Restockio

Privacy Policy

Last updated: 10 July 2026

Restockio (“the app”, “we”, “us”) is a purchase-order and inventory replenishment application for Shopify, operated by Talivio Technology OÜ (Estonian commercial register no. 16991406), Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia. This policy explains what data the app accesses, how it is used, and the choices available to you. Use of the app is also governed by our Terms of Service.

Information we access

When you install Restockio on your Shopify store, the app is granted the following access through the Shopify Admin API:

Restockio does not request or access your customers’ personal information. The app operates entirely on product, inventory, and purchasing data.

Information you create in the app

As you use Restockio, you create and store records such as purchase orders, suppliers, supplier contact details, reorder points, and received-stock history. This data is stored securely and is scoped to your store only.

Supplier contact details — our role as processor

Supplier records you enter may include personal data of individuals at your suppliers (for example a contact name, email address, or phone number). For this data you (the merchant) are the data controller and we act as your data processor: we store and display it on your behalf, only on your instructions, and only to provide the app’s features. It is your responsibility to ensure you may lawfully share such supplier contact details with a service provider like us. We do not use supplier contact data for our own purposes and we delete it together with the rest of your store’s data as described below.

For your own account data (your shop domain, store details, and your use of the app), Talivio Technology OÜ is the data controller.

We will, on request, enter into a GDPR Article 28 data processing agreement with business customers governing our processing of supplier contact data on your behalf; our standard DPA is available at [email protected].

How we use information and legal bases

We use the information described above solely to provide and operate the app’s features — creating and receiving purchase orders, managing suppliers, and generating low-stock reorder alerts. We do not sell your data, and we do not use it for advertising.

Where the GDPR applies, we rely on the following legal bases under Article 6(1) GDPR:

Supplier contact details are processed on your documented instructions as your processor, as described above.

Data sharing and recipients

Processors (act on our behalf). We do not share your data with third parties except trusted infrastructure providers that host and run the service on our instructions — our EU-based hosting provider, our EU-based transactional email infrastructure, and Cloudflare, which provides content delivery and security in front of the service — and only to the extent necessary to operate the app. These providers act as our sub-processors and are bound by data-processing agreements (including the EU Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework commitments for any processing outside the EEA), confidentiality, and data-protection obligations.

Independent controllers (act on their own account). Shopify Inc. operates the platform on which the app runs and is an independent data controller for the store and merchant data it holds; its processing is governed by Shopify’s own privacy policy, not by this policy. Billing for the app is handled entirely through Shopify’s billing system; we do not operate our own payment processor, we do not use Stripe, and we never receive or store your card or bank details.

We do not sell or rent personal data.

Data retention and deletion

Your data is retained for as long as the app is installed on your store. When you uninstall the app, Shopify sends us its mandatory privacy webhooks (customers/data_request, customers/redact, and shop/redact — the shop-redact request arrives 48 hours after uninstallation). We act on the shop-redact request by deleting the data associated with your store — purchase orders, suppliers, reorder points, and received-stock history — within 30 days of receiving it. Because Restockio does not access customer personal data, customer data requests and redaction requests are acknowledged with a confirmation that we hold no such data.

Residual copies in encrypted backups are overwritten within a further 30 days by ordinary backup rotation. In every case your personal data is deleted or anonymised within 90 days of account closure at the latest, unless a longer statutory retention period applies. Invoicing and accounting records are kept for 7 years from the end of the financial year as required by the Estonian Accounting Act (a statutory exception to erasure under Article 17(3)(b) GDPR). You may also request deletion at any time by contacting us.

Your rights

Where the GDPR applies, you have the right to access, rectify, erase, and export (data portability) the personal data we hold about you, to restrict or object to its processing, and to withdraw consent where processing is based on consent. To exercise any of these rights, email us at the address below; we will respond within one month. You also have the right to lodge a complaint with a supervisory authority — for us that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), but you may also contact the authority in your own country. For supplier contact data we process on your behalf, we will forward requests from your suppliers’ personnel to you as the controller.

Cookies

Restockio uses only essential first-party cookies: a session cookie that keeps you signed in inside the Shopify admin and remembers your language choice, and a CSRF cookie that protects forms against abuse. We do not use analytics, advertising, or any third-party cookies, and we do not track you across other sites.

International transfers

Your data is stored on servers located in the European Union. Traffic to the service passes through Cloudflare’s network, which may route it through points of presence outside the EU/EEA; such transfers are covered by Cloudflare’s Standard Contractual Clauses and Data Privacy Framework commitments. Data you submit through Shopify is also handled by Shopify under its own privacy policy.

Security

We use industry-standard measures, including encrypted connections (HTTPS) and access controls, to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

Contact

If you have any questions about this policy or your data, contact us at [email protected].