Winslet Back In Stock
Privacy Policy
Last updated: August 21, 2026
1. Introduction
Your privacy matters to us. Winsletapps (“we,” “us,” or “our”) develops and operates the Shopify app Winslet Back In Stock (the “App”). This Privacy Policy explains how we collect, use, store, share, and protect information when a merchant installs and uses the App, and when a merchant’s storefront visitors use the App’s “notify me when available” widget to request a back-in-stock alert.
By installing the App, the merchant agrees to the practices described here.
Scope: This Privacy Policy applies only to information collected through the App.
Roles: When a Shopify merchant installs the App, that merchant is the data controller of its store and customer data. We act as a data processor, handling this data on the merchant’s behalf to provide the App’s features.
2. Information We Collect
2.1 Store data accessed through Shopify
The App requests the following access scopes: read_products, read_inventory, write_app_proxy. This allows the App to check current inventory levels for products and variants, detect when a variant becomes available again, and run the storefront endpoint that lets a shopper submit their email address to join the waiting list for an out-of-stock product. The App does not request access to customer names, order history, or checkout data, and does not use those access scopes.
2.2 Back in stock subscription requests
When a storefront visitor uses the App’s “Notify me when available” widget on an out-of-stock product, they submit their email address, along with the product and variant they’re interested in. The App stores this email address together with the associated product and variant information and a status (waiting, notified, or cancelled), so it can send a one-time notification email once that variant is back in stock. This information is retained until the visitor is notified, the subscription is cancelled, the merchant removes it, or the merchant uninstalls the App (see Section 6).
2.3 Notification delivery records
When a restock notification is sent, the App records that a message was queued, sent, or failed for a given subscription, including a timestamp and a delivery message identifier from our email service. This record does not contain any additional personal information beyond what is described in Section 2.2.
2.4 Merchant configuration
Merchants can configure the App’s widget text, notification email subject and content, and plan settings. This configuration is store-level and is not personal information about any individual shopper.
2.5 Inventory and webhook data
To detect when a product variant becomes available again, the App receives Shopify inventory webhook data containing product, variant, and inventory quantity information. This data is not linked to an individual shopper.
2.6 Information you provide to us directly
If you contact us for support, we collect the details you provide, such as your name, email address, and message.
3. How We Use Information
- Operate the storefront “notify me when available” widget and maintain the waiting list it creates
- Detect restocks and send the one-time notification email through our email delivery provider
- Enforce the merchant’s selected plan, such as waiting-list limits on the Free plan
- Show the merchant subscription and notification analytics in the App’s dashboard
- Respond to support requests
- Monitor, troubleshoot, and improve the App
- Meet legal and regulatory obligations, including Shopify’s compliance webhook requirements
We do not sell personal information, and we do not use a shopper’s email address for our own marketing.
4. Legal Bases for Processing (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, to provide the App; legitimate interests, to operate and secure the App and fulfill back-in-stock requests; and legal obligation. For store and customer data processed on a merchant’s behalf, the merchant determines the legal basis as data controller.
5. How We Share Information
- Shopify — the App runs on the Shopify platform and exchanges data with Shopify’s APIs, including the Admin and webhook APIs, to function.
- Service providers (subprocessors) — we use Fly.io and Neon to host the App and its data, and Resend to deliver the restock notification email to the shopper on the merchant’s behalf. These providers process data only under our instructions.
- Legal and safety — we may disclose information where required by law.
- Business transfers — if we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction.
We do not disclose personal information to third parties for their own marketing.
6. Data Retention and Deletion
A shopper’s email address and associated back-in-stock subscription are retained only for as long as needed to fulfill the request: until the notification is sent, the subscription is cancelled by the shopper or merchant, or the record is deleted as described below.
When a merchant uninstalls the App, we delete the shop’s data within 48 hours, unless a longer period is required by law.
We comply with Shopify’s mandatory compliance webhooks:
- customers/data_request — we return any stored back-in-stock subscription and notification records linked to the specified customer’s email address.
- customers/redact — we permanently delete stored subscription and notification records linked to the specified customer’s email address.
- shop/redact — we delete the shop’s data after uninstall.
7. Data Security
We take reasonable technical and organizational measures to protect information, including HTTPS encryption in transit, encrypted database storage at rest, and environment-secured credentials restricting system access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Data Transfers
We may process and store information in the United States. Where required, we put appropriate safeguards in place for international transfers.
9. Your Rights
Depending on your location, you may have the right to access, correct, delete, or restrict the use of your personal information, object to certain processing, request data portability, and withdraw consent. To exercise these rights for data we control directly, contact us using Section 12.
If your request concerns data submitted to a specific merchant’s store, please contact that merchant directly, as they control that data. We will assist the merchant as their processor.
10. Children’s Privacy
The App is business software that merchants use to let their shoppers request back-in-stock notifications, and is not directed to children under 16. We do not knowingly collect personal information from children through the App’s own administrative interfaces. If a parent or guardian believes a child has submitted their email address through the App’s storefront widget, they may contact us using Section 12 to request deletion.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date. Significant changes may be communicated through the App or by email.
12. Contact Us
Winsletapps
ajmal.developer@gmail.com