Privacy · PL Inventory Forecast & Alerts

PL Inventory Forecast & Alerts Privacy Policy

Last updated · August 12, 2026Applies to Alcaris Inc., doing business as Propel Commerce, and all Propel apps

PL Inventory Forecast & Alerts, formerly Propel Low Stock Alerts (“the App”), is a Shopify app operated by Propel Commerce / Alcaris Inc. This policy explains what data the App accesses, why, how long it is kept, and how it is deleted.

§ 01

What the App accesses

The App is a read-only inventory monitor. It requests only these Shopify scopes:

read_products — to read product and variant titles, SKUs, vendors, types, tags, and status so low-stock items can be identified and labeled in reports and digests.
read_inventory — to read available quantities per variant so the App can compare them against your configured thresholds.
read_locations — to read location names so inventory can be reported and filtered per location.
read_orders — to read the quantities and dates on order line items so the App can compute per-variant sales velocity for forecasting (days of cover, projected stockout dates, and suggested reorder quantities). The App does not read customer names, emails, addresses, phone numbers, or payment details from orders.

The App does not request write access to your store, and does not access customers, payment, or storefront-customer data.

§ 02

What we store

To deliver scheduled low-stock digests, the App stores, keyed to your shop domain:

Inventory snapshots — product, variant, and location identifiers, titles, SKUs, available quantities, and timestamps captured at each scan.
Alert configuration — thresholds, schedules, filters, and threshold overrides you set.
Recipient email addresses — the email addresses you enter to receive digests. These are merchant or staff addresses you provide; the App does not collect storefront-customer emails.
Run history — records of each scan (timing, item counts, email delivery status) for troubleshooting and the in-app activity log.
Sales velocity aggregates — daily units-sold totals per product variant, computed from order line items. These are variant-level aggregates only: no order records, customer identifiers, or order-level details are stored. Each daily total is kept for 90 days and then deleted automatically.
Session data — the Shopify offline access token and shop metadata required to call the Shopify API on your behalf.

§ 03

What we do not store

The App does not store, process, or have access to storefront customer personal data — names, addresses, customer emails, or payment information. Order data is read only as line-item quantities and dates, and is stored only as daily units-sold totals per variant, never as order records. Because no customer-identifiable data is stored, there is no customer data to export or erase in response to Shopify's customer GDPR requests.

§ 04

How data is used

Stored data is used solely to evaluate inventory against your thresholds, render in-app reports, and send the low-stock email digests you configure. We do not sell data, and do not share it with third parties except the infrastructure providers required to run the service (hosting and transactional email).

§ 05

Sub-processors

Render — application hosting and database.
Amazon Web Services (Amazon SES) — delivery of digest emails to the recipients you configure.

§ 06

Data retention and deletion

On uninstall: the App receives Shopify's app/uninstalled webhook and marks your shop as uninstalled — it stops all processing and stops sending alerts. Your data is not deleted at this point; it is retained until Shopify's shop/redact webhook is received (see below).

Data deletion: the App deletes all data keyed to your shop — inventory snapshots, alert configuration, recipients, run history, threshold overrides, sales velocity aggregates, shop settings, and session token — when it receives Shopify's shop/redact webhook, which Shopify fires approximately 48 hours after uninstall.

Rolling deletion: independent of uninstall, each daily sales velocity total is deleted 90 days after the day it describes.

Customer GDPR webhooks: the App handles customers/data_request and customers/redact. Because no storefront-customer data is stored, these complete with nothing to export or erase.

§ 07

Your choices

You can remove individual recipients or delete an alert at any time from within the App. Uninstalling the App marks your shop as uninstalled and stops all processing; your data is then deleted when Shopify sends the shop/redact webhook, as described above.

§ 08

Contact

Questions about this policy or your data: support@propelcommerce.io.

Propel Commerce / Alcaris Inc.
170-422 Richards St
Vancouver, BC V6B 2Z4
Canada

§ 09

Changes

We may update this policy; material changes will be reflected by a new effective date at the top.