Privacy Policy
Last updated: 3 September 2026
BuyAhead ("the app") helps Shopify merchants forecast inventory: when a product will run out, when to reorder, and how much to order. This page explains exactly what data the app reads, what it stores, and for how long.
What we read from your store
The app requests read-only access to four scopes: read_products, read_inventory, read_orders and read_locations. It never requests write access and cannot change anything in your store.
From orders, we read only three fields:
- the product variant that was sold,
- the quantity sold, and
- the date the order was processed.
What we do not read
We do not request, receive, or store any customer-identifying data. Our API queries do not include customer name, email address, phone number, shipping or billing address, IP address, or customer ID. These fields are absent from the queries themselves, not merely discarded after retrieval.
As a result, when Shopify sends us a customers/data_request or customers/redact notification, there is no customer data on our side to return or delete.
What we store, and why
Shopify gives apps only the last 60 days of order history. To produce reliable forecasts we keep our own record from the day you install: daily quantity sold per variant, a daily snapshot of stock levels, product and variant names, and your store settings (lead time, target stock days, service level). This is what allows the forecast to become more accurate the longer you use the app.
We also store your Shopify access token so the app can refresh your numbers once a day. It is encrypted at rest with AES-256-GCM; the encryption key is held outside the database.
How long we keep it
Store data is retained while the app is installed. When you uninstall, your access token is deleted immediately and the store is deactivated. Shopify then sends a shop/redact request (normally 48 hours later), at which point all remaining data for your store is permanently deleted.
Security
- All data is transmitted over HTTPS/TLS.
- Data is stored in an EU-region PostgreSQL database with encryption at rest.
- Access tokens are additionally encrypted by the app itself (AES-256-GCM), so a database copy alone does not expose them.
- The app holds read-only permissions and cannot modify your store.
Sharing
We do not sell data and we do not share it with third parties for advertising or any other purpose. Data is processed only by the infrastructure providers that run the app (hosting and database).
Contact
Questions about this policy or a request regarding your data: m.resat.yardimci04@gmail.com