Privacy Policy
Last updated: July 16, 2026
Replenly ("the app", "we", "us") is a Shopify app that helps merchants manage purchase orders and forecast when to reorder inventory. It is operated by an individual developer. This policy explains what data the app processes, why, and how it's protected.
What data we process
When a merchant installs Replenly, we process:
- Your store's domain and basic shop information.
- Your product and variant catalog: titles, SKUs, costs, and inventory levels.
- Supplier records you create in the app (supplier name, contact details, lead times, etc.).
- Purchase orders you create, edit, or send through the app.
- Aggregate order line-item data — variant ID, quantity, order date, and a pseudonymous order line identifier (the Shopify order ID and line item ID, with no customer data attached) — used to calculate sales velocity, generate reorder suggestions, and prevent double-counting a line item if its webhook is redelivered.
- Authentication and session data for the staff account that installs and uses the app (name, email, and Shopify user ID), stored so the embedded app can maintain your team's login session.
We do not collect, store, or process your customers' names, emails, phone numbers, shipping/billing addresses, or payment details. The order and order-line identifiers we retain exist only to compute how quickly a product sells and to deduplicate repeated webhook deliveries; they are never linked to who bought the item.
Why we process it
Every piece of data listed above is used for one purpose: inventory forecasting, reorder suggestions, and purchase-order management — the core function of the app. We do not use your data for advertising, we do not sell or share it with third parties, and we do not build profiles of your shoppers.
Storage and security
Data is stored in a managed PostgreSQL database. It's encrypted in transit (TLS) and at rest, and access is restricted to the systems that run the app. We don't grant broad third-party access to your shop data.
Service providers
We use a small number of infrastructure providers to run the app, each acting as a data processor on our behalf and bound by their own security and confidentiality obligations:
- Fly.io — hosts the application servers that run the app's web and background-job processes.
- Supabase — hosts the PostgreSQL database described above, where your shop's data is stored.
- Google (Gmail) — when you choose to email a purchase order to a supplier, we send it through Google's Gmail service as our email transport. That means the supplier's name and email address and the contents of the purchase order (including the PDF attachment) are disclosed to Google solely to deliver the message. Sent messages are retained in the sending mailbox in accordance with Google's own terms and retention practices until you or we delete them — that copy is not covered by the 48-hour deletion described below, which applies only to data stored in our own database.
None of these providers is given access to your data beyond what's necessary to host and run the app; we don't use any other third-party processor for your shop data.
Data retention
- Aggregate sales records (used for velocity calculations) older than 90 days are automatically deleted on a nightly schedule.
- If you uninstall Replenly, all of your shop's data — products, suppliers, purchase orders, and sales aggregates — is permanently deleted within 48 hours, triggered by Shopify's mandatory
shop/redact webhook. - You can request earlier deletion at any time by emailing vkundar@gmail.com.
Shopify GDPR compliance webhooks
Replenly implements Shopify's three mandatory webhooks:
- customers/data_request — we hold no customer personal data, so there is nothing to return.
- customers/redact — we hold no customer personal data, so there is nothing to delete.
- shop/redact — triggers a full, permanent purge of all data associated with the shop.
Billing
Subscription billing is handled entirely by Shopify's billing system. We never see or store your payment card details.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Continued use of the app after a change means you accept the updated policy.