Legal

Privacy Policy

Last updated: 14 June 2026

Data controller: Malik Systems Ltd t/a Replenishly · Company No. 17265815 · Registered in England & Wales · ICO Registration No. ZC168374
Contact: privacy@replenishly.co.uk

1. Who we are

Replenishly is a Shopify application operated by Malik Systems Ltd t/a Replenishly ("we", "us", "our"), a company registered in England and Wales (Company No. 17265815) and registered with the UK Information Commissioner's Office (ICO Reg. No. ZC168374).

This Privacy Policy explains how we collect, use, store, and protect information about merchants who install and use the Replenishly Shopify application ("the App"), in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

2. What data we collect and why

Replenishly collects only the minimum data necessary to provide its purchase order automation service.

Data Purpose Legal basis
Shopify shop domain Identify the merchant account Contract performance
Shopify access token Query Shopify API on the merchant's behalf Contract performance
Merchant reorder settings Threshold, buffer %, cooldown, lead time, auto-trigger preferences Contract performance
Factory/supplier records Name, email, column mapping, MOQ settings per factory Contract performance
PO draft data Line items (SKU, title, qty), status, timestamps Contract performance
Inventory audit logs Per-PO received quantities for audit trail Legitimate interest (operational record-keeping)
Support requests Message content, type, optional contact email Contract performance / Legitimate interest
Shopify product/inventory data Fetched transiently from Shopify to generate POs, not persisted beyond the draft Contract performance

Replenishly does not collect customer data (names, addresses, order history, payment information). The App accesses only inventory and product data via read-only Shopify API scopes, except where write_inventory is used to commit stock adjustments on the merchant's explicit instruction.

3. Shopify API scopes

Replenishly requests the following OAuth scopes:

  • read_products: read product and variant details to build PO line items
  • read_inventory: read current inventory levels to detect low stock
  • write_inventory: adjust inventory quantities when the merchant commits a received delivery (inventoryAdjustQuantities mutation)
  • read_locations: list active Shopify locations for the receiving location selector

No other scopes are requested. We do not access customer data, orders, payments, or any other Shopify resource outside the above list.

4. How we store your data

All persistent data is stored in a Neon Serverless PostgreSQL database hosted in the United States (AWS us-east-1 region) via Neon's cloud platform. All data is encrypted in transit (TLS 1.2+) and at rest.

The Replenishly API runs on Cloudflare Workers. All request processing happens at the Cloudflare edge. Data is not written to Cloudflare's KV or Durable Objects: it flows transiently through the edge to Neon.

Transatlantic data transfers to Neon (USA) are covered by standard contractual clauses (SCCs) under UK GDPR Article 46.

5. Data retention

  • Active merchants: Data is retained for as long as the Replenishly subscription is active.
  • After cancellation: Merchant data (settings, factories, PO drafts, audit logs) is retained for 30 days after the subscription ends, then deleted.
  • Support requests: Retained for 12 months, then deleted.
  • Access tokens: Deleted immediately on receiving a Shopify shop/redact webhook or upon merchant request.

6. Third-party processors

Processor Role Data shared
Neon (Neon Inc.) Database hosting All persistent data listed in §2
Cloudflare Inc. Edge compute & CDN Request metadata (transient); no persistent storage
Resend (Resend Inc.) Email delivery Factory email addresses; PO content for dispatch emails
Shopify Inc. Platform & billing OAuth token exchange; billing managed by Shopify

We do not sell, rent, or share your data with any third parties for marketing purposes.

7. Your rights under UK GDPR

As a data subject, you have the following rights:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure: request deletion of your data (subject to legal retention obligations).
  • Right to restriction: request that we restrict processing of your data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest.

To exercise any of these rights, contact us at privacy@replenishly.co.uk. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. GDPR compliance & data deletion endpoints

Replenishly implements the mandatory Shopify GDPR webhooks:

  • POST /api/gdpr/customers/data_request: returns all customer-linked data (none held)
  • POST /api/gdpr/customers/redact: erases any customer-linked data
  • POST /api/gdpr/shop/redact: permanently deletes all merchant data 48 hours after shop closure

All webhook payloads are HMAC-verified before processing.

9. Cookies and tracking

The Replenishly dashboard (app.replenishly.co.uk) does not use cookies for tracking or analytics. No third-party analytics scripts are loaded. The only browser storage used is localStorage to remember dashboard preferences (e.g. auto/manual mode toggle), and this data never leaves your browser.

This marketing website (replenishly.co.uk) uses Google Analytics 4 to understand which pages are useful, and only after you accept it. Decline and no analytics script is loaded and no analytics cookies are set. Your choice is stored in localStorage on your own device; clear your site data to be asked again. IP addresses are anonymised, and we never send Google any personal data about you or your store.

10. Security

We implement appropriate technical and organisational measures to protect your data:

  • All API traffic is encrypted via TLS 1.2+
  • Shopify webhook payloads are verified with HMAC-SHA256 before processing
  • Database access tokens are stored as Cloudflare Worker secrets, never committed to source control
  • Access tokens are stored encrypted in Neon; never logged or exposed in API responses

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.

12. Contact us

For privacy-related queries, contact:

Malik Systems Ltd t/a Replenishly

Company No. 17265815 · ICO Reg. ZC168374

Email: privacy@replenishly.co.uk