Privacy Policy
Last updated: September 19, 2026
This Privacy Policy explains how Countloop Stock Take(“the App”, “we”, “us”) collects, uses, and protects data when a Shopify merchant installs the App to count and reconcile their store's inventory.
The App does not have any access to a store's customers. It only requests the read_inventory, write_inventory, read_locations, and read_products permissions from Shopify — there is no permission to read customer names, emails, addresses, or orders, and our database has no fields for them.
Who we are
Countloop Stock Take is developed and operated by MicroForge. You can contact us at support@microforgehq.com with any privacy question or request.
What we collect
When a merchant installs the App, we receive and store:
- the shop's domain and an access token that lets the App read and adjust inventory on the merchant's behalf
- the store's subscription/plan status, obtained from Shopify so we can operate the App and bill through Shopify App Pricing
While the merchant uses the App to run an inventory count, we also store:
- a snapshot of the counted products: variant ID, SKU, barcode, title, vendor, the collection it belongs to, cost, and the quantity breakdown Shopify reports (on hand, committed, reserved, damaged, safety stock, quality control)
- the quantities typed or scanned in during the count, when they were entered, and the count/adjustment made to Shopify's inventory as a result
- names the merchant types in to identify who is counting — for example the name of a staff member or a temporary helper the merchant invites with a link (helpers do not need a Shopify account or to install anything; the App does not verify these names against any account)
The links a merchant creates to invite a helper to count are stored only as a one-way cryptographic hash (the link itself is not stored), and a person who opens one of those links does not need to sign in.
To protect the invited-helper link pages against abuse (for example, automated requests), we also process the visitor's IP address to rate-limit requests. We do not store the IP address itself: we store only a one-way, salted cryptographic hash of it that cannot practically be reversed to recover the address.
If Shopify ever grants the App access to the name or email of the staff member who installs it (this happens only for “per-user” access, which the App does not currently request), that information would be stored in the same session record as the access token above.
Our role: processor for merchants, controller for our own account data
When a merchant installs the App, the merchant is the data controller for the inventory data and staff names collected through their store, and we act as a data processor on the merchant's behalf. For data about the merchant's own account (shop domain, plan, and billing status), we are the data controller.
Why we process this data
As a processor, we process inventory and staff-attribution data only to carry out what the merchant installed the App for — running an inventory count, detecting stock that moved during the count, writing the reconciled quantities back to Shopify, and showing the merchant who counted what. The legal basis for this processing is the merchant's instructions, under our contract with the merchant.
As a controller, we process the merchant's own account data (shop domain, plan, and billing status) to operate the App, provide support, and bill through Shopify App Pricing. The legal basis for this processing is the performance of our contract with the merchant and our legitimate interest in operating and securing the App.
How long we keep data
We have not yet finalized a fixed retention schedule for most of the data listed above. Here is what is true today:
- Your store's session (the access token, and the online-access fields described above if they are ever populated) is deleted when the store uninstalls the App.
- Rate-limiting counters (the hashed value described above, not the visitor's IP address) are meant to expire quickly — a few minutes to a few hours — but we do not yet run an automated job that removes expired rows, so in practice they may persist longer until that job is built.
- Inventory counts, the products snapshotted for them, staff and helper names, and differences found during a count are kept until the merchant deletes them by request, or until Shopify notifies us that the store has fully closed its account (see “Deleting data” below). Uninstalling the App by itself does not delete this data — we mark the store as uninstalled and keep the data until one of those two things happens.
- Webhook delivery records (used to avoid processing the same Shopify notification twice) are kept indefinitely at present; we have not yet set a fixed retention period for them.
Deleting data
- A merchant can email us at any time to request deletion of their store's data, and we will delete it.
- Uninstalling the App by itself does not delete previously stored data — it only stops the App from accessing your store. Your store's data is deleted automatically only when Shopify notifies us that the store has closed its account and asked for its data to be erased (the
shop/redactnotification below), or when you email us to request it sooner. - Because the App has no access to a store's customers, a
customers/redactorcustomers/data_requestrequest from Shopify never matches any data we hold — we record that we received the request, but there is nothing to delete or disclose. - When Shopify sends us a
shop/redactrequest (this happens when a store fully closes its account and Shopify asks every app that was installed to erase its data), we automatically delete every row of that store's inventory-count data — the snapshot of counted products, the quantities entered, staff and helper names, differences found, and the store's own account record — within the same request.
Sub-processors
We use the following service providers to operate the App. Each only receives the data it needs to perform its function:
- Shopify — the platform the App is built on; source of inventory, product, and shop data.
- Fly.io — hosts the App (region: United States, Virginia).
- Neon — hosts our Postgres database (United States).
All of the sub-processors above are located in the United States. Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses with each sub-processor.
Security
Data in transit to and from the App is encrypted with HTTPS/TLS. Our database is hosted by a managed provider that encrypts data at rest. Access to production data is limited to the people operating the App.
Cookies and tracking
The App runs embedded in the Shopify admin and does not set advertising or analytics cookies of its own.
Your rights
Depending on where you are located, you may have rights under GDPR, the UK GDPR, or similar laws to access, correct, or delete personal data we hold about you, or to object to certain processing. To exercise these rights, email support@microforgehq.com. If you are a shop's staff member or a helper whose name was entered into the App by a merchant, please also contact that merchant directly, since they control that data.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date above when we do.