Inventur & Stock Take for Shopify
Privacy policy of the app
This is a translation for convenience. Only the German version is legally binding.
This privacy policy applies to the Shopify app “effware: Inventur & Stock Take”. The controller, your rights and how to contact us are described in our general privacy policy.
1. Roles
Merchants install the app in their Shopify store.
- The merchant is the controller for the count data and the counters’ names. We process this data on the merchant’s behalf (Art. 28 GDPR). The agreement is available under data processing agreement.
- We are the controller for providing the app to the merchant, for the usage statistics (section 8) and for the server logs (section 9).
- Shopify (Shopify International Limited, Ireland) processes the installation, billing and the merchant’s Shopify account under its own responsibility. The Shopify privacy policy applies to that.
2. No customer data
The app requests only these permissions from Shopify: read products, read and write inventory, read locations. It has no access to customer or order data and stores none.
3. Personal data processed by the app
- Counters’ names: free text, initials are enough. Stored per count entry, per device and per count.
- Shopify user ID and name of the person who creates, reviews or closes a count, and the link between a counter name and a Shopify user ID.
- Timestamps per entry (server time and device time) and per count.
- Random device ID per browser. It is generated in the device’s browser (localStorage), distinguishes devices of the same person and does not allow recognition outside the app.
- Free text: notes, cancellation reasons and reasons for differences.
- Address of the location (street, city) as stored in Shopify.
- Shop domain of the merchant.
- Company name, if the merchant enters it in the settings (it appears on the reports), and the time zone of the shop.
4. Purposes and legal bases
- Carrying out and documenting the stock take (count data, names, timestamps, device ID, free text, reports, company name): processing on behalf of the merchant under Art. 28 GDPR. The merchant as controller determines the legal basis; for the names of their staff this is usually the employment relationship and the merchant’s statutory stock take obligation (Art. 6 (1) (b) and (c) GDPR).
- Providing the app (shop domain, Shopify session, Shopify user ID): Art. 6 (1) (b) GDPR, contract with the merchant for using the app.
- Usage statistics and server logs: Art. 6 (1) (f) GDPR; our legitimate interests are steering the product without third parties and secure, stable operation.
Note for merchants: If staff count under their name, inform them as the controller about the processing (Art. 13 GDPR), for example with a notice or in your privacy information for employees. Because the log shows who counted what and when, introducing the app may require the consent of a works council where one exists (in Germany § 87 (1) no. 6 BetrVG). Initials instead of full names are enough for the app.
5. Storage location
All data is stored on our own server at Hetzner Online GmbH in the Nuremberg data center; the daily backups are stored encrypted in Hetzner Object Storage in Falkenstein. All data stays in Germany.
6. Camera scan page
People without access to the Shopify admin can count along with their phone via a link or QR code. The link contains a random access key, is valid for 12 hours and can be revoked by the merchant at any time. Expired or revoked links are deleted after 7 days.
7. Stored reports and exports
When a count is closed, the app generates the inventory list, the deviation list and, if chosen, a valued list as PDF and stores them with a checksum. The reports contain per line who counted and when, signature lines for counters and reviewer, who closed the count, remarks and reasons for differences, the location with its address and the shop name. They serve the merchant as evidence of the stock take and remain stored as long as the app is installed.
CSV exports (inventory list, log) are generated on request and not stored.
8. Usage statistics
To improve the app without third-party tools we count a few steps per shop: installation, first count, booking, uninstall.
After the shop’s data has been deleted (section 10), one row per shop remains in which the shop domain is replaced by a hash (HMAC-SHA256 with a secret key); dates are rounded to the day. This is pseudonymization, not anonymization. These rows are deleted 24 months after the uninstall.
9. Server logs
The server logs contain session IDs, the shop domain, steps of the usage statistics and error messages from Shopify, never counters’ names or free text. Addresses are written without parameters, access keys in paths are masked. The proxy on our server keeps no access log. The logs rotate by size (3 × 10 MB per container) and are overwritten in the process; depending on traffic that is a few days to weeks.
10. Retention and deletion
As long as the app is installed it deletes nothing automatically. Merchants have their own retention obligations for stock take records.
After an uninstall Shopify notifies the app. 48 hours later the app deletes all data of the shop from the database, including the stored reports. The data then remains in the encrypted backups for up to 30 more days, because the backups are locked against changes and early deletion; after that it is deleted there as well. Download the PDF reports before uninstalling if you need them for your records.
Entries recorded by a device without a connection stay only on that device until they are transferred.
11. Backups
The database and the stored reports are backed up daily, encrypted with our own key before upload and kept unchangeable for 30 days in Hetzner Object Storage in Falkenstein.
12. Rights of counters
Counters direct requests about their data to the merchant they counted for; the merchant is the controller. We support the merchant on instruction: with access requests (the merchant can filter the log per person) and with rectification and erasure of names (pseudonymization of all name fields; quantities and times remain). Stored PDF reports stay unchanged by default because the merchant has to keep them (Art. 17 (3) (b) GDPR); on the merchant’s express instruction we delete them.
13. Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – server (Nuremberg) and backups (Falkenstein).
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – email (Google Workspace), only where merchants send us personal data by email in support.
Details are in the data processing agreement.
14. Changes
We update this privacy policy when the app or the legal situation change. The version published here applies.
Back to Inventur & Stock Take for Shopify
Last updated: 2026-10-09