Backordr Privacy Policy
This policy covers Backordr, our backorder management app for Shopify. Our website is covered by the separate website privacy policy.
Backordr ("we", "our", "us") operates the Backordr application available on the Shopify App Store. This Privacy Policy describes what data Backordr collects, how we use it, where it is stored, who else processes it on our behalf, and what rights merchants and their customers have regarding that data. It is written to address the disclosure requirements of the GDPR and the CCPA/CPRA, and to document our handling of Shopify's Protected Customer Data at Level 2 access (Backordr processes the customer's name and email taken from the order payload — fields Shopify classifies as Level 2 per https://shopify.dev/docs/apps/launch/protected-customer-data).
1. Who we are (controller / processor roles)
For data exchanged through the Shopify Admin API on behalf of your store, Backordr acts as a data processor. You, the merchant who installs the app, remain the data controller for your customers' personal data.
For the small set of data you provide directly to Backordr (your shop preferences, restock dates you type into the app, support correspondence) Backordr acts as the controller.
The legal entity operating the service is Veltrio Labs LLC, a limited liability company registered in the State of Wyoming, United States, which operates the domain veltriolabs.com and publishes Backordr on the Shopify App Store under its Shopify Partner organization. Contact and support information is in Section 13.
2. What data we collect
2.1 Data received from Shopify
When you install Backordr, Shopify provides us with an OAuth access token and we begin receiving webhooks. Through that token and those webhooks we read or receive the following:
- Shopify session and shop information —
Sessionrecords (offline access token, scope, and the shop domain), shop name, currency, timezone, primary location, and the active billing subscription returned bycurrentAppInstallation. Where Shopify includes them in the OAuth response, theSessionrow also holds the first name, last name and email address of the staff account that installed or authorized the app. We do not request these fields; we store what the OAuth session returns. - Product and variant data — product and variant IDs, titles, SKUs,
inventoryPolicy,inventoryItemIDs, and theexpected_restock_datevariant metafield that we ourselves write back. We do not duplicate your full catalog; we store references and the small product snapshot needed to render the dashboard without an extra API call. - Inventory levels — the
availablequantity per variant per location via theinventory_levels/updatewebhook. Used to detect when stock returns and trigger FIFO allocation. - Order data — for orders that contain at least one backordered line item, we store: order ID and name, line item IDs, fulfillment order ID, the customer's email address and name, and the line items themselves (quantity, variant, price). For orders that contain no backordered items we discard the payload after evaluation.
- Fulfillment order data — IDs of fulfillment orders, the hold IDs we create, and the split results. Used to release holds when stock returns.
2.2 Data you enter into the app
- Restock dates — the expected restock date you type into the Restock Dates page, plus any free-text notes.
- Backorder behavior settings — auto-detection toggle, mixed-cart mode, default restock-date source, sender display name, reply-to email.
- Your own contact addresses — the digest recipient address (
digestEmail), the reply-to address (emailReplyTo) and the business postal address (emailBusinessAddress) you configure for the footer of customer emails. These are the merchant's addresses, not your customers'. - Backorder limits — the per-variant cap (
BackorderLimit) you set, or that the app derives from an expected incoming quantity and your reserve percentage: variant and product IDs, titles, SKU, and the maximum number of units allowed on backorder. - CSV imports — files you upload to bulk-create restock dates.
2.3 Data we generate
- Backorder records — one row per backordered line item, including status (
PENDING,ALLOCATED,FULFILLING,FULFILLED,CANCELLED), timestamps, and FIFO priority. - Email logs — the recipient email, subject, status, and the Resend message ID for each transactional email we send.
- Activity logs — operational events such as "backorder created", "stock allocated", "email failed". Useful for the merchant's own audit trail and for our customer support.
- Webhook events — short-lived deduplication records used to make webhook processing idempotent.
