Stockroom

Privacy policy

Last updated: August 20, 2026

This policy describes how MyWorks ("we", "us") collects, uses and protects information when you use the Stockroom app for Shopify, the Stockroom Network, or this website, stockroom.app. The short version, which the rest of this page spells out:

  • We never sell your data. To anyone, for anything.
  • Your business data is shared with exactly two kinds of recipients: the service providers that run the app (hosting, email delivery and similar), and - only with your explicit consent - suppliers you choose to connect with through Stockroom Network. A connected supplier receives only the purchase orders you send them - including where to ship them - and nothing else.
  • Uninstalling the app removes our access immediately, and your operational data is deleted shortly after.

1. Information we collect

Store information. When you install the app, Shopify provides your store's name, myshopify domain, and contact email, and we store the access credential that lets the app work with your store (encrypted, always).

Catalog and inventory data from Shopify. The app reads your products, variants, locations and inventory levels - the data its features work on - and keeps a copy so the app is fast and doesn't call Shopify for every screen. Sales figures used in reports are stored as daily totals per product.

Data you put into the app. Suppliers and their contact details, purchase orders, costs, receipts, stocktakes, notes, settings, and files you attach to purchase orders.

Usage and diagnostic data. Which features are used and how (product analytics tied to your store, not to individuals), error and crash reports, and standard server logs.

Support conversations. If you contact support, we keep the conversation so we can help you over time.

Your customers' personal information: we don't collect it, apart from two things you choose. Stockroom's features work on products, inventory and purchase orders. The app does read your orders - that's how it works out how fast products sell and how it builds a purchase order from an order - but the fields it asks for are line items, quantities, prices, the location an order was routed to, and dates. Not your customers' names, emails, addresses or phone numbers. Sales figures are stored as daily totals per product, so nothing customer-level is kept.

The two exceptions happen only when you choose them, order by order:

  • Drop-shipping a purchase order. If you create a purchase order from a Shopify order and choose to have your supplier ship direct to the customer, the app reads that order's shipping address - name, company, address and phone - and stores it on that purchase order as the ship-to. It prints on the purchase order your supplier receives, and it crosses a Stockroom Network connection as described in section 4. Choosing your own store address instead reads nothing.
  • Inviting a customer to Stockroom Network. If you use the "Invite to Stockroom" link on a customer's page in Shopify, the app reads that customer's name and email to fill in the invitation, and stores them with the invitation you send. You're asked for this permission the first time you use the link; declining it just means typing the details in yourself.

Shopify's installation screen describes what a permission can reach, not what an app reads. Because an order record contains the customer who placed it, permission to read orders is classified as access to customer personal information, and the screen says so whether or not an app uses those fields. What Stockroom actually reads and stores is what's described above.

This website is a static site with no accounts and no forms. It uses Google Analytics to count visits and see which pages people read; that sets a first-party cookie so we can tell one visit from another. Google Signals and ad personalisation are turned off, so the site still sets no advertising or cross-site tracking cookies. This is the marketing site only - your store's data isn't involved.

2. How we use information

  • To provide and operate the service - the app's features are the use.
  • To send email you've asked the app to send, such as purchase orders to your suppliers and scheduled reports to you.
  • To answer support requests and notify you about the service.
  • To understand how features are used, fix problems, and improve the app.
  • To keep the service secure and prevent abuse.

3. What we never do

  • We never sell your data.
  • We never share it with advertisers or data brokers.
  • We never share one store's business data with another store - except through a Stockroom Network connection you explicitly consented to, scoped exactly as described below.

4. Stockroom Network: sharing you control

Stockroom Network connects two Shopify stores that both use Stockroom - a buyer and their supplier - so purchase orders can cross directly instead of traveling as a PDF, and a supplier can publish a product catalog and price list to their connected buyers. Nothing crosses until both sides have explicitly consented: the buyer when sending the invitation, the supplier when accepting it. The consent screen states exactly what will be shared, and an old consent never silently covers new data - a new flow on an existing connection stays off until the side that owns the data explicitly turns it on (for the shared catalog, that is the supplier's own act of publishing, and the buyer's acceptance of prices - described below).

What crosses (buyer to supplier): the purchase orders the buyer sends that supplier - line items, quantities, the buyer's costs on those orders, requested dates, and the order's ship-to address (the buyer's own location; or, when the buyer chooses to dropship an order, their customer's name, shipping address, and phone - the same delivery block that prints on the emailed purchase order PDF) - and the buyer's business contact details (store name and contact email) so the supplier can set them up as a customer.

What crosses (supplier to buyer): if the supplier chooses to publish a shared catalog, the product details they explicitly select - name, variant, SKU and, per the supplier's own sharing switches, images, barcode, and pack and ordering details - plus the wholesale price list the supplier assigns to that buyer's connection. Publishing is per-product, revocable at any time, and nothing is published until the supplier shares it. Published prices enter the buyer's records only under the buyer's approval policy, which defaults to asking every time.

What never crosses: the buyer's sales and stock levels, the buyer's other suppliers and their prices, the buyer's retail prices and margins, customer data beyond the dropship ship-to the buyer explicitly chose to include; and the supplier's own costs, stock numbers, and other buyers - a buyer never sees what any other buyer pays. Purchase orders are shared only with the supplier they're addressed to, and a supplier's published catalog only with the buyers they're connected to - never with anyone else on the network.

Disconnecting: either side can disconnect at any time, immediately and unilaterally. Disconnecting stops anything new from crossing - purchase orders, catalog, and price updates alike. It doesn't retract what already crossed - orders in the supplier's store, records on the buyer's purchase orders, and prices the buyer accepted stay where they are, because they're that side's business records.

5. Information we receive from third parties

To power the app's "likely on Shopify" hints, we license a directory of Shopify store domains compiled from publicly available information. It contains store domains only - no private data about you or your suppliers - and it's matched against supplier email domains inside the app; nothing about your suppliers is sent out to build it.

6. Data retention and deletion

We keep your data for as long as the app is installed. When you uninstall, our access credential for your store is invalidated immediately. Shortly after (about 48 hours, via Shopify's standard redaction request), your operational data - suppliers, purchase orders, receipts, stocktakes, settings, uploaded files - is deleted.

We retain a minimal business record after deletion: your store's name, domain, install and uninstall dates, and an aggregate order-volume figure. This is kept as an ordinary business record; if you reinstall later, the app starts fresh.

7. Your rights

Depending on where you are, you may have rights to access, correct, export, delete or restrict the processing of your personal information (under laws such as the GDPR or CCPA/CPRA). Because you reach Stockroom through Shopify, data requests made through Shopify's standard privacy tooling reach us automatically and are honored. You can also contact us directly atsupport@stockroom.app - we don't discriminate against anyone for exercising their rights.

8. Security

Data is encrypted in transit (TLS) and at rest. Store access credentials are additionally encrypted at the application level and never appear in logs or API responses. Uploaded files live in private storage accessible only to your store. The app requests the minimum Shopify permissions its features need, and every store's data is isolated from every other store's.

9. International transfers

The service is hosted in the United States. If you use it from elsewhere, your data is processed in the United States under this policy.

10. Children

The service is for businesses and isn't directed to children. We don't knowingly collect personal information from anyone under 16.

11. Changes to this policy

We may update this policy from time to time. When we do, we'll update the date at the top of this page, and for material changes we'll take reasonable steps to notify you - for example, a notice in the app. A material change to what crosses a Stockroom Network connection always requires fresh consent, not just an updated policy.

12. Contact

Questions about privacy or this policy:support@stockroom.app.