Restock privacy policy
Last updated: September 28, 2026
Restock (“the App”) is a Shopify app made by cloud2k (“we”, “us”). It lets shoppers ask to be notified when a sold-out product is available again. This policy explains what data the App handles, why, and how it is deleted. It applies to merchants who install the App and to shoppers who sign up for an alert in a store that uses it.
Data we collect
From merchants, when the App is installed:
- The store's Shopify domain and the access token Shopify issues to the App.
- Store name, contact email and primary domain, read from Shopify when an alert is sent (used as the email sender name and reply-to address).
- Product and inventory information for the products shoppers sign up for (title, variant, image, handle and stock level).
From shoppers, only when they submit the “Notify me” form:
- Email address.
- The product variant they want, and the store language they were browsing in.
- The date of the sign-up and whether the alert has been sent.
The App does not use cookies on the storefront and does not collect payment information, addresses or browsing history.
How we use the data
- To send one email to the shopper when the product they asked about is back in stock.
- To show the merchant who is waiting and which products are most requested.
- To operate, secure and troubleshoot the App.
We never sell shopper data, never add shoppers to marketing lists, and never use the data to contact shoppers for our own purposes. The merchant is the controller of their shoppers' data; we process it on the merchant's behalf.
Service providers
We use a small number of providers to run the App: our hosting and infrastructure providers (including Cloudflare) to run the App and store its data, and Resend to deliver alert emails. They process data only to provide their service to us.
Retention and deletion
- Shopper sign-ups are kept until the merchant uninstalls the App or the data is deleted on request.
- When Shopify tells us a customer asked to be forgotten (customers/redact), we delete that shopper's sign-ups for that store.
- When a merchant uninstalls the App, Shopify sends a deletion request 48 hours later (shop/redact) and we delete all data for that store.
Your rights
Depending on where you live (for example under the GDPR or CCPA), you may have the right to access, correct or delete your personal data, or to object to its processing. Shoppers can exercise these rights through the store where they signed up, or by contacting us directly. We respond to data requests Shopify forwards to us (customers/data_request).
International transfers
cloud2k is based in Argentina and our providers may process data in other countries, including the United States and Brazil. We rely on our providers' standard safeguards for these transfers.
Changes
If we change this policy we will update the date above. Material changes will be announced to merchants in the App.
Contact
Questions about privacy: support@cloud2k.com, or any channel on our contact page.