This policy explains what data Hide Out of Stock (“the App”, “we”) accesses and stores when you install it on your Shopify store. We are committed to collecting only what we need to operate the App.
Hide Out of Stock is published by CartWorks.io. For privacy questions, contact hello@cartworks.io.
Hide Out of Stock automatically hides products in your Shopify catalog when they reach your stock threshold, and restores them when stock returns. It also offers optional image and collection filters, unavailable-variant hiding, hidden-URL redirects, manual scans, restore-all, and a daily safety-net sync.
When you install the App, you grant the following permissions, used only to perform the features above:
read_inventory — read inventory levels and inventory tracking state to determine availability.read_products — read product, variant, collection, image, and tag information so we know which products to act on.write_products — change a product’s status to draft (hide) or active (restore).read_themes — list themes for the optional theme embed (redirecting /collections/all).write_online_store_navigation — create and remove URL redirects on your store when the optional “Redirect hidden URLs” feature (Pro plan) hides or restores a product, so visitors are forwarded to a relevant collection instead of seeing a 404.write_publications — unpublish an unavailable product variant from your Online Store, and re-publish it when it’s available again, for the optional “Hide unavailable variants” feature.We store the minimum needed to run the App on your behalf:
your-store.myshopify.com).We do not read or store customer names, customer emails, addresses, orders, or payment data. The store owner’s business contact email may be stored for optional lifecycle messages.
The App runs on Cloudflare Workers and stores data in Cloudflare D1 (a managed SQL database). Cloudflare acts as our infrastructure sub-processor. See Cloudflare’s privacy policy.
If lifecycle messaging is enabled for this deployment, Brevo acts as an email and contact-management sub-processor. See Brevo’s privacy policy. If lifecycle messaging is not configured, no data is sent to Brevo.
We keep operational data for as long as the App is installed. When you uninstall, Shopify sends
an app/uninstalled webhook and we immediately delete the shop’s local operational data.
If lifecycle messaging is enabled, the shop email may remain in Brevo in an uninstalled state to
deliver the optional feedback request; you can request its deletion at any time. After uninstall,
we retain only that email in a short compliance record so Shopify’s delayed
shop/redact request can identify and delete the Brevo contact; that record is removed
after the request succeeds. We also handle customers/data_request and
customers/redact; because we do not store customer data, those requests contain nothing
for us to disclose or redact.
You can uninstall the App from your Shopify admin at any time, which triggers deletion of local operational data. You may also email us at hello@cartworks.io for any data-related request.
All connections to the App use HTTPS. Webhook calls from Shopify are verified with HMAC signatures. Access tokens are stored only in our database and are never exposed to the merchant admin UI or to third parties.
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated via the App listing.
For any question about this policy or your data, please email hello@cartworks.io.