Privacy Policy

Last updated: August 4, 2026

Who we are

DEADSTOCK (“we”, “us”) operates app.dead-stock.ca, a service that cross-lists a merchant’s Shopify inventory to external marketplaces (currently Grailed) and keeps stock levels in sync between them. This policy describes what we collect from merchants who use the service, why, and how to get it removed. Questions: [email protected].

What we collect

  • Account data — your name, email address, and authentication state, handled by our sign-in provider (Clerk).
  • Store and product data — product titles, descriptions, photos, prices, and inventory quantities from your connected Shopify store. Our Shopify access is limited to product and inventory scopes (read/write products, read/write inventory).
  • Access tokens — the Shopify access token your store grants us, and marketplace session credentials you provide, stored encrypted at rest (AES-256-GCM) and used only to operate the sync on your behalf.
  • Billing data — subscription payments are processed through Shopify’s own billing system, on the same invoice as the rest of your store. We never see or store card numbers.
  • Operational logs — records of listing, sync, and pricing actions the service performs, kept so that every automated change to your inventory is auditable and reversible.

What we deliberately do not collect

We do not request or store your shoppers’ personal information. Our Shopify scopes exclude customer and order data. If a Shopify data request ever includes customer fields, we have nothing to return, because nothing is held.

How we use it

Only to provide the service: creating and updating marketplace listings from your products, keeping inventory in sync in both directions, and showing you what the service did and why. We do not sell data, share it with advertisers, or use it to train machine-learning models.

Where it lives

Account and connection records are stored in our database (Supabase). Each merchant’s sync agent runs on an isolated server dedicated to that merchant, firewalled so that only our control plane can reach it. Product data cached on that server belongs to one store only and is destroyed with the server.

Deletion

  • Uninstalling the app from your Shopify store deletes our stored connection and encrypted access token for that store.
  • Shopify redaction requests (the GDPR webhooks Shopify sends on your behalf) are honoured: shop data is erased on shop/redact; customer requests return nothing because nothing is held.
  • Closing your DEADSTOCK account — email [email protected] and we will delete your account, your agent server, and all associated data within 30 days, confirmed in writing.

Sub-processors

Clerk (authentication), Supabase (database), Shopify (billing), DigitalOcean (hosting), Cloudflare (DNS and transport security). Each receives only what its function requires.

Changes

If this policy changes materially, we will note the new date above and email active merchants before the change takes effect.