Allocator — Privacy Policy
Last updated: 28 July 2026
Cette page existe en français
1. What data we collect
Allocator collects the following data from your Shopify store:
- Store information: Your Shopify store domain and an access token (provided by Shopify during app installation) to communicate with the Shopify Admin API.
- Locations: The names and identifiers of your store locations (warehouse and retail stores) so you can assign them roles in Allocator.
- Product and variant data: Product titles, variant options (size, color), SKUs and prices — used to compute allocation suggestions at the variant level.
- Inventory levels: Available stock per variant per location, plus daily snapshots.
- Sales aggregates: Units sold and revenue per variant, per location, per day. Nothing customer-identifying comes with them — no name, email, address, or payment information.
- Transfers and shipments: The status of inventory transfers created through Allocator and their reception status, to reconcile expected vs received quantities.
- In-store lookups and restock requests: What your staff searched for on the store page or the POS tile, and the optional free-text note they attach to a restock request. That note is typed by a human: the app asks them not to enter customer names or contact details, and strips email addresses and anything shaped like a phone or reference number out of the text before storing it. See section 9, which also says what that stripping cannot catch.
2. How we use the data
We use the collected data exclusively to:
- Compute stock allocation suggestions from your central warehouse to your stores.
- Create Shopify inventory transfers when you approve a suggestion.
- Track reception of transfers and detect discrepancies.
- Measure the outcome of accepted suggestions (units sold at destination within 30 days).
We do not sell your data, and we do not transfer it to anyone other than the subprocessors we need to run the service — hosting and transactional email. Each one is named, with what it actually receives, in the DPA.
2 bis. Anonymized, aggregated statistics
To improve the allocation engine and to publish figures about how well it performs, Allocator combines data in aggregated and anonymized form only across merchants. Aggregates never include your store name, domain, product names, or any figure attributable to your store individually.
Any aggregate published outside the app is computed across at least 10 distinct merchants. Below that floor we publish nothing at all, rather than a number from which one store could be recovered. That floor is enforced in code, and it is the same number you read here.
There is no self-service opt-out toggle for these statistics today, and this policy does not promise one: a switch that no code reads would be worse than no switch at all. If you want your store left out, write to support@getallocator.com and we will exclude it by hand.
3. Legal basis for processing
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) for everything the app needs in order to work: reading your locations, products, inventory and aggregated sales, computing suggestions, creating transfers, tracking receptions, and sending the operational emails tied to those actions.
- Legitimate interests (Art. 6(1)(f)) for keeping the service secure and reliable (logs, abuse and error detection), for the anonymized cross-merchant aggregates described in section 2 bis, and for the minimal compliance record described in section 7. Our interest is running and improving a service you asked for; the data involved is either non-personal or limited to your store identity, and you can object at the address below.
- Legal obligation (Art. 6(1)(c)) for retaining the record that proves a deletion request was honoured.
We do not rely on consent for any of the above, and we do not process special categories of personal data. Note the division of roles: for the data of your customers, Shopify and you are the parties concerned — Allocator never receives it. For your own store identity, we act as controller; for everything else we act as your processor, under the DPA.
4. Your rights
You may, at any time and free of charge:
- Access the data we hold about your store, and obtain a copy of it.
- Rectify anything inaccurate. Most of it is read from Shopify — correcting it there propagates on the next sync — but anything you entered in the app we will correct on request.
- Erase it: uninstalling triggers the automatic deletion described in section 7, and you can also ask for immediate erasure without uninstalling.
- Restrict or object to processing based on legitimate interests, including the anonymized aggregates.
- Receive your data in a portable form — a machine-readable export of what we hold.
- Lodge a complaint with your national data protection authority.
Write to support@getallocator.com. We answer within one month. We do not ask for anything beyond what is needed to check that the request comes from the store it concerns.
5. Data storage and security
- Data is stored in a PostgreSQL database hosted on Railway (EU/US).
- Access tokens are short-lived and rotated automatically by Shopify.
