Allocator — Privacy Policy

Last updated: 28 July 2026

Cette page existe en français

1. What data we collect

Allocator collects the following data from your Shopify store:

2. How we use the data

We use the collected data exclusively to:

We do not sell your data, and we do not transfer it to anyone other than the subprocessors we need to run the service — hosting and transactional email. Each one is named, with what it actually receives, in the DPA.

2 bis. Anonymized, aggregated statistics

To improve the allocation engine and to publish figures about how well it performs, Allocator combines data in aggregated and anonymized form only across merchants. Aggregates never include your store name, domain, product names, or any figure attributable to your store individually.

Any aggregate published outside the app is computed across at least 10 distinct merchants. Below that floor we publish nothing at all, rather than a number from which one store could be recovered. That floor is enforced in code, and it is the same number you read here.

There is no self-service opt-out toggle for these statistics today, and this policy does not promise one: a switch that no code reads would be worse than no switch at all. If you want your store left out, write to support@getallocator.com and we will exclude it by hand.

3. Legal basis for processing

Where the GDPR applies, we rely on the following legal bases:

We do not rely on consent for any of the above, and we do not process special categories of personal data. Note the division of roles: for the data of your customers, Shopify and you are the parties concerned — Allocator never receives it. For your own store identity, we act as controller; for everything else we act as your processor, under the DPA.

4. Your rights

You may, at any time and free of charge:

Write to support@getallocator.com. We answer within one month. We do not ask for anything beyond what is needed to check that the request comes from the store it concerns.

5. Data storage and security

6. How long we keep data while the app is installed

Data does not accumulate for as long as you stay. A daily sweep deletes anything past the window in which the product actually uses it. The durations below are read from the code that applies them, so this page cannot drift from the sweep:

Allocation suggestions and the decision log are kept for as long as the app is installed: they are what lets the product show you what it proposed, what you changed, and what came of it. Everything in this section is deleted with the rest when you uninstall — see below.

7. Deletion when you uninstall

8. Contact

For any privacy question: support@getallocator.com

9. The one free-text field, and what we do with it

Everything Allocator reads from Shopify is aggregated by product variant, location and day: no customer name, email, address or payment information ever reaches us, and we do not request the Shopify scopes that would return one.

One field is different, because a human types into it: the optional note on an in-store restock request, on the store page and on the POS tile. It exists so a salesperson can say why they need the item — how often it was asked for, which size runs out first. The field asks explicitly for no customer names and no contact details, and before the note is stored Allocator removes email addresses, and any run of digits carrying the marks of a phone or reference number — an international prefix, a leading zero, an unbroken run of seven digits or more — replacing it with a marker. What remains is visible to your own head office inside the app, and is deleted with the rest of your data.

That stripping is a safety net, not a guarantee, and we would rather tell you where it stops than let you assume it is airtight. It cannot recognise a first name. It also deliberately leaves alone a number written in the same shape as a run of sizes — 12 34 56 78 90 is indistinguishable from 34 36 38 40 42, and we chose to keep your staff's size runs readable rather than shred them. If someone in your team writes a customer's identity into that field, it is stored as typed, on your instruction and under your responsibility as the data controller — and you can have it removed at support@getallocator.com.