- Usage counters — per-shop, per-calendar-month counts of detected backorders and emails sent (
UsageCounter), used to enforce your plan's limits and to show you where you stand against them. These counters hold numbers only, no personal data.
2.4 Data collected directly from your storefront visitors
Backordr's Theme App Block can display an optional "notify me when back in stock" form. If you enable that form, it is the one place where Backordr collects personal data directly from a visitor to your store:
- The form posts to
/apps/backordr/subscribeon your own domain. Shopify proxies that request to Backordr through the Shopify App Proxy and signs it; we verify the signature before doing anything with the request. - What we store is a
RestockSubscriptionrow: the email address the visitor typed into the form, the variant and product ID they asked about, the product title, the time of signup, and an opaque unsubscribe token. Nothing else from the request is retained. - The address is used for one purpose: to email that visitor when the variant is back in stock. Every such email carries a one-click unsubscribe link; using it deletes the row immediately.
- If you do not enable the notify-me form, no
RestockSubscriptionrows are ever created for your shop.
2.5 What we do not collect
- Apart from the notify-me form described in 2.4, Backordr collects nothing from your storefront. There is no Backordr SDK, pixel, or analytics script on your pages; the Theme App Block is rendered by Shopify Liquid and loads no JavaScript from our domain.
- We do not collect payment instrument data, IP addresses of your customers, browsing history, or location data.
- Backordr is not directed to children, and we do not knowingly collect data from individuals under the age of 16. The notify-me form in 2.4 has no age gate, so if you believe a child has entered their address there, contact us and we will delete it.
3. Why we collect each category (purposes & legal bases)
| Data category | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Shopify session, shop info | Authenticate API calls; tell shops apart in the database | Performance of contract |
| Product, variant, inventory data | Detect backorder items, render the dashboard, allocate FIFO | Performance of contract |
| Order data + customer email and name | Create the backorder record, send the customer a backorder confirmation, restock-update, and shipped email | Performance of contract (the merchant's contract with the customer; we process on the merchant's behalf) |
| Restock dates and settings | Drive the storefront badge, Google Merchant feed, and email content | Performance of contract |
| Back-in-stock waitlist signups (storefront visitor's email address, section 2.4) | Send that visitor the back-in-stock notification they asked for | Consent (GDPR Art. 6(1)(a)) — the visitor types their address into the notify-me form for this one purpose. Consent can be withdrawn at any time via the unsubscribe link in the email, which deletes the record |
| Email logs | Diagnose delivery problems; honor "show me what was sent to this customer" | Legitimate interest (operational integrity) |
| Activity logs | Internal audit, customer-support diagnostics | Legitimate interest |
| Webhook events | Idempotency / duplicate suppression | Legitimate interest |
We do not process this data for advertising, profiling, automated decision-making, or training of AI models.
4. Where data is stored
Backordr's primary database is PostgreSQL hosted on Neon in the aws-us-east-1 region (Northern Virginia, United States). The application itself runs on Fly.io in the iad region (Northern Virginia, United States), so both the application and the data are hosted in the United States. All connections use TLS. Neon maintains continuous backups with a rolling point-in-time-restore window; backup history ages out of that window automatically.
Because that infrastructure is located in the United States, personal data originating in the EU, the EEA, or the UK is transferred outside those regions. Each sub-processor listed in Section 5 publishes its own data processing terms and transfer safeguards, linked in that table. If you need to know which safeguards apply to your store, write to the address in Section 13 and we will confirm what is in place.
Operational logs (HTTP request logs, error traces) are emitted by the application and held by Fly's logging infrastructure for short retention windows.
