← StockPilot

Privacy policy

Last updated 7 September 2026

StockPilot is provided by Fleeta Limited. It is a merchant-facing inventory operations app for purchase orders, suppliers, receiving, stocktakes, transfers, bulk inventory edits, demand forecasting and inventory reporting. We process data only to run those workflows for the Shopify store that installed the app.

Data we store

For each installed store we store the shop domain and Shopify shop identifier; Shopify sessions, including the encrypted access token and encrypted session payload, together with the granted scopes, the session expiry and, for the staff member signed in through Shopify, their Shopify user id, first name, last name, email address, locale, account-owner flag, collaborator flag and email-verified flag; and the operational records the merchant creates in the app. Those records are supplier profiles (supplier name, contact name, contact email address, contact phone number, currency, lead time, minimum order quantity, free-text notes, attachment names and links, and receiving performance counters), supplier to variant mappings, purchase orders and their lines, receiving events, stocktakes and counted quantities, transfers, bulk inventory operations, forecast results, single-variant inventory corrections (the inventory item, the location, the quantity before and after, the short reason the merchant types and the Shopify adjustment id it produced), any CSV rows a merchant pastes into the migration centre, and any private feedback a merchant chooses to send us in the in-app feedback prompt. Those records also hold a snapshot of the Shopify product title, variant title, SKU and the quantities involved in the operation they describe, so a purchase order, count or forecast still reads correctly after the catalog changes. We also store an audit trail of app actions, which includes a copy of the record data saved by each action, and the raw payloads of the Shopify webhooks we receive.

Data we read from Shopify but do not store

Products, variants, SKUs, inventory items, inventory quantities, inventory transfers, inventory shipments and locations are queried live from the Shopify Admin API each time a screen or report is rendered. Shopify remains the source of truth: StockPilot does not sync your catalog and does not keep a shadow copy of your live stock levels. The only catalog and quantity values it keeps are the snapshot fields written into an individual purchase order, receipt, stocktake, transfer, bulk operation, inventory correction or forecast, described in the previous section. For forecasting we query your recent Shopify orders and read only the line-item quantity and the variant identifier on each line, which we total into a units-sold figure per variant; that total and the reorder figures derived from it are kept when a forecast is saved. We do not request, receive or store customer names, email addresses, phone numbers, shipping or billing addresses, order numbers, payment data or any other customer identifier.

Why we process it

We use this data to provide the app: to authenticate the store with Shopify, to build and print purchase orders for your suppliers, to record what was received, counted, transferred or corrected, to write the resulting quantities back to Shopify when you confirm an operation, to calculate reorder recommendations, to produce reports and CSV exports you request, to keep an auditable history of who changed what, to answer support questions and to meet legal obligations. We do not sell data, we do not use it for advertising, and we do not use it to train models.

Shopify permissions we request

StockPilot requests read_products, read_inventory, write_inventory, read_locations, read_orders, read_inventory_transfers, write_inventory_transfers, read_inventory_shipments, write_inventory_shipments and write_inventory_shipments_received_items. The write permissions exist because the app sets inventory quantities, creates and cancels inventory transfers and receives inventory shipments on your instruction. read_orders is used only for the sales-velocity input to forecasting, as described above.

Sharing and third parties

Data is shared with Shopify, which is the source and destination of every catalog, inventory, location, transfer and shipment operation, and with the hosting infrastructure Fleeta Limited operates for the app. In addition, when a store installs StockPilot for the first time, the app sends a single server-side install notification to Shoffi, an install-attribution provider, at platform.shoffi.app. That notification contains the store's myshopify.com domain, the StockPilot application id and the IP address of the request that completed the install. It is sent once per new installation and is not repeated on later sign-ins or token refreshes. If the same store also installs Inbound ETA, a separate Fleeta Limited app, that app can read this store's StockPilot purchase-order records so an inbound shipment can be linked to the order it belongs to; that link is limited to the same store and to purchase-order records. StockPilot does not send email to your customers, does not use an email or SMS provider, and does not embed analytics or advertising trackers.

Retention

We keep the data described above for as long as the app is installed. Uninstalling the app does not by itself delete it: Shopify sends a shop redaction request after an uninstall, and that request is the deletion event. When it arrives we delete the store record and every session, operational record, audit event, stored webhook payload, queued job and billing record attached to it. StockPilot does not currently run any additional scheduled purge, so an installed store's audit history and stored webhook payloads are retained for the life of the installation rather than for a fixed period. A merchant who wants their data removed sooner can uninstall the app and email us at accounts@fleeta.co.uk.

Shopify privacy webhooks

StockPilot subscribes to the three mandatory Shopify compliance topics. A shop redaction request deletes all data for that store, as described above. Because StockPilot stores no customer personal data, a customer data request and a customer redaction request have no customer records to return or erase; each one is recorded in the store's audit trail as an explicit statement of that boundary, so the outcome can be evidenced later. If that ever changes, this policy will change with it.

Security

Traffic to StockPilot is served over TLS. Shopify access tokens and the full session payload are encrypted with AES-256-GCM authenticated encryption before they are written to the database. Incoming webhooks are verified against Shopify's HMAC signature before they are accepted, and duplicate deliveries are rejected by a uniqueness constraint. Every query the app makes is scoped to a single store and to StockPilot's own application key, and session records are namespaced per app, so one store can never read another store's data and no other app can load a StockPilot session. The single deliberate exception is the Inbound ETA link described above, which reaches only the same store's purchase-order records.

Your rights

The merchant is the controller of the data in their store and Fleeta Limited processes it on the merchant's instructions. Merchants can view the records StockPilot holds inside the app, add new ones, export the inventory and records report as CSV, and delete everything by uninstalling and allowing Shopify's redaction request to complete. The app does not currently provide a control that edits, archives or deletes an individual saved record, so a correction to one record, or an early deletion of it, is handled by us on request. Requests to access, correct or delete data, and any question about this policy, can be sent to accounts@fleeta.co.uk.

Changes

If we change what StockPilot processes, we will update this page and the date at the top of it before the change reaches production.

Contact

Fleeta Limited, United Kingdom. Privacy and security enquiries: accounts@fleeta.co.uk.