1. Who we are
StockReclaim is operated by Gandhi Polymers, a sole proprietorship registered in India (proprietor: Ankita Bhandiya), trading as StockReclaim. In this policy "we", "us" and "our" mean Gandhi Polymers. "Jevian Labs" is the development name you may see in the Shopify Partner directory; it refers to the same business.
You can reach us about anything in this policy at support@stockreclaim.com.
2. What this policy covers
This policy applies to:
- the StockReclaim app installed from the Shopify App Store into a merchant's Shopify admin (the "App");
- this website, stockreclaim.com (the "Site"), including the help centre, blog, changelog, support and feature-request pages;
- the emails the App sends on a merchant's behalf (the weekly digest, the monthly reconciliation packet, product announcements and support replies).
It does not cover Shopify itself. Shopify's handling of your store and your customers' data is governed by Shopify's privacy policy.
3. The short version
- The App reads your refunds and returns live from Shopify to find stock that never came back. It does not copy your products, orders, refunds or inventory into our systems.
- We do not request, receive or store your customers' names, email addresses, phone numbers or addresses.
- We keep only what the App needs to work: a rebuildable cache of your last scan, the decisions you make on exceptions, the settings you enter, and the messages you send us.
- When you uninstall, everything we hold for your store is deleted and the deletion is verified.
- We do not sell data, run advertising, or use analytics cookies on this Site.
4. Information we collect
4.1 From Shopify, when you install the App
- Store identity — your store's
myshopify.comdomain, timezone and currency, and the date you installed. - Access token — the credential Shopify issues so the App can read your store. It is encrypted at rest and used only to make the API calls described below.
- Installing user details — where Shopify passes them during installation, the name and email address of the staff account that installed the App. We use these only to identify the installation and to answer support requests.
4.2 Store data the App reads to run the audit
With the permissions you grant at install (read_products,
read_inventory, read_locations, read_orders,
read_returns and write_inventory), the App reads:
- orders from the last 60 days (or a longer window if Shopify has granted the App access to older orders), including their refunds, refund line items and whether each refunded item was marked for restock;
- returns and their dispositions (for example restocked, not restocked, missing);
- products and variants (title and SKU), inventory levels and locations.
This data is read during a scan and used to compute your figure. It is not retained, with the specific exceptions in §4.3.
StockReclaim is declared to Shopify for store management use and requests none of Shopify's optional protected customer fields. Shopify therefore does not provide your customers' names, email addresses, phone numbers or addresses to the App, and we do not store them.
4.3 What the App stores for your store
- Scan cache — the result of your most recent scan: order numbers, SKUs, product titles, quantities, amounts, the cause assigned to each case and its age. Kept so the dashboard loads instantly; rebuilt on every scan; deleted on uninstall.
- Restock claims and last-seen inventory levels — for the "restock recorded, stock unchanged" check: the order number, SKU, product title, refund reference, quantity and amount of each claimed restock, and the last inventory level seen per item and location. No inventory history and no copy of your catalogue is kept.
- Your decisions — each case you mark resolved, write off or restock, with the order number, SKU, amount, the date and any note you type.
- Settings — age thresholds, the locations you include, whether the weekly digest and monthly packet are enabled, the day they send, and the email addresses you enter as recipients (for example your bookkeeper's).
- Plan and lifecycle — which plan your store is on, install and uninstall dates, and a de-duplication log of the webhooks Shopify has sent us.
4.4 Support tickets and feature requests
When you open a support ticket in the App we store the subject, your messages, our replies and any screenshots you attach. When you submit a feature request in the App or on the Site we store the title, description, category and the email address you optionally provide. Support tickets are linked to your store; a feature request from the Site is linked only to the email you give, if any.
4.5 The Site
The Site is static. It sets no cookies and uses no analytics or tracking scripts. Our hosting provider records standard server logs (IP address, requested page, browser type, timestamp) for security and capacity purposes.
4.6 Technical and operational data
- Application logs — request metadata, timestamps and your store domain, used to operate and debug the App.
- Error reports — when something fails, an error report is sent to our monitoring service with the store domain and technical context. Personal identifiers are disabled in that reporting.
- Internal notifications — new installs, uninstalls and new support tickets generate a short internal notice to the founder (store domain and ticket subject) so we can respond quickly.
5. How we use information
- to run the audit, show you the results and let you act on them (the App's core function);
- to send the emails you enable — the weekly digest and the monthly reconciliation packet — to the recipients you specify;
- to tell you about material changes to the App or these terms (in-app announcement and, where appropriate, email);
- to answer support requests and consider feature requests;
- to keep the App secure, prevent abuse, and meet our obligations to Shopify;
- to understand, in aggregate and without identifying stores, how the App is used so we can improve it.
