Legal
Privacy Policy
Last updated: 14 June 2026
Contact: privacy@replenishly.co.uk
1. Who we are
Replenishly is a Shopify application operated by Malik Systems Ltd t/a Replenishly ("we", "us", "our"), a company registered in England and Wales (Company No. 17265815) and registered with the UK Information Commissioner's Office (ICO Reg. No. ZC168374).
This Privacy Policy explains how we collect, use, store, and protect information about merchants who install and use the Replenishly Shopify application ("the App"), in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
2. What data we collect and why
Replenishly collects only the minimum data necessary to provide its purchase order automation service.
| Data | Purpose | Legal basis |
|---|---|---|
| Shopify shop domain | Identify the merchant account | Contract performance |
| Shopify access token | Query Shopify API on the merchant's behalf | Contract performance |
| Merchant reorder settings | Threshold, buffer %, cooldown, lead time, auto-trigger preferences | Contract performance |
| Factory/supplier records | Name, email, column mapping, MOQ settings per factory | Contract performance |
| PO draft data | Line items (SKU, title, qty), status, timestamps | Contract performance |
| Inventory audit logs | Per-PO received quantities for audit trail | Legitimate interest (operational record-keeping) |
| Support requests | Message content, type, optional contact email | Contract performance / Legitimate interest |
| Shopify product/inventory data | Fetched transiently from Shopify to generate POs, not persisted beyond the draft | Contract performance |
Replenishly does not collect customer data (names, addresses, order history, payment information). The App accesses only inventory and product data via read-only Shopify API scopes, except where write_inventory is used to commit stock adjustments on the merchant's explicit instruction.
3. Shopify API scopes
Replenishly requests the following OAuth scopes:
read_products: read product and variant details to build PO line itemsread_inventory: read current inventory levels to detect low stockwrite_inventory: adjust inventory quantities when the merchant commits a received delivery (inventoryAdjustQuantities mutation)read_locations: list active Shopify locations for the receiving location selector
No other scopes are requested. We do not access customer data, orders, payments, or any other Shopify resource outside the above list.
4. How we store your data
All persistent data is stored in a Neon Serverless PostgreSQL database hosted in the United States (AWS us-east-1 region) via Neon's cloud platform. All data is encrypted in transit (TLS 1.2+) and at rest.
The Replenishly API runs on Cloudflare Workers. All request processing happens at the Cloudflare edge. Data is not written to Cloudflare's KV or Durable Objects: it flows transiently through the edge to Neon.
Transatlantic data transfers to Neon (USA) are covered by standard contractual clauses (SCCs) under UK GDPR Article 46.
5. Data retention
- Active merchants: Data is retained for as long as the Replenishly subscription is active.
- After cancellation: Merchant data (settings, factories, PO drafts, audit logs) is retained for 30 days after the subscription ends, then deleted.
- Support requests: Retained for 12 months, then deleted.
- Access tokens: Deleted immediately on receiving a Shopify
shop/redactwebhook or upon merchant request.
6. Third-party processors
| Processor | Role | Data shared |
|---|---|---|
| Neon (Neon Inc.) | Database hosting | All persistent data listed in §2 |
| Cloudflare Inc. | Edge compute & CDN | Request metadata (transient); no persistent storage |
| Resend (Resend Inc.) | Email delivery | Factory email addresses; PO content for dispatch emails |
| Shopify Inc. | Platform & billing | OAuth token exchange; billing managed by Shopify |
We do not sell, rent, or share your data with any third parties for marketing purposes.
7. Your rights under UK GDPR
As a data subject, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your data (subject to legal retention obligations).
- Right to restriction: request that we restrict processing of your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
To exercise any of these rights, contact us at privacy@replenishly.co.uk. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. GDPR compliance & data deletion endpoints
Replenishly implements the mandatory Shopify GDPR webhooks:
POST /api/gdpr/customers/data_request: returns all customer-linked data (none held)POST /api/gdpr/customers/redact: erases any customer-linked dataPOST /api/gdpr/shop/redact: permanently deletes all merchant data 48 hours after shop closure
All webhook payloads are HMAC-verified before processing.
9. Cookies and tracking
The Replenishly dashboard (app.replenishly.co.uk) does not use cookies for tracking or analytics. No third-party analytics scripts are loaded. The only browser storage used is localStorage to remember dashboard preferences (e.g. auto/manual mode toggle), and this data never leaves your browser.
This marketing website (replenishly.co.uk) uses Google Analytics 4 to understand which pages are useful, and only after you accept it. Decline and no analytics script is loaded and no analytics cookies are set. Your choice is stored in localStorage on your own device; clear your site data to be asked again. IP addresses are anonymised, and we never send Google any personal data about you or your store.
10. Security
We implement appropriate technical and organisational measures to protect your data:
- All API traffic is encrypted via TLS 1.2+
- Shopify webhook payloads are verified with HMAC-SHA256 before processing
- Database access tokens are stored as Cloudflare Worker secrets, never committed to source control
- Access tokens are stored encrypted in Neon; never logged or exposed in API responses
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.
12. Contact us
For privacy-related queries, contact:
Malik Systems Ltd t/a Replenishly
Company No. 17265815 · ICO Reg. ZC168374
Email: privacy@replenishly.co.uk