Skip to content

Legal

Privacy policy

What StockReclaim collects, why, where it is kept, who can see it, and how to have it removed.

Effective September 5, 2026.

1. Who we are

StockReclaim is operated by Gandhi Polymers, a sole proprietorship registered in India (proprietor: Ankita Bhandiya), trading as StockReclaim. In this policy "we", "us" and "our" mean Gandhi Polymers. "Jevian Labs" is the development name you may see in the Shopify Partner directory; it refers to the same business.

You can reach us about anything in this policy at support@stockreclaim.com.

2. What this policy covers

This policy applies to:

  • the StockReclaim app installed from the Shopify App Store into a merchant's Shopify admin (the "App");
  • this website, stockreclaim.com (the "Site"), including the help centre, blog, changelog, support and feature-request pages;
  • the emails the App sends on a merchant's behalf (the weekly digest, the monthly reconciliation packet, product announcements and support replies).

It does not cover Shopify itself. Shopify's handling of your store and your customers' data is governed by Shopify's privacy policy.

3. The short version

  • The App reads your refunds and returns live from Shopify to find stock that never came back. It does not copy your products, orders, refunds or inventory into our systems.
  • We do not request, receive or store your customers' names, email addresses, phone numbers or addresses.
  • We keep only what the App needs to work: a rebuildable cache of your last scan, the decisions you make on exceptions, the settings you enter, and the messages you send us.
  • When you uninstall, everything we hold for your store is deleted and the deletion is verified.
  • We do not sell data, run advertising, or use analytics cookies on this Site.

4. Information we collect

4.1 From Shopify, when you install the App

  • Store identity — your store's myshopify.com domain, timezone and currency, and the date you installed.
  • Access token — the credential Shopify issues so the App can read your store. It is encrypted at rest and used only to make the API calls described below.
  • Installing user details — where Shopify passes them during installation, the name and email address of the staff account that installed the App. We use these only to identify the installation and to answer support requests.

4.2 Store data the App reads to run the audit

With the permissions you grant at install (read_products, read_inventory, read_locations, read_orders, read_returns and write_inventory), the App reads:

  • orders from the last 60 days (or a longer window if Shopify has granted the App access to older orders), including their refunds, refund line items and whether each refunded item was marked for restock;
  • returns and their dispositions (for example restocked, not restocked, missing);
  • products and variants (title and SKU), inventory levels and locations.

This data is read during a scan and used to compute your figure. It is not retained, with the specific exceptions in §4.3.

StockReclaim is declared to Shopify for store management use and requests none of Shopify's optional protected customer fields. Shopify therefore does not provide your customers' names, email addresses, phone numbers or addresses to the App, and we do not store them.

4.3 What the App stores for your store

  • Scan cache — the result of your most recent scan: order numbers, SKUs, product titles, quantities, amounts, the cause assigned to each case and its age. Kept so the dashboard loads instantly; rebuilt on every scan; deleted on uninstall.
  • Restock claims and last-seen inventory levels — for the "restock recorded, stock unchanged" check: the order number, SKU, product title, refund reference, quantity and amount of each claimed restock, and the last inventory level seen per item and location. No inventory history and no copy of your catalogue is kept.
  • Your decisions — each case you mark resolved, write off or restock, with the order number, SKU, amount, the date and any note you type.
  • Settings — age thresholds, the locations you include, whether the weekly digest and monthly packet are enabled, the day they send, and the email addresses you enter as recipients (for example your bookkeeper's).
  • Plan and lifecycle — which plan your store is on, install and uninstall dates, and a de-duplication log of the webhooks Shopify has sent us.

4.4 Support tickets and feature requests

When you open a support ticket in the App we store the subject, your messages, our replies and any screenshots you attach. When you submit a feature request in the App or on the Site we store the title, description, category and the email address you optionally provide. Support tickets are linked to your store; a feature request from the Site is linked only to the email you give, if any.

4.5 The Site

The Site is static. It sets no cookies and uses no analytics or tracking scripts. Our hosting provider records standard server logs (IP address, requested page, browser type, timestamp) for security and capacity purposes.

4.6 Technical and operational data

  • Application logs — request metadata, timestamps and your store domain, used to operate and debug the App.
  • Error reports — when something fails, an error report is sent to our monitoring service with the store domain and technical context. Personal identifiers are disabled in that reporting.
  • Internal notifications — new installs, uninstalls and new support tickets generate a short internal notice to the founder (store domain and ticket subject) so we can respond quickly.

5. How we use information

  • to run the audit, show you the results and let you act on them (the App's core function);
  • to send the emails you enable — the weekly digest and the monthly reconciliation packet — to the recipients you specify;
  • to tell you about material changes to the App or these terms (in-app announcement and, where appropriate, email);
  • to answer support requests and consider feature requests;
  • to keep the App secure, prevent abuse, and meet our obligations to Shopify;
  • to understand, in aggregate and without identifying stores, how the App is used so we can improve it.