We do not sell personal information, do not share it for advertising, and do not use automated decision-making that produces legal or similarly significant effects on individuals.
6. Legal bases (EEA, UK and similar jurisdictions)
- Performance of a contract — providing the App you installed and the plan you chose.
- Legitimate interests — securing and improving the App, answering support, preventing abuse. We balance these against your interests and rights.
- Consent — optional emails and recipients you enable in Settings; you can withdraw by turning them off.
- Legal obligation — where we must keep or disclose information by law.
7. Who we share information with
We use a small number of service providers to run StockReclaim. Each processes data only on our instructions and only to the extent needed for its service:
| Provider | Purpose | What it handles |
|---|---|---|
| Shopify | The platform the App runs on, and billing | All App traffic passes through Shopify's APIs; Shopify bills your plan |
| Fly.io | Application hosting (United States) | The App's servers, logs and background jobs |
| Supabase | Managed PostgreSQL database | Everything listed in §4.3 and §4.4 |
| Resend | Transactional email delivery | Digest, packet, announcement and support emails, including recipient addresses and attachments |
| Sentry | Error monitoring | Error reports with store domain and technical context; personal identifiers disabled |
| Telegram | Internal operational alerts to the founder | Store domain and support-ticket subject lines only |
| Hostinger | Hosting for this Site | Standard web-server logs |
We may also disclose information if required by law or a valid legal process, to protect the rights, safety or property of merchants, the public or ourselves, or as part of a merger, acquisition or sale of the business (in which case this policy continues to apply to the transferred data).
8. International transfers
We operate from India. The App and its database are hosted by providers in the United States. If you are in the EEA, the United Kingdom or another jurisdiction with data-transfer rules, your information is transferred to and processed in those countries. Where required, we rely on appropriate safeguards such as the standard contractual clauses in our providers' data-processing terms.
9. How long we keep information
- While the App is installed — we keep the data in §4.1–4.4 so the App can work. The scan cache is overwritten on every scan.
- When you uninstall — Shopify notifies us, and 48 hours later sends a
shop/redactrequest. On that request we delete your sessions and access token, your store record, the scan cache, restock claims, last-seen inventory levels, your decisions, your settings, your support tickets (including attachments) and any feature requests linked to your store — and we read the database back to confirm nothing remains. If you reinstall within those 48 hours, your decisions and settings are kept. - Feature requests submitted on the Site — kept while they are open or shipped; deleted on request to the email below.
- Logs and error reports — retained for up to 90 days, then deleted automatically.
- Emails we have sent — delivery records are kept by our email provider for a limited period for deliverability and abuse prevention.
10. Your customers' data
When the App processes information about your customers' orders, we act as
your processor (or "service provider") and you are the
controller. We process that data only to provide the App to
you, and we hold no customer personal identifiers (see §4.2). Shopify's
mandatory privacy webhooks are honoured automatically: a
customers/data_request or customers/redact request is
answered with the fact that we hold no personal data for that customer, and a
shop/redact request triggers the deletion described in §9. If one of
your customers contacts us directly, we will refer them to you.
Merchants subject to the GDPR or UK GDPR are covered by our Data processing agreement, which includes the standard contractual clauses for transfers and the current list of sub-processors.
11. Security
- All traffic between Shopify, the App, the Site and your browser is encrypted (TLS).
- Shopify access tokens are encrypted at rest.
- Every webhook from Shopify is verified with its HMAC signature before it is processed.
- Database access is scoped per store (row-level security), so one store's data cannot be read in the context of another.
- The App requests the minimum permissions it needs, and no customer personal fields.
- The App writes to your store in exactly one case: when you click Restock now on a specific exception. The audit itself never writes.
No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
12. Your rights
Depending on where you are, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy of it in a portable format, and to withdraw consent where processing is based on consent. Residents of California and certain other US states have equivalent rights under their state privacy laws; we do not sell or share personal information as those laws define it.
To exercise any of these rights, email support@stockreclaim.com from the address associated with your store. We will respond within the time required by applicable law. Uninstalling the App is the fastest way to have everything we hold for your store deleted (§9). You also have the right to lodge a complaint with your local data-protection authority.
13. Children
StockReclaim is a business tool for Shopify merchants. It is not directed at, and we do not knowingly collect information from, anyone under 18.
14. Changes to this policy
We will post any changes on this page and update the effective date above. For material changes we will also notify installed stores through an in-app announcement and, where we have an address for you, by email. Continued use of the App after a change takes effect means you accept the updated policy.
15. Contact
Gandhi Polymers, trading as StockReclaim (India).
Email: support@stockreclaim.com
A plain-language summary of what the App reads and stores is also in the help centre: Data and privacy.