Privacy Policy
Last updated: September 20, 2026 · Applies to the Shopify app “njX Stock Alerts & Reorder” by njX
Who we are
njX Stock Alerts & Reorder is operated by njX, an independent developer. Contact: [email protected].
What the app does
It reads your products, stock levels and recent sales, works out how many days of stock are left and how much to reorder, and sends you a reorder list and stock alerts by e-mail, to Slack or to Discord. Access is read-only: the app cannot change products, stock, prices or orders.
Data we read and store
- Products and variants: title, SKU, vendor, tags, status, price, cost per item, whether stock is tracked.
- Stock levels by location, and the names of your locations.
- Sales: from orders we keep only the line items — which variant, how many units, what they sold for, whether a discount applied — added up per product per day. Returns and refunds are kept as “variant, units, date”.
- Settings and recipients: your warning lines and lead times; the e-mail addresses, Slack channels and Discord webhook URLs you add (e-mail addresses, Slack bot tokens and webhook URLs are stored encrypted and shown masked).
- Logs: which report went where and when (without its content), and messages you send through the support form.
We do not store anything about your customers. Order webhooks are reduced to “variant + quantity + amount” before they are even queued: names, e-mails, phone numbers, addresses and notes are dropped and never reach our database. Shopify requires apps that receive order data to declare protected-customer-data access; we use it for this single purpose and request no customer fields.
How your numbers are used
- Your shop’s numbers are used for your shop only: to build your lists, alerts and the app’s own accuracy check.
- They are never sold or shared, and never used to train machine-learning or AI models, or to improve forecasts for other stores, unless you explicitly switch that on. There is no such switch today; if one is added it will be off by default, described in plain words, and reversible at any time.
- The test results we publish come from an open dataset (Online Retail, UCI Machine Learning Repository, CC BY 4.0), not from merchants’ stores.
Where data is processed
- Cloudflare (Workers, D1, Queues) runs the app and stores its database. E-mail is sent through Cloudflare Email Service; a backup provider (Resend) may deliver a message when the first one is unavailable.
- Slack (Slack Technologies, LLC, a Salesforce company) and Discord (Discord Inc.) deliver messages to the channels you connect. Delivered messages live there under their own privacy policies.
- Shopify handles billing; we never see payment details.
Retention
- Units sold per product per day: 90 days. Weekly totals per product (units and revenue): kept while the app is installed, so that your own seasonality builds up.
- Restock events: 13 months. Return events: 200 days. Delivery logs: 90 days. Processed-webhook ids: 7 days.
- When you uninstall the app, or when Shopify sends a
shop/redactrequest, all data for your store is deleted within 48 hours and Slack bot tokens are revoked. - Customer data requests and customer redaction requests from Shopify are acknowledged automatically: we hold no customer names, e-mails or addresses, so there is nothing to return or erase.
E-mail recipients
An address you add receives nothing until its owner clicks the confirmation link. Every message carries a one-click unsubscribe. Addresses are used only for the reports and alerts of your store.
Security
All traffic is encrypted in transit (TLS). Stored data and its backups are encrypted at rest by Cloudflare (D1); e-mail addresses, Slack bot tokens and Discord webhook URLs are additionally encrypted with a separate key (AES-256-GCM). Links in e-mails are signed and expire. Test and production data are separated. Only the operator has access to production; the Cloudflare, GitHub and Shopify Partner accounts require strong passwords and two-factor authentication, and every access is recorded in Cloudflare’s audit log.
Incident response
- Detection. Errors, failed deliveries and health checks are monitored around the clock by an internal alerting bot.
- Containment. On a suspected breach we revoke the affected access tokens, rotate secrets and, if needed, pause deliveries until the cause is fixed.
- Notification. Affected merchants are notified by e-mail within 72 hours of confirming an incident; Shopify is informed through the Partner channels.
- Review. Every incident ends with a written post-mortem and a change that prevents the same failure.
Your responsibilities
You decide who receives the lists. Anyone in a connected channel or mailbox sees your products, stock and suggested order quantities. A live Google Sheet link can be read by anyone who has it — share the sheet, not the link, and make a new link in the app if it leaks.
Contact
Questions or GDPR requests: [email protected], or the support form.