DueIn
Privacy policy
Effective July 16, 2026
DueIn processes the minimum Shopify store data needed to connect confirmed inbound inventory to merchant-controlled preorders.
Information DueIn stores
DueIn stores the shop domain and settings; shipment references, suppliers, destinations, notes, expected dates and quantities; product and variant titles, SKUs and Shopify identifiers; app-owned preorder policy and Selling Plan identifiers; minimal order, line-item, quantity, update and cancellation data; allocations, exceptions and audit events; webhook delivery identifiers and bounded errors; Shopify authentication sessions; verified Shopify App Pricing state; and customer full-order cancellation request status and timestamps. Delay-notification records contain order/shipment identifiers, both promised dates, delivery state, attempt count, and redacted errors, but no email address.
Customer identity
For a Customer Account cancellation request, DueIn transiently compares Shopify's customer identifier with the signed session token to prove the signed-in customer owns the order. DueIn does not store that customer identifier, name, email, phone number, or address. If a promised preorder date moves later, DueIn reads the affected order's email from Shopify only for the duration of sending the required order update.
How information is used
Data is used only to record incoming inventory, create and synchronize merchant-enabled Shopify preorder options, publish supported storefront dates, allocate order quantities to specific inbound items, reconcile order changes, communicate revised dates in Shopify Customer Accounts, send required transactional delay notices, process reviewed cancellation requests, verify app access, and provide an operational audit trail.
Data leaving Shopify
The listed data reaches DueIn through Shopify's authenticated APIs, signed webhooks, and merchant input. Billing status is verified with Shopify's Partner API. The affected order email and delay message pass through Resend (Plus Five Five, Inc.) only for transactional delivery. Messages use Resend's Ireland sending region. Resend documents that account data, email metadata, logs, and API records are stored in the United States; the configured plan exposes 30 days of email and log history, and Resend's DPA says customer data is deleted within 90 days after account termination. Open and link tracking are disabled. DueIn does not send this data to advertising, analytics, marketing, or third-party payment services. Shopify handles checkout, billing, refunds, and cancellation notifications.
Storage, exports, and deletion
Application data is stored in Render PostgreSQL 17 in Frankfurt, Germany, with encrypted transport and access controls. The final backup recovery window and deletion schedule will be added after the live restore drill. Authorized staff can export shop-scoped shipment and allocation CSV files. Shopify customer data requests create an authorized-staff JSON export for 30 days. Authenticated customer and shop redaction requests remove matching operational data, sessions, and related exports as required.
Merchant controls
Variants default off. Draft, arrived, cancelled, unsynchronized, and zero-capacity records fail closed. A customer cancellation request does not change Shopify: authorized store staff must distinctly confirm the irreversible full-order cancellation, original-payment refund, restock, and Shopify notification.
Service providers
DueIn uses Shopify for commerce APIs and billing, Render for application hosting and PostgreSQL in Frankfurt, and Resend for transactional email sent from Ireland with account metadata and logs stored in the United States. Needly Labs will update this policy before adding a provider that processes merchant or customer data.
Questions
Questions or privacy requests can be directed to needlylabs@gmail.com. Shopify merchants should include their store domain but must not email access tokens, passwords, payment details, or customer exports.