that reinstalls within that time gets its base stocks, links, activity, and settings back. 30 days after the uninstall, OneShelf erases every operational record it holds for that store — unless the store has reinstalled, in which case the data is kept so the audit trail survives the reinstall. This is inside the 30-day window Shopify allows for acting on a shop/redact request. The erasure job's own bookkeeping record (store domain only) is purged within 7 days of the erasure. Session records are deleted immediately on uninstall, and the shop/redact erasure transaction deletes any that remain.

Third-party subprocessors

ProviderPurpose
RailwayHosts the app server and its database (EU region)
Cloudflare (Email Routing)Routes mail sent to our support address
Google (Gmail)The mailbox where support correspondence is received and answered
Anthropic (Claude)AI-assisted development and operations tooling used by the operator. It is not part of the app's runtime data path; operational material it may process (application logs, store metadata such as store domains and order identifiers) excludes customer personal information, which the app does not store
ShopifyThe platform the app runs on; all API, webhook, and billing traffic
DiscordOperational alerts to the operator. When a store installs the app, creates its first base stock, goes live, or records its first live sale, the app posts one line to a private operator channel: the store domain and the event name. No customer data, no order data, no staff data

The app's runtime itself sends data to no analytics, error-tracking, or AI service. Its one outbound message apart from Shopify is the Discord operational alert above.

Data subject requests

OneShelf subscribes to Shopify's three mandatory compliance webhooks and answers all of them: customers/data_request (no customer personal data is stored at rest, so there is nothing to export); customers/redact (no customer personal data is stored, including in the job queue — webhook payloads are minimized on arrival; the handler additionally blanks the stored payload of completed and permanently-failed jobs for that shop); and shop/redact (performs the same scrub and then erases all of the shop's operational records, including stored sessions, in one transaction, as described above).

Your rights

Depending on where you (or your customers) are located, you may have rights to access, correct, or delete personal data, or to object to or restrict its processing. Because OneShelf does not hold customer personal data at rest, most such requests will have nothing to return; for anything else — including a merchant's own staff account information — contact us below and we will respond.

Children's privacy

OneShelf is a business tool for Shopify merchants and their staff. It is not directed at, and we do not knowingly collect information from, children.

Changes to this policy

Material changes will be reflected by updating the effective date above.

Contact

OneShelf is operated by Wilson Chen (sole proprietor).
Email, for all privacy matters and data requests: support@oneshelf.app