Plumb Privacy Policy
Last updated: September 26, 2026
Plumb is a Shopify app for stocktakes and cycle counting (the “App”), provided by TGProd (“we”, “us”). The merchant who installs the App is the data controller of their store data; we act as a data processor on their behalf and use data only to provide the App’s functionality.
1. What we access
Using only the Shopify access scopes a merchant grants at install, the App accesses:
- Products and variants — title, SKU, barcode, image, vendor, product type, tags and unit cost, to build count lists and to price a variance.
- Locations and inventory — on-hand quantities at the location being counted, read at the moment of counting and written back only on approval.
- Orders — read to rank products by sales velocity. Only line quantities and line totals are used, aggregated per product variant. Customer, contact, shipping, and payment fields are never requested and never stored.
- Staff identity — the Shopify staff member ID of whoever counted a line or approved a count, and the name of the POS device it was counted on, so a count carries an audit trail.
2. What we store — and what we don’t
We do not store customer personal data. No customer names, emails, addresses, phone numbers or payment details are written to our database at any point, and order webhook payloads are not persisted or logged.
We store, per shop:
- Count sessions and their lines — what was scheduled, expected and counted, when, on which device, by which staff member ID, with the variance reason given and the unit cost as it stood when the line was created.
- Stock movements observed while a count was open, recorded as inventory item and quantity so a variance can be explained.
- A mirror of product and variant identity (title, SKU, barcode, image, vendor, type, tags, cost), which is what lets counting work on a POS device with no network.
- Sales velocity aggregated per variant — units, revenue and order count over a rolling window, and the resulting ABC class. No order or customer records are kept.
- Catalogue sync history, and which onboarding steps a shop has completed or dismissed.
- Shopify session tokens for the shop, which authenticate the App’s own API calls.
Separately from the App’s database, we keep an operational log on monitoring infrastructure we run ourselves: a record of each install and uninstall (the shop’s domain, store name and contact email), and reports of errors the App encounters (the error message, where in the App it occurred, and the shop it occurred for). Error reports never include order, customer or product data.
3. How we use data
We process data solely to provide App functionality to the merchant: to rank the catalogue and build each day’s count list, to hand that list to staff in the admin and on Shopify POS, to compare counted quantities against Shopify’s record, to write approved adjustments back to inventory with the merchant’s chosen reason, to reverse an applied count on request, and to produce the App’s accuracy, variance and audit reports. We do not sell personal data, and we do not use it for advertising or profiling.
4. Sub-processors
| Provider | Purpose |
|---|---|
| Shopify | Source platform hosting the merchant’s data, and the destination for approved inventory adjustments |
| Railway | Application hosting and database |
The operational log described in section 2 runs on infrastructure we operate ourselves, not a third-party service. The App sends no data to any other third party. If a merchant emails us or books a support call, that correspondence is handled by our email and scheduling providers and is kept separately from store data. We may disclose data if required by law. We do not otherwise share personal data with third parties.
5. Data retention and deletion
We retain data while the App is installed and needed to provide functionality. When a store uninstalls the App, its session tokens are deleted immediately; Shopify then sends a shop/redact request approximately 48 hours later, on receipt of which we permanently delete every record we hold for that shop — count sessions and their lines, stock movements, the catalogue mirror, sync history, velocity data and onboarding state. Nothing is soft deleted. The install and uninstall record in our operational log is kept for account administration — knowing which stores have used the App — and is deleted on request. We also honor Shopify’s customers/data_request and customers/redact webhooks; because we store no customer personal data, there is no customer information to return or erase.
6. Security
We apply protections appropriate to Shopify’s data requirements: encryption in transit (HTTPS/TLS) and at rest, including encrypted backups; HMAC signature verification on every inbound Shopify webhook, with unsigned requests rejected before processing; session-token authentication on the App’s own POS endpoints; secret management for tokens and API credentials; and limited staff access to production data.
7. International data transfers
Data may be processed in the United States and other regions where our infrastructure providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards as required by applicable law.
8. Your rights
Depending on your jurisdiction (e.g. GDPR, UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, restrict, or port personal data. Customers of a store should contact the merchant they purchased from, who can action requests through Shopify. Merchants can delete their data by uninstalling the App, or by contacting us at tom@tgprod.dev.
9. Children’s data
The App is a business tool, is not directed to children, and does not knowingly process children’s personal data.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
11. Contact
TGProd — tom@tgprod.dev