Parwise: Reorder Points ("Parwise", "the app", "we", "us") is a Shopify app that helps merchants prevent stockouts by tracking inventory levels, computing sales-velocity reorder points, and managing purchase orders with suppliers. This policy explains what data the app accesses and stores, how we use it, who we share it with, and what rights you have.
The app is operated by Ioannis Kerkinos (sole operator). Contact details are in Section 9.
With your authorization, the app accesses your Shopify store's orders, products, inventory levels, and locations through the Shopify Admin API. We use this access solely to compute reorder points from your sales velocity and to manage purchase orders with your suppliers.
Specifically, the app reads:
The app does not request or read customer names, email addresses, phone numbers, or shipping
addresses. It does not use a read_customers scope and has no access to end-customer
personal data.
The table below summarizes every category of data the app stores.
| Data | Contains personal data? | Purpose | Retention |
|---|---|---|---|
| Store domain and Shopify access/refresh tokens | Merchant store credential (not end-customer data) | Authenticate Admin API calls | Until uninstall or shop/redact, then deleted |
| Subscription plan state | No | Entitlements (feature access by plan tier) | Until shop/redact |
Raw inbound webhook payloads (including orders/create) |
Transiently yes (an order payload includes buyer fields while in transit) | Async processing via the outbox queue; velocity computation only | Once processing reaches a terminal state, the payload becomes purge-eligible after 7 days and is removed by the next daily purge (02:00). Entries still processing or retrying are retained until they reach a terminal state, then follow that schedule. |
| Inventory products (SKU, on-hand per location) | No (SKU and item IDs only) | Reorder dashboard | Until shop/redact |
| Velocity aggregates (average daily sales, reorder point, on-hand thresholds) | No (SKU and quantity only) | Reorder-point formula | Until shop/redact |
| Purchase orders (SKU, quantity, supplier) | No (no customer fields) | PO lifecycle management (Pro and Scale plans) | Until shop/redact |
| Suppliers (supplier name, lead time) | No (merchant-defined supplier records) | PO creation and lead-time defaults | Until shop/redact |
| Alert settings (merchant-chosen recipient email address, webhook URL, channel toggles) | Merchant contact data (the recipient address the merchant enters, not end-customer data) | Deliver low-stock alerts to the merchant's chosen email and/or webhook | Until shop/redact |
| Low-stock alert records (SKU, on-hand, reorder point, status) | No (SKU and unit figures only) | In-app alert feed and re-alert cooldown | Until shop/redact |
| Web vitals and product events | No | App performance and funnel telemetry (internal only) | Until shop/redact |
What Parwise retains, and what it does not. The only long-lived records hold derived inventory figures: SKU, quantities, prices and currency, and supplier data. They never include a customer name, email address, or phone number. Raw order payloads, which do carry buyer fields in transit, are held only in the processing queue until the velocity computation is complete; once an entry reaches a terminal state it becomes purge-eligible after 7 days and is removed by the next daily purge (02:00), while entries still processing or retrying are retained until they terminalize. Buyer fields are never read, used, or retained beyond that queue processing.
Parwise retains no end-customer personal data. The derived data we keep (SKU, quantities, prices and currency, and supplier data) contains no customer names, email addresses, physical addresses, phone numbers, or payment details. The only place buyer fields appear is inside raw order payloads transiting the processing queue; those payloads are used solely to compute velocity aggregates and are then purged on the schedule above (terminal after 7 days, removed by the next daily purge at 02:00; active or retrying entries held until terminal). No buyer field is read, stored, or used beyond that queue processing.
We use the data described above only to provide the Parwise service: showing you which SKUs are running low, computing when and how much to reorder, and managing the purchase order lifecycle with your suppliers. We do not use your data for advertising, profiling, or any purpose outside the service you signed up for.
We do not sell or share your data with third parties for marketing or advertising purposes. The app relies on the following sub-processors to operate:
No advertising networks, analytics SDKs, or other third parties receive your data. The core reorder formula is deterministic software running on our servers and uses no AI. The only AI processing is the optional restock-note feature described above, which receives the PII-free inventory figures listed there and nothing else.
We apply the following technical safeguards:
Parwise honors Shopify's three mandatory privacy-compliance webhooks, all protected by HMAC-SHA256 verification:
customers/data_request): Acknowledged and
logged. The app retains no end-customer personal data, so there is nothing to disclose.
customers/redact): Acknowledged and logged.
The app retains no per-customer data, so there is nothing to erase.
shop/redact): Permanently and completely removes all
data for your store via cascading database deletion, including all inventory products, velocity
entries, reorder points, purchase orders, suppliers, staging events, and subscription records.
Inventory and velocity data are retained while the app is installed on your store. On uninstall,
and on receipt of a valid shop/redact request from Shopify, all data for your store
is permanently deleted. You may also request deletion at any time by contacting us at the address
in Section 9.
If you are a merchant in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection law, you may have rights to access, correct, or erase the merchant-scoped data we hold about your store. To exercise any of these rights, contact us at support@parwise.app.
Support and privacy enquiries: support@parwise.app
Data controller: Ioannis Kerkinos (sole operator)