5. Sub-processors
We use the following sub-processors. Each is bound by its own data- processing agreement with the data they receive limited to what is needed for the function described.
| Sub-processor | Function | Data shared | Privacy policy |
|---|---|---|---|
| Fly.io, Inc. (United States) | Application hosting (servers in Northern Virginia, United States) | All app data (encrypted in transit) | https://fly.io/legal/privacy-policy/ |
| Neon (Databricks, Inc.) (United States) | Managed PostgreSQL database hosting (servers in Northern Virginia, United States) | All app data (encrypted at rest and in transit) | https://neon.tech/privacy-policy |
| Resend (Plus Five, Inc.) (United States) | Transactional email delivery for backorder confirmation, restock-update, and shipped emails | Customer email address, customer name, order name, product titles, restock date, branded sender info | https://resend.com/legal/privacy-policy |
| Cloudflare, Inc. (United States) | DNS for veltriolabs.com and forwarding of inbound email to our support/privacy addresses | Email you send to the contact addresses in Section 13 (sender, subject, body) | https://www.cloudflare.com/privacypolicy/ |
| Shopify Inc. (Canada) | Platform integration, OAuth, billing, and webhook delivery | Data exchanged via the Shopify Admin API as described in Section 2 | https://www.shopify.com/legal/privacy |
We do not transfer data to any other third party. We do not sell or rent your data, ever.
6. Retention
| Data | Retained for |
|---|---|
| Shop, Session, Backordr settings | The lifetime of the install |
| BackorderRecord | The lifetime of the install (used for analytics and fill-rate computation) |
| RestockDate | The lifetime of the install |
| ImportHistory | Rotated annually |
| EmailLog | Rotated annually (we keep one year of transactional-email metadata for delivery diagnostics) |
| ActivityLog | Rotated every 90 days |
| RestockSubscription (back-in-stock waitlist) | Deleted 365 days after we send the visitor their back-in-stock notification. A signup that is still waiting for its notification is kept until the notification is sent — or until the visitor unsubscribes, which deletes it immediately |
| WebhookEvent (idempotency table) | Rotated every 7 days |
| Backups (Neon point-in-time restore) | Rolling restore window of at most 30 days, then automatically purged |
| Support correspondence | Up to 24 months from last contact, unless you ask us to delete sooner |
The rotations above are enforced by two scheduled jobs that run daily and delete anything past its window across every shop. Rows marked "lifetime of the install" are not on a timer: they are removed when the app is uninstalled or when Shopify sends shop/redact, both of which delete every row we hold for that shop straight away. See Section 8 for the deletion path.
7. Customer data subject rights and Shopify compliance webhooks
Backordr supports the three mandatory Shopify GDPR / Privacy webhooks. These are wired up at the /webhooks/compliance route via the compliance_topics declaration in shopify.app.toml. Every delivery is HMAC-verified before it is processed.
customers/data_request— When a store customer asks the merchant for their data, Shopify forwards the request to us. Backordr does not produce an automatic JSON export in response. Instead we record an entry in the merchant's own Activity log inside the app that states which data we hold for that customer and where to get it: the customer's name and email attached to their backorders, exportable from the backorder queue CSV, and — if that address is on a back-in-stock waitlist — the waitlist entries, exportable from Restock dates → Waitlist subscribers. The merchant runs the export and forwards it to the customer. If a merchant wants us to assemble the export instead, we do it on request to the address in Section 13, within 30 days.
customers/redact— When a customer requests deletion (or one is requested 10 days after the customer's last order, per Shopify's policy), Shopify forwards us the redact request. We then, for that shop: clearcustomerEmailandcustomerNameon everyBackorderRecordmatching that email address (case-insensitively) and on every record belonging to an order listed in the request; delete everyEmailLogrow addressed to that email; delete everyRestockSubscription(waitlist) row for that email; and delete theActivityLogentries created by an earliercustomers/data_requestfor that customer, because those entries quote the address. Order, variant, and shop references survive (they are not personal data) so historical fill-rate figures stay correct; the personal fields do not.
shop/redact— Sent 48 hours after a merchant uninstalls the app. We rundeleteShopData(shopId), which issues an explicit delete for every table that holds rows for that shop — sessions, backorder records, restock dates, email logs, activity logs, import history, webhook dedupe rows, waitlist subscriptions, backorder limits, usage counters, and finally the shop row itself. There is no database-level cascade behind this; each table is deleted by name, so nothing is left behind by an unconfigured relation. In practice the shop's data is already gone by then — see Section 8. Backups age out of Neon's point-in-time-restore window within at most 30 days.
