Privacy Policy

EF: Back in Stock Alerts

This Privacy Policy explains how EcomFlow Digital collects, uses, stores, and protects information when merchants install and use EF: Back in Stock Alerts.

Effective date: June 28, 2026

1. About this app

EF: Back in Stock Alerts is a Shopify app that helps merchants collect customer email addresses on sold-out product variants and send email notifications when the selected product or variant is available again.

The app is designed for email-only restock notifications. It does not process payments, replace Shopify checkout, or sell customer data.

2. Information we collect

We collect only the information needed to provide the back-in-stock notification service.

  • Merchant store information: shop domain, store name, app installation status, app settings, selected design settings, subscription status, and theme app block status.
  • Product and inventory information: product ID, product title, product handle, product URL, variant ID, variant title, product image URL, and inventory availability needed to match restock alerts to the correct product variant.
  • Customer notification information: customer email address, requested product, requested variant, notification status, request date, and sent date.
  • Email sender settings: sender name, sender email, SMTP verification status, and SMTP app password if the merchant chooses to connect their own sender.
  • Technical information: basic logs, request timestamps, webhook delivery information, and error logs needed to operate and secure the app.

3. How we use information

We use collected information to:

  • Display the back-in-stock form on sold-out product variants.
  • Save customer restock notification requests.
  • Match each request to the exact product and variant selected by the shopper.
  • Send restock notification emails when inventory becomes available.
  • Let merchants manage pending and sent notifications inside the app.
  • Let merchants customize the storefront alert block.
  • Verify and use merchant-provided SMTP sender settings.
  • Maintain app security, prevent abuse, and troubleshoot errors.
  • Meet Shopify platform and legal compliance requirements.

4. Customer email addresses

Customer email addresses are collected only when a shopper submits a back-in-stock request through the merchant’s storefront. These email addresses are used to send the requested restock notification.

We do not sell customer email addresses. We do not use customer email addresses for unrelated marketing. Merchants are responsible for ensuring that their use of customer emails complies with applicable email marketing, privacy, and consent laws.

5. SMTP sender information

Merchants may connect their own email sender using SMTP. If a merchant chooses this option, the app stores the SMTP app password and sender email so restock emails can be sent from the merchant’s verified sender.

Merchants should use an app password or provider-specific SMTP password, not their normal mailbox password. The app uses this information only to verify SMTP access and send restock notification emails for the merchant’s store.

6. Shopify data access

The app accesses Shopify store data only as needed to provide its functionality. This may include product, variant, inventory, store, and app installation information.

The app uses Shopify webhooks to respond to relevant store events, such as inventory updates and app uninstallation. The app also supports Shopify’s required privacy and data compliance webhook requests.

7. Data sharing

We do not sell personal information. We may share limited information only with service providers needed to operate the app, such as:

  • Hosting and database providers.
  • Email delivery or SMTP services selected by the merchant.
  • Logging, security, or infrastructure services.
  • Shopify, when required for app platform functionality.

These providers are used only to operate, maintain, secure, and improve the app.

8. Data retention

We keep merchant settings and notification records while the app is installed and as needed to provide the service. If a merchant uninstalls the app, we may delete or anonymize store-related data after a reasonable period unless retention is required for legal, security, billing, or compliance reasons.

Customer restock notification records may be retained so merchants can review pending and sent notifications, prevent duplicate notifications, and troubleshoot email delivery.

9. Data deletion and access requests

Merchants may contact us to request access, correction, or deletion of app data associated with their store.

Shopify may also send mandatory privacy webhook requests, including customer data requests, customer redaction requests, and shop redaction requests. We process these requests in accordance with Shopify’s requirements.

10. Security

We use reasonable technical and organizational safeguards to protect information processed by the app. These safeguards may include HTTPS, access controls, environment-based secrets, database protections, webhook verification, and restricted access to production systems.

No method of transmission or storage is completely secure. Merchants should protect their Shopify account, email account, SMTP app password, and admin credentials.

11. Cookies and tracking

The app may use necessary technical cookies, Shopify session mechanisms, or similar technologies required for authentication, security, and app functionality inside Shopify admin.

The storefront app block may send a lightweight technical request to confirm that the block is installed and active. This is used only to show app setup status to the merchant.

12. International data transfers

Information may be processed in countries where our hosting, infrastructure, database, or service providers operate. By using the app, merchants understand that information may be processed outside their country or region.

13. Merchant responsibilities

Merchants are responsible for:

  • Providing accurate privacy notices to their own customers where required.
  • Ensuring they have a lawful basis or required consent to collect customer emails for restock notifications.
  • Responding to customer privacy requests that relate to their store.
  • Using email notifications in compliance with applicable laws and Shopify policies.
  • Keeping their SMTP credentials and Shopify account secure.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date on this page. Continued use of the app after changes means the merchant accepts the updated policy.

15. Contact us

For privacy questions, data requests, or support, contact us at:

ecomflowdigital@gmail.com