We do not sell personal information, do not share it for advertising, and do not use automated decision-making that produces legal or similarly significant effects on individuals.

6. Legal bases (EEA, UK and similar jurisdictions)

  • Performance of a contract — providing the App you installed and the plan you chose.
  • Legitimate interests — securing and improving the App, answering support, preventing abuse. We balance these against your interests and rights.
  • Consent — optional emails and recipients you enable in Settings; you can withdraw by turning them off.
  • Legal obligation — where we must keep or disclose information by law.

7. Who we share information with

We use a small number of service providers to run StockReclaim. Each processes data only on our instructions and only to the extent needed for its service:

ProviderPurposeWhat it handles
ShopifyThe platform the App runs on, and billingAll App traffic passes through Shopify's APIs; Shopify bills your plan
Fly.ioApplication hosting (United States)The App's servers, logs and background jobs
SupabaseManaged PostgreSQL databaseEverything listed in §4.3 and §4.4
ResendTransactional email deliveryDigest, packet, announcement and support emails, including recipient addresses and attachments
SentryError monitoringError reports with store domain and technical context; personal identifiers disabled
TelegramInternal operational alerts to the founderStore domain and support-ticket subject lines only
HostingerHosting for this SiteStandard web-server logs

We may also disclose information if required by law or a valid legal process, to protect the rights, safety or property of merchants, the public or ourselves, or as part of a merger, acquisition or sale of the business (in which case this policy continues to apply to the transferred data).

8. International transfers

We operate from India. The App and its database are hosted by providers in the United States. If you are in the EEA, the United Kingdom or another jurisdiction with data-transfer rules, your information is transferred to and processed in those countries. Where required, we rely on appropriate safeguards such as the standard contractual clauses in our providers' data-processing terms.

9. How long we keep information

  • While the App is installed — we keep the data in §4.1–4.4 so the App can work. The scan cache is overwritten on every scan.
  • When you uninstall — Shopify notifies us, and 48 hours later sends a shop/redact request. On that request we delete your sessions and access token, your store record, the scan cache, restock claims, last-seen inventory levels, your decisions, your settings, your support tickets (including attachments) and any feature requests linked to your store — and we read the database back to confirm nothing remains. If you reinstall within those 48 hours, your decisions and settings are kept.
  • Feature requests submitted on the Site — kept while they are open or shipped; deleted on request to the email below.
  • Logs and error reports — retained for up to 90 days, then deleted automatically.
  • Emails we have sent — delivery records are kept by our email provider for a limited period for deliverability and abuse prevention.

10. Your customers' data

When the App processes information about your customers' orders, we act as your processor (or "service provider") and you are the controller. We process that data only to provide the App to you, and we hold no customer personal identifiers (see §4.2). Shopify's mandatory privacy webhooks are honoured automatically: a customers/data_request or customers/redact request is answered with the fact that we hold no personal data for that customer, and a shop/redact request triggers the deletion described in §9. If one of your customers contacts us directly, we will refer them to you.

Merchants subject to the GDPR or UK GDPR are covered by our Data processing agreement, which includes the standard contractual clauses for transfers and the current list of sub-processors.

11. Security

  • All traffic between Shopify, the App, the Site and your browser is encrypted (TLS).
  • Shopify access tokens are encrypted at rest.
  • Every webhook from Shopify is verified with its HMAC signature before it is processed.
  • Database access is scoped per store (row-level security), so one store's data cannot be read in the context of another.
  • The App requests the minimum permissions it needs, and no customer personal fields.
  • The App writes to your store in exactly one case: when you click Restock now on a specific exception. The audit itself never writes.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

12. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy of it in a portable format, and to withdraw consent where processing is based on consent. Residents of California and certain other US states have equivalent rights under their state privacy laws; we do not sell or share personal information as those laws define it.

To exercise any of these rights, email support@stockreclaim.com from the address associated with your store. We will respond within the time required by applicable law. Uninstalling the App is the fastest way to have everything we hold for your store deleted (§9). You also have the right to lodge a complaint with your local data-protection authority.

13. Children

StockReclaim is a business tool for Shopify merchants. It is not directed at, and we do not knowingly collect information from, anyone under 18.

14. Changes to this policy

We will post any changes on this page and update the effective date above. For material changes we will also notify installed stores through an in-app announcement and, where we have an address for you, by email. Continued use of the App after a change takes effect means you accept the updated policy.

15. Contact

Gandhi Polymers, trading as StockReclaim (India).
Email: support@stockreclaim.com

A plain-language summary of what the App reads and stores is also in the help centre: Data and privacy.


Questions about this document? Email support@stockreclaim.com. See also our Privacy policy, Terms of service and Data processing agreement.