OneShelf ("the App", "we", "us") is a Shopify app that helps merchants track a shared base stock — one physical count of raw material or component — across every product listing that draws from it, and keeps Shopify's own inventory numbers and storefronts in sync automatically as orders come in. OneShelf is operated by Wilson Chen, an individual developer (sole proprietor), who is the data controller for the processing described here. This policy explains what information the App collects when a merchant installs and uses it, why, and what happens to it. It is written for merchants who install OneShelf, and covers, where relevant, the merchant's own customers.
From Shopify, through the Admin API and webhooks. When a merchant installs OneShelf,
Shopify grants it these access scopes: read_products, write_products,
read_inventory, write_inventory, read_orders,
read_locations, and read_validations — the minimum the app's sync
engine needs.
What we store: base stock records (name, optional SKU, location, quantity, backorder setting); links between
product variants and base stocks (variant/product IDs and titles, how many units each sale uses); an
append-only activity ledger of every stock change (order IDs, order names, line-item IDs, refund IDs, and
signed quantity changes — never a customer name, email, address, or phone number); and internal bookkeeping
that lets the app recognize its own inventory writes. None of these records contain customer personal
data — the app's job is to move a stock count, not to know who bought what.
Order webhook payloads, in transit. Shopify's order and refund webhooks carry a full order object, which can include the buyer's name, email, phone, and addresses. OneShelf extracts only the order identifiers and line items — order ID, order name, order date, and line-item IDs, variant IDs, and quantities — at the moment the webhook arrives, and writes only that minimal record to its internal job queue. The customer fields exist only in the HTTP request itself, in transit; they are never stored. When a job reaches a terminal state — finished successfully or permanently failed — even that minimal payload is overwritten with an empty object, and the job record itself is deleted within 7 days.
From the merchant, directly. When a staff account authorizes the app, we store that staff user's basic profile as provided by Shopify (name, email, locale, account-owner flag) with the store's access token, to run the authenticated admin session. We also store the merchant's own settings in the app (preview mode, deduction trigger, low-stock buffer, billing tier).
From merchants' customers, directly. OneShelf ships one storefront component: the
optional "Checkout stock check" app embed. When the merchant enables it in the theme editor, a small script
loads on storefront pages. At the checkout click it sends the cart's variant IDs and quantities to OneShelf
through Shopify's app proxy, to check the cart against shared stock. The script reads Shopify's own cart
endpoints only (/cart.js, /cart/change.js) and contacts no third party. It stores
one short-lived note in the browser's sessionStorage (about 45 seconds) when it adjusts a cart quantity, so
the cart page can say what changed. It sets no cookies and does no tracking or fingerprinting. OneShelf's
server keeps nothing from these requests: the cart lines are checked and discarded, and the
logged-in-customer identifier Shopify attaches to app-proxy requests is ignored. The app's other buyer-facing
surface, the checkout validation function, runs entirely inside Shopify's sandboxed runtime and sends no data
to OneShelf's servers. We collect no payment card details (Shopify handles all billing) and use no analytics
or telemetry libraries.
Only to operate the app's core function: detecting a sale, refund, or manual edit; updating the affected base stock; and pushing the resulting available-to-sell quantity back to every linked listing. Staff account information authenticates admin sessions. We do not use any of this information for advertising, do not sell it, and do not share it with anyone except the infrastructure providers below.
The app and its database run on Railway in the Amsterdam (Netherlands, EU) region. The production
database uses Railway Point-in-Time Recovery — continuous write-ahead-log archiving to a Railway storage
bucket, with a weekly full backup and daily incremental backups, giving a restore window of roughly four weeks.
All API and webhook traffic uses HTTPS/TLS. Webhook payloads are scrubbed and purged as described above.
Operational records (base stocks, links, ledger, settings) are retained for as long as the app is installed,
so merchants keep their full audit trail. When a store uninstalls the app, Shopify sends the
shop/redact webhook about 48 hours later. OneShelf then holds the store's operational records for
30 days after the uninstall, so a store that reinstalls within that time gets its base stocks, links, activity,
and settings back. 30 days after the uninstall, OneShelf erases every operational record it holds for that
store — unless the store has reinstalled, in which case the data is kept so the audit trail survives the
reinstall. This is inside the 30-day window Shopify allows for acting on a shop/redact request.
The erasure job's own bookkeeping record (store domain only) is purged within 7 days of the erasure. Session
records are deleted immediately on uninstall, and the shop/redact erasure transaction deletes any
that remain.
| Provider | Purpose |
|---|---|
| Railway | Hosts the app server and its database (EU region) |
| Cloudflare (Email Routing) | Routes mail sent to our support address |
| Google (Gmail) | The mailbox where support correspondence is received and answered |
| Anthropic (Claude) | AI-assisted development and operations tooling used by the operator. It is not part of the app's runtime data path; operational material it may process (application logs, store metadata such as store domains and order identifiers) excludes customer personal information, which the app does not store |
| Shopify | The platform the app runs on; all API, webhook, and billing traffic |
| Discord | Operational alerts to the operator. When a store installs the app, creates its first base stock, goes live, or records its first live sale, the app posts one line to a private operator channel: the store domain and the event name. No customer data, no order data, no staff data |
The app's runtime itself sends data to no analytics, error-tracking, or AI service. Its one outbound message apart from Shopify is the Discord operational alert above.
OneShelf subscribes to Shopify's three mandatory compliance webhooks and answers all of them:
customers/data_request (no customer personal data is stored at rest, so there is nothing to
export); customers/redact (no customer personal data is stored, including in the job queue — webhook
payloads are minimized on arrival; the handler additionally blanks the stored payload of completed and
permanently-failed jobs for that shop); and shop/redact (performs the same scrub and then
erases all of the shop's operational records, including stored sessions, in one transaction, as described
above).
Depending on where you (or your customers) are located, you may have rights to access, correct, or delete personal data, or to object to or restrict its processing. Because OneShelf does not hold customer personal data at rest, most such requests will have nothing to return; for anything else — including a merchant's own staff account information — contact us below and we will respond.
OneShelf is a business tool for Shopify merchants and their staff. It is not directed at, and we do not knowingly collect information from, children.
Material changes will be reflected by updating the effective date above.
OneShelf is operated by Wilson Chen (sole proprietor).
Email, for all privacy matters and data requests:
support@oneshelf.app