Beyond the Shopify-mandated webhooks, merchants and their customers have the following rights depending on jurisdiction:
- Access — Get a copy of the data we hold. Email support@veltriolabs.com and we will provide a JSON export within 30 days.
- Rectification — Ask us to correct inaccurate information.
- Erasure — Request that we delete the data. For merchants, this means uninstalling the app; for customers, this is the
customers/redactflow described above. - Portability — Receive your data in a machine-readable format (JSON).
- Restriction / Objection — Limit or object to specific processing.
- Withdraw consent — Anyone who signed up to a back-in-stock waitlist (Section 2.4) can withdraw at any time using the unsubscribe link in the email, which deletes the record, or by writing to the privacy address in Section 13.
- Lodge a complaint — With your local data protection authority (in the EU/UK) or the California Privacy Protection Agency.
California residents have a further set of rights under the CCPA/CPRA; Section 11 sets those out, together with the notice at collection those laws require.
8. Deletion behavior
When the application is uninstalled (app/uninstalled), we delete your data immediately. We do not hold it for a grace period and there is no "pending deletion" flag on the shop record. In order:
- We attempt to release any outstanding
fulfillmentOrderHoldrecords we created, on a best-effort basis (the access token may already be revoked at this point — we honor whatever Shopify allows). - We attempt to clear the
expected_restock_datevariant metafields we wrote, on a best-effort basis. - We run
deleteShopData(shopId), which deletes every row we hold for that shop:Session,BackorderRecord,RestockDate,EmailLog,ActivityLog,ImportHistory,WebhookEvent,RestockSubscription,BackorderLimit,UsageCounter, and theShoprow itself. Each table is deleted explicitly by name rather than through a database cascade, so a relation added later cannot silently escape the wipe. If any part of the deletion fails we return an error to Shopify so the webhook is redelivered and the wipe is retried.
When Shopify subsequently sends shop/redact (typically 48 hours later), we run exactly the same routine again. It is written to be safely repeatable, and by that point it normally finds nothing left to delete.
Backups containing that data age out of Neon's point-in-time-restore window within at most 30 days and are automatically purged.
The same routine can be triggered manually at the merchant's request via support.
Because deletion is immediate, uninstalling the app is not reversible: reinstalling gives you a clean install, not your previous data.
9. Security
- Encryption in transit: all traffic to Backordr uses TLS 1.2+.
- Encryption at rest: Neon encrypts database storage at rest.
- Access control: access to production credentials is limited to the app's operator. Application servers connect to the database with a credential that has only the privileges it needs.
- Webhook verification: every incoming Shopify webhook is verified using the HMAC signature (
X-Shopify-Hmac-Sha256); unverified requests are rejected. - No customer-facing tracking: the storefront Theme App Block is pure Liquid; it does not load JavaScript from our domain.
- Vulnerability reports: we accept reports at security@veltriolabs.com.
10. Security incident notification
For the personal data we handle on your behalf, Backordr is a processor and you are the controller. If we become aware of a personal data breach affecting data we process for your store, we notify you without undue delay, at the contact address Shopify holds for your store and at any notification address you have configured in the app.
That notice describes what we actually know at the time: the nature of the incident, the categories of data and the records involved, the effect we have been able to establish, and the steps we have taken or intend to take. Where the picture is still incomplete we send what we have and follow up as the investigation continues, rather than delaying the first notice until everything is known.
The duty to notify a supervisory authority (GDPR Art. 33), to inform affected data subjects (Art. 34), and any equivalent duty under US state law, sits with you as the controller. Our job is to give you the information and the assistance you need to discharge it, and to answer follow-up questions. We do not notify your customers directly unless you ask us to.
