Privacy Policy

Last updated: August 26, 2026

Reorderly is a Shopify app that helps merchants decide what to reorder and spot cash trapped in dead stock. This policy explains exactly what data we access from your store, what we store, and how you can have it deleted. In short: we never access your orders or customers, and we store no customer personal data.

At a glance

Who we are

Reorderly (“we”, “us”) is the data controller for the account data described below and a data processor for the store data we process on your behalf. For any privacy question, contact us at hello@datadir.co.

What data we access

Reorderly requests only the Shopify scopes it needs to do its job:

  • Products & variants (read_products) — titles, SKUs, variant IDs, and unit costs, to identify what you stock.
  • Inventory levels (read_inventory) — on-hand and available quantities per location, and their changes over time, to compute sales velocity and reorder points.
  • Locations (read_locations) — your location names and IDs, to report stock per location.

We do not request or receive access to orders, customers, checkout, or payment information. We hold no protected customer data as defined by Shopify.

What we store

  • Your store's .myshopify.com domain and an offline access token, so the app can sync in the background.
  • An inventory ledger we derive from inventory-level changes (per-variant stock movements over time).
  • Settings and records you create in the app: unit costs, reorder points, suppliers, purchase orders, currency, and VAT preferences.

None of this contains personal data about your customers.

How we use it

We use the data solely to provide the service to you — reorder suggestions, sales velocity, purchase-order drafts, and dead-stock / trapped-cash analysis. We do not sell your data, use it for advertising, or share it with third parties except the infrastructure providers below.

Sub-processors

  • Shopify — the platform your store and our app run on.
  • Hetzner Online GmbH (Germany, EU) — hosting and database.
  • Bunny.net — authoritative DNS for our domain.

Retention & deletion

When you uninstall the app, Shopify notifies us and we delete your access token immediately. About 48 hours after uninstall, Shopify sends a shop/redact request, and we erase all remaining data for your store — the ledger, settings, suppliers, and purchase orders. You can request deletion at any time by emailing hello@datadir.co. We also honor Shopify's customers/data_request and customers/redact webhooks; because we store no customer data, there is nothing for us to return or erase in response to them.

Security

Data is encrypted in transit (TLS). Access to production systems is restricted to the operator of the service. Access tokens are stored server-side and never exposed to the browser.

Your rights

If you are in the EEA/UK, you have the right to access, correct, export, or delete the data we hold, and to lodge a complaint with your supervisory authority. Our lawful basis for processing is the performance of our contract with you. To exercise any right, contact hello@datadir.co.

Changes to this policy

We may update this policy as the app evolves. Material changes will be posted here with a new “last updated” date.