Privacy Policy
1. Overview & Architectural Commitment
VibeStock is a product of Ancon Hill Services LLC ("we", "our", or "the Application"). VibeStock provides catalog validation and inventory synchronization software for merchants using the Shopify platform. VibeStock is engineered under a strict Zero-Customer-PII architecture: we do not collect, process, store, or profile consumer personal data, customer names, shipping addresses, phone numbers, payment details, or individual shopper order histories.
2. Information We Process
We process exclusively the technical and business data required to validate catalogs and synchronize inventory:
- Shopify Store Identifiers: Store domain (e.g.,
store-name.myshopify.com), internal Shopify Shop ID, and offline API access tokens required for Admin API communication. - Supplier Catalog Data: Product titles, descriptions, vendor names, handles, variant identifiers, Stock Keeping Units (SKUs), barcodes, pricing values, and supplier inventory quantities uploaded via CSV and XLSX spreadsheets.
- Subscription & Entitlement State: Selected commercial plan handle, billing period, subscription lifecycle status (Trial, Active, Cancelled, Frozen), Managed Active SKU counts, and Shopify Partner billing cycle timestamps.
- Operational & Telemetry Logs: Ephemeral server-side request logs, API response status codes, synchronization execution durations, and error diagnostics required for system reliability.
3. Purpose of Processing
Your business and catalog data is processed solely to:
- Validate supplier catalog files against business rules prior to store synchronization;
- Create and update product listings and inventory quantities in your authorized Shopify store;
- Enforce Managed Active SKU allowances corresponding to your chosen commercial plan;
- Provide line-level error diagnostics and historical audit trails in your merchant dashboard.
4. Data Sharing & Third Parties
VibeStock does not sell, rent, monetize, or disclose merchant catalog data to data brokers or advertising networks. Data is shared exclusively with:
- Shopify: To execute authorized GraphQL product and inventory mutations via the Shopify Admin API;
- Infrastructure Providers: Hosted securely on Microsoft Azure (Northern Europe region) utilizing Azure Container Apps, Azure Database for PostgreSQL Flexible Server, and Azure Key Vault under strict access control.
5. Multi-Tenant Isolation & Security
Relational Row-Level Security (RLS): All catalog records, staged imports, sync logs, saved mapping profiles, and billing caches are stored in PostgreSQL tables protected by FORCE ROW LEVEL SECURITY. Each database query is strictly partitioned by tenant_id session context.
Secret Encryption: Store access tokens and platform API secrets are encrypted using AES-256-GCM via dedicated keys in Azure Key Vault and are never committed to source control or logged in diagnostic payloads.
6. Data Retention & Mandatory GDPR Lifecycles
- Active Installation: Catalog data and operational logs are retained for the duration of your active installation to maintain synchronization continuity.
- App Uninstallation (
app/uninstalled): When you uninstall VibeStock, your subscription status transitions immediately toCancelled, store access tokens are authoritatively revoked, and all background synchronization mutations are permanently blocked. - Store Redaction & Permanent Erasure (
shop/redact): In accordance with Shopify platform requirements, Shopify dispatches a mandatoryshop/redactwebhook (scheduled by Shopify, typically approximately 48 hours following app uninstallation). Upon verified receipt of this webhook, VibeStock automatically orchestrates permanent, irreversible deletion of all tenant data across all system components. - Customer Data Webhooks (
customers/data_request,customers/redact): Because VibeStock stores zero customer or order PII, customer data requests receive an immediate, automated technical acknowledgement confirming that no customer records exist within our systems.
7. Merchant Rights & Inquiries
Privacy Contact: support@vibestock.app
In-App Inquiries: Accessible directly within your Shopify Admin under Apps > VibeStock Catalog Sync
Governance: Ancon Hill Services LLC, Attn: Privacy Contact.