- All communication with Shopify is over HTTPS, with HMAC-verified webhooks.
- Transactional email (weekly digest, reception reminders) is delivered by Resend, which receives your store's contact address and the content of the message. The full list of subprocessors is in the DPA.
6. How long we keep data while the app is installed
Data does not accumulate for as long as you stay. A daily sweep deletes anything past the window in which the product actually uses it. The durations below are read from the code that applies them, so this page cannot drift from the sweep:
- Daily inventory snapshots: 200 days. One weekly sample (Mondays) is kept beyond that as an archive — Shopify does not let anyone recover past stock per location, so a deleted snapshot is gone for good, and that archive is what makes it possible to evaluate the engine later. It feeds no figure shown to you.
- Daily sales aggregates: 450 days. The longest estimation window the product uses is far shorter; the surplus exists so a full year of engine evaluation stays possible.
- In-store lookups: 60 days. The engine reads them over 14 days.
- Handled restock requests (done, declined, unmet): 180 days after they were handled. A request that is still open is never deleted, whatever its age — someone in a store asked for something and nobody answered; erasing it would be pretending it was dealt with. A request the engine examined and could not serve is closed as "unmet" after 21 days, with its reason, and then follows the 180-day rule.
- Product usage events: 180 days.
Allocation suggestions and the decision log are kept for as long as the app is installed: they are what lets the product show you what it proposed, what you changed, and what came of it. Everything in this section is deleted with the rest when you uninstall — see below.
7. Deletion when you uninstall
- When you uninstall Allocator, your access tokens are invalidated immediately.
- 48 hours after uninstall, Shopify sends us a redaction request and your store's data is permanently deleted: locations, products and variants, inventory levels and snapshots, sales aggregates, allocation history and decisions, transfers, receptions, in-store requests, settings and tokens. If that deletion does not go through, an hourly sweep retries it until it does.
- What survives that deletion, and why. Two minimal records are kept, because they are the only remaining proof that the deletion happened: (a) one line per purged store, holding a one-way fingerprint of your store domain, the internal store id, the uninstall and redaction timestamps, and whether the purge ran on the webhook or on the retry sweep; (b) the identifier and topic of each compliance webhook already applied, with the same fingerprint, kept so that a replayed webhook cannot erase the data of a store that has since reinstalled. Neither record holds your store domain in readable form: it is replaced by a keyed hash, which still lets us answer "was this store purged, and when?" without keeping the name. Neither holds inventory, sales, revenue, settings, or any customer data. We keep them without a fixed expiry, as our record of compliance; you can ask us to erase them at support@getallocator.com.
- You can request deletion at any time at support@getallocator.com.
8. Contact
For any privacy question: support@getallocator.com
9. The one free-text field, and what we do with it
Everything Allocator reads from Shopify is aggregated by product variant, location and day: no customer name, email, address or payment information ever reaches us, and we do not request the Shopify scopes that would return one.
One field is different, because a human types into it: the optional note on an in-store restock request, on the store page and on the POS tile. It exists so a salesperson can say why they need the item — how often it was asked for, which size runs out first. The field asks explicitly for no customer names and no contact details, and before the note is stored Allocator removes email addresses, and any run of digits carrying the marks of a phone or reference number — an international prefix, a leading zero, an unbroken run of seven digits or more — replacing it with a marker. What remains is visible to your own head office inside the app, and is deleted with the rest of your data.
That stripping is a safety net, not a guarantee, and we would rather tell you where it stops than let you assume it is airtight. It cannot recognise a first name. It also deliberately leaves alone a number written in the same shape as a run of sizes — 12 34 56 78 90 is indistinguishable from 34 36 38 40 42, and we chose to keep your staff's size runs readable rather than shred them. If someone in your team writes a customer's identity into that field, it is stored as typed, on your instruction and under your responsibility as the data controller — and you can have it removed at support@getallocator.com.
Terms of Service · Data Processing Agreement · Data Deletion · All legal documents