Privacy Policy
Last updated: 2026-07-20
This Privacy Policy explains how Grenz ("SkuVitals", "we", "us") handles data when a merchant
installs and uses the SkuVitals inventory-health app ("the App") on their Shopify store.
Summary
- The App analyses your catalog and inventory and reports on dead stock, slow movers, and catalog-health issues.
- We do not store your customers' personal information. Order data is used only to compute per-variant sales aggregates — never customer names, emails, phone numbers, or addresses.
- We store the minimum store and catalog data needed to provide the App, plus your Shopify access token, encrypted at rest.
Data we access and store
Store profile. Your .myshopify.com domain, store name, the store contact email Shopify provides, currency,
and timezone. We store your Shopify access token encrypted at rest and never write it to logs or telemetry.
Catalog & inventory. Products, variants, inventory levels and locations, and catalog metadata (titles, SKUs, tags, SEO fields, image counts). We use these to compute health scores and detect data-quality issues.
Sales aggregates (order-derived). To measure how fast inventory sells, the App reads order line items and folds them into rolling per-variant totals (units sold and gross sales over trailing windows, plus first/last sold dates). It requests no customer fields from Shopify, streams the results, and stores only the aggregates — raw orders are never written to our database.
Customer personal data. None is stored. The App does not collect or retain customer names, email addresses, phone numbers, shipping/billing addresses, IP addresses, or order notes.
How we use data
To operate the App: analyse inventory health, surface dead stock and catalog issues, generate the reports and CSV exports you request, apply the merchant actions you initiate (e.g. bulk tagging), and manage your subscription through Shopify's Billing API. We do not sell your data or use it for advertising.
Website analytics
Our public marketing website uses Google Analytics to understand aggregate site traffic — but only after a visitor accepts our cookie-consent banner. This concerns visitors browsing our marketing pages, not your store data or your customers, and the embedded App itself uses no analytics. See our Cookie Notice(/legal/cookies) for the cookies involved and how to opt out.
Sub-processors
We share data only with the service providers necessary to run the App — see our Sub-processors(/legal/sub-processors) page. Billing is handled by Shopify; we do not process or store card details.
Retention and deletion
We keep data only as long as needed to provide the App. Generated export files are deleted automatically after
their download window lapses. When you uninstall, we disconnect and clear your access token; your store data is
then deleted when Shopify sends the shop/redact request (approximately 48 hours after uninstall). See our
Data Retention Policy(/legal/data-retention) for details.
Your rights (GDPR / CCPA / CPRA)
Depending on your jurisdiction you may have rights to access, correct, export, or delete data we hold about your
store, and to object to or restrict certain processing. Because we hold no customer personal data, Shopify's
customer data-request and redaction webhooks are acknowledged with nothing to return or delete. To exercise a
right regarding your store data, contact us at hellogrenz@gmail.com. Our legal basis for processing store and
catalog data is the performance of our agreement with you.
Security
Access tokens are encrypted at rest, every Shopify webhook is verified by HMAC over the raw request body, each store's data is isolated from every other store's, and tokens and personal data are scrubbed from logs and error telemetry.
Changes
We may update this policy; the "Last updated" date will change and material changes will be communicated
an in-app notice.
Contact
Grenz, 24, St.6, SGNR, Rajasthan, India — hellogrenz@gmail.com.
SkuVitals