Privacy
v2 · updated 18 September 2026
Shelfward runs inside your Shopify admin. It holds your suppliers, purchase orders, receipts, cost history and stocktakes, and it writes quantities and cost per item back to your store. It reads no orders and stores no shopper data.
Seller: WaveApp LLC
Checkout: Shopify
Contact: support@shelfward.app
Product domain: shelfward.app
Contact: support@shelfward.app (Cloudflare Email Routing to the WaveApp LLC mailbox, the same arrangement as every other WaveApp product).
1. What never happens
- Shelfward asks Shopify for products, inventory levels and locations. It does not request orders or customers, so no shopper name, email address, phone number or postal address reaches us.
- No third party receives your store's data for advertising, profiling or enrichment. We sell nothing to anyone.
- A supplier email carries only an allowlisted set of fields: your shop name and address, the ordered lines with quantities and agreed unit cost, your terms, the expected date and your note. Sale prices, on-hand quantities and another supplier's costs stay out of it.
- A printed label carries the product title, variant, price and barcode. Costs are never printed.
- The app creates no charge and never sees your card.
2. Data we touch
2.1 Your purchasing records
Data: suppliers and their contact details, product-supplier links, purchase orders and their lines, receipts, cost history, stocktakes and count lines, reorder thresholds, label templates and your settings.
Used to: raise and send purchase orders, receive deliveries, compute the new cost per item, print labels, run counts, and list what is short.
Basis: performing our contract with you.
Kept: until you delete it from Settings, or until the shop data is deleted after you uninstall (§4).
2.2 Your store's catalogue and inventory
Data: product titles, variants, barcodes, prices, inventory items with their cost, inventory levels per location, locations and collections.
Used to: build orders, price labels, compute variance at cost, and show what is on hand. The catalogue is cached for 10 minutes; levels are read live on the screens that show them.
Who holds it: your own Shopify store. Shelfward writes back on-hand quantities when you receive or apply a count, and cost per item after each receipt.
Basis: performing our contract with you, as your processor for this data.
Kept: the cache is replaced on the next read; the records above follow §2.1.
2.3 Who did what
Data: the Shopify staff id and display name of the staff members who use the app, whether that account can view product costs, and which account raised, received, counted or applied each record.
Used to: show your team who counted what and who received a delivery, and to hide cost columns from an account without Shopify's "View product costs" permission.
Basis: our legitimate interest in an auditable record of writes to your store.
Kept: with the record it belongs to, under §2.1.
2.4 Your Shopify connection
Data: the access token Shopify issues for your shop, and your shop domain, plan and trial dates.
Used to: read and write the data above, and to unlock the features your plan includes.
Protected: the token is encrypted before it is written, and the key is held outside the database.
Kept: until the shop data is deleted after you uninstall (§4).
2.5 The Stocky import
Data: the Stocky export file you upload. We read purchase orders, their lines and supplier names from it, and create the matching history in Shelfward.
Used to: give you back the purchase-order and cost history Stocky held. An imported order is history only; it writes nothing to your Shopify inventory.
What we record: the file name, the row counts, each skipped row with the reason it was skipped, and the column names, plus the shape of each column's values — a date written 05/02/2026 is recorded as ##/##/####, never the date itself.
Kept: the file is read once and discarded; only the imported rows and what we record above are kept: the file name, the row counts, the skipped rows with their reasons, the column names and the value shapes
2.6 What your suppliers receive
A supplier gets the purchase order as an email with a PDF, sent from orders@shelfward.app with your shop's address as the reply-to, so a reply goes to you. The fields are the allowlist in §1, and every send is recorded on the order timeline with the recipient. A supplier never signs in.
2.7 Email to us
Data: what you write to support@shelfward.app, your address, and anything you attach.
Used to: answer you and fix the problem.
Kept: 12 months after the thread closes.
3. Processors
- Shopify — the platform Shelfward runs inside. Your catalogue, your inventory and the billing for this app stay with Shopify under its own terms.
- Email delivery service — sends your purchase-order email to your supplier (United States).
- Hosting and security providers — run the app server and database, the network in front of them, and the routing for support@shelfward.app.
Nobody else receives data from Shelfward.
4. Where the data sits, how long, and how it is protected
Every request between Shelfward, Shopify and your browser uses TLS. Each call from your admin carries a Shopify session token that we verify. Webhooks from Shopify are checked against their signature and processed once.
The database runs on our server in the United States, reachable only from the app on that server.
Retention after you uninstall: your data stays until Shopify sends its deletion request, which arrives about 48 hours after you uninstall. Shelfward then waits a further 48 hours before deleting, so a store that reinstalls in that window keeps its records; a store that has not reinstalled is deleted about four days after the uninstall. If Shopify's request never arrives, a fail-safe deletes everything 30 days after the uninstall, and you can change that number in Settings while the app is installed.
Quantities and cost per item already written to your Shopify store stay there. Deleting Shelfward data does not reverse a write.
5. Your rights
You can export your Shelfward data as a zip of CSV files from Settings at any time, and you can delete every Shelfward row for your shop from the same screen after typing a confirmation. The export includes cost history on Plus and whenever your store has no active subscription; cost columns are left out for staff without Shopify's permission to view product costs.
If you are in the EU, the UK or another place with data-protection rights, you can ask us to show, correct, delete, restrict, export or stop using data about you. You can also complain to your local supervisory authority. Write to support@shelfward.app; we answer within one month.
Shelfward holds no shopper data. customers/data_request and customers/redact are answered with the fact that we hold none, and shop/redact deletes your shop's rows.
6. Children
Shelfward is a tool for Shopify merchants and is not directed at children. We do not knowingly request personal information from children.
7. Changes
This notice describes what the app does today. If a change affects the data we touch, we say so in the app before it takes effect.
8. Contact
support@shelfward.app — WaveApp LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA