DocToStock

Privacy Policy

Last updated: April 5, 2026

Information We Collect

When you install DocToStock, we collect the data necessary to provide the service:

  • Shopify OAuth session data — your shop domain and access token, stored encrypted in PostgreSQL (via Prisma). We use this to authenticate requests on your behalf to the Shopify Admin API.
  • Usage data — documents you upload, processing results, and usage tracking data. This data is used solely to operate and improve the service.

How We Use Your Data

We use the data we collect to:

  • Process your uploaded documents using the OpenAI API to extract product and inventory data.
  • Sync extracted inventory data to your Shopify store via the Shopify Admin API.
  • Track your monthly document usage in the app's Billing & Usage dashboard.
  • Provide customer support and respond to your inquiries.
  • Maintain, secure, and improve the DocToStock service.

We do not sell your personal data to third parties, and we do not use your data to train AI models.

Document Storage

Documents you upload are stored in isolated per-tenant AWS S3 buckets. No cross-tenant data access is permitted — your documents are never accessible to other merchants. AWS S3 server-side encryption is enabled for all stored objects.

When you uninstall DocToStock, all your documents and associated data are scheduled for deletion. The SHOP_REDACT webhook, required by Shopify, triggers automatic deletion of all your shop data within 30 days of uninstallation.

Third-Party Services

DocToStock relies on the following third-party services to operate:

  • OpenAI — document text is sent to the OpenAI API for extraction. OpenAI may retain API inputs for a period per their data retention policy. See the OpenAI Privacy Policy.
  • Shopify — store data and app session management are handled through the Shopify platform. See the Shopify Privacy Policy.
  • Amazon Web Services (AWS) — document files are stored in AWS S3 with server-side encryption and per-tenant bucket isolation.
  • Google Analytics 4 (GA4) — on our public marketing pages (doctostock.com), we use Google Analytics 4 to collect anonymous usage statistics with your explicit consent. See "Analytics and Cookies" below for details and how to withdraw consent.

Analytics and Cookies

On our public marketing pages, we use Google Analytics 4 (GA4) to collect anonymous usage statistics — such as pageviews and which sections of the site visitors engage with — so we can understand and improve the public site experience.

GA4 is only activated after you explicitly click "Accept cookies" on our consent banner. Once active, GA4 sets first-party cookies (for example _ga and _ga_<container-id>) to distinguish anonymous sessions. We do not use Google Analytics to identify you personally, and no personal data is shared with Google Analytics beyond anonymized usage events.

You can withdraw your analytics consent at any time. Resetting your cookie settings clears your stored consent decision, stops Google Analytics from running on this device, and shows the cookie consent banner again the next time you visit.

Data Retention and Deletion

We retain your data for as long as your store has an active DocToStock installation. When you uninstall DocToStock from your Shopify store, a SHOP_REDACT webhook automatically triggers deletion of all your shop data within 30 days.

You may request immediate deletion of your data at any time by contacting us at [email protected].

GDPR Rights (EU/UK Residents)

If you are located in the European Union or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate personal data.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to restriction of processing — request that we restrict how we use your data.
  • Right to data portability — request your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

CCPA Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:

  • Right to know — the categories and specific pieces of personal information we collect about you.
  • Right to delete — request deletion of your personal information, subject to certain exceptions.
  • Right to opt out of sale — we do not sell personal information to third parties, so this right is not applicable. However, you may contact us to confirm.

To submit a CCPA request, contact us at [email protected].

Security

We take reasonable technical and organizational measures to protect your data:

  • All data in transit is encrypted using TLS (HTTPS).
  • Shopify access tokens are stored encrypted in our PostgreSQL database.
  • AWS S3 objects are encrypted at rest using server-side encryption.
  • Access to production systems is restricted to authorized personnel.

No system is perfectly secure. If you discover a security issue, please report it to [email protected].

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact:

MB ŠOPITEKA
[email protected]

We use cookies to understand how visitors use our site. No personal data is shared until you accept.