Needly Bundle Stock Alerts

Privacy policy

Effective August 27, 2026

Needly Bundle Stock Alerts processes the minimum Shopify store and inventory data needed to warn merchants about broken bundles.

Information the app reads

Shopify store domain, store name and contact email; merchant-selected product and variant identifiers, titles and optional SKUs; inventory-item identifiers, inventory-tracking state, and aggregate available quantities.

Information the app stores

The app stores the shop domain, display name and configured alert email; bundle-to-component mappings and thresholds; the recovery notification preference; current component snapshots, bundle status, cause and check times; alert delivery state and bounded non-secret errors; coalesced inventory-refresh jobs and retry state; whether and when the app made its one-time native review request; whether and when a test alert was attempted and sent; Shopify App Pricing subscription state, plan/item name, trial and billing-cycle dates, and the store/app identifiers needed to verify access; and Shopify authentication sessions. The app does not transmit or store ratings, review text, or the result of Shopify's review modal. Online Shopify sessions can include staff identity and role fields supplied by Shopify for authentication.

How information is used

Data is used only to authenticate the installed app, evaluate mapped bundle capacity, group shared-component restock work, display status and alert history, retry operational work, and send merchant-configured transactional bundle alerts and optional recovery confirmations.

Data leaving Shopify

The listed data reaches the app through Shopify's authenticated GraphQL API and signed webhooks. Application data is processed by the hosted app and managed PostgreSQL database. Shopify's Partner API is used only to verify the store's App Pricing subscription. Alert recipient, bundle/component names, quantity, threshold, and message metadata pass through Resend for transactional email. Open and link tracking are disabled. No data is sent to advertising, analytics, or marketing services.

Storage and deletion

The production service uses Render for application hosting and PostgreSQL in Frankfurt, Germany. A merchant can remove mappings and uninstall to revoke Shopify access. After Shopify sends the mandatory signed shop-redaction webhook, the shop, mappings, snapshots, alerts, refresh jobs, and sessions are deleted. Encrypted backup copies expire under the provider's documented retention window.

Customer privacy requests

Needly Bundle Stock Alerts does not read or store customer or order data. It authenticates Shopify's mandatory customer data-request and redaction webhooks and acknowledges that no customer record is held.

Service providers

The app uses Shopify for commerce APIs, authentication, and subscription verification; Render for app hosting and PostgreSQL; and Resend for transactional email. Needly Labs will update this policy before adding a provider that processes merchant data.

Questions

Email needlylabs@gmail.com. Merchants may include their store domain and approximate UTC time, but must not email access tokens, passwords, payment details, customer exports, or database copies.

← Back to Needly Bundle Stock Alerts