Where an incident originates with one of the sub-processors in Section 5, they notify us under their own terms and we pass on what is relevant to your store.
11. California privacy rights (CCPA / CPRA)
This section applies to California residents and, together with Sections 2, 3 and 6, serves as the notice at collection required by Cal. Civ. Code §1798.100. We collect only the categories listed below, for the purposes listed below, and we do not collect additional categories or use them for materially different purposes without updating this notice first.
| CCPA category | What it is here (see Section 2) | Where it comes from | Why we collect it | Who receives it |
|---|---|---|---|---|
| Identifiers | Customer name and email from the order payload; the email a storefront visitor enters in the notify-me form; the merchant staff name and email in the OAuth session; the merchant's own reply-to, digest and business addresses; shop domain | Shopify, your storefront, and you | Create and track backorders, send the transactional and back-in-stock emails, authenticate API calls, support | Our hosting and email service providers (Section 5) |
| Commercial information | Order and line-item records for backordered items, backorder records and their status, restock dates, backorder limits, import history | Shopify and you | Run the backorder workflow and the merchant's dashboard and analytics | Our hosting service providers (Section 5) |
| Internet or other electronic network activity information | Server-side operational logs of requests to our own application. We do not collect your customers' browsing history, search history, or interaction data on your storefront | Our own infrastructure | Operate and debug the service | Our hosting service providers (Section 5) |
| Geolocation data, biometric information, audio/visual data, education or employment information, inferences, and sensitive personal information as defined in §1798.140(ae) | Not collected | — | — | — |
Retention is set out in Section 6. We keep each category only for the period stated there.
We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA/CPRA. We have never done so. We do not use sensitive personal information to infer characteristics or for any secondary purpose, so the right to limit its use under §1798.121 has no application to our processing. The disclosures to the providers in Section 5 are disclosures to service providers for a business purpose, not sales.
Your rights. Subject to verification, you may exercise the right to know what personal information we have collected, used, and disclosed and to receive a copy of it in a portable form (§1798.100, §1798.110, §1798.115); the right to delete it (§1798.105); and the right to correct inaccurate personal information (§1798.106). Send the request to privacy@veltriolabs.com. We verify requests by matching the request to the store or order records we hold; where the request concerns data we process for a merchant, the merchant is the business and we act on their instruction, so we may route the request to them.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We ask for written permission signed by you, and we may still contact you directly to confirm the request and verify your identity.
No discrimination (§1798.125). We will not deny you our service, charge you a different price, or give you a lower quality of service because you exercised any of these rights. Backordr has no service tier or feature that is conditioned on a merchant or a customer declining to exercise them.
12. Cookies and tracking
Backordr's embedded admin app uses Shopify session tokens for authentication. We do not set our own cookies for analytics, advertising, or behavioral tracking, and backordr.veltriolabs.com sets no third-party cookies.
13. Contact
Questions about this Privacy Policy, data subject requests, or sub-processor inquiries:
- Company: Veltrio Labs LLC (Wyoming, United States)
- Privacy contact / data subject requests: privacy@veltriolabs.com
- General support: support@veltriolabs.com
- Security reports: security@veltriolabs.com
- Postal address: 30 N Gould St, STE R, Sheridan, WY 82801, USA
Data Protection Officer. Backordr is operated as a small business and does not currently meet the GDPR Article 37 thresholds that mandate designation of a DPO (i.e. we are not a public authority, our core activities do not consist of large-scale systematic monitoring of data subjects, and we do not process special categories of data at scale). The privacy contact above (privacy@veltriolabs.com) is the dedicated inbox for all data subject and sub-processor inquiries and is monitored on every business day.
14. Changes to this policy
We may update this Privacy Policy as the app evolves. If a change is material we will notify installed merchants by email and update the "Effective date" at the top. Continued use of the app after a change takes effect indicates acceptance of the updated policy.