Nextstock Privacy Policy

Last updated: 2026-09-24

Nextstock is a Shopify app that tells you when to reorder stock. This page explains what we take from your store, why, how long we keep it, who else sees it, and how to get it deleted.

The short version. We look at what you sold and what you have left. We do not store your customers' names or contact details. We do not sell your data or use it for ads.

Who we are

Nextstock is run by BROJAS LLC, an Arizona limited liability company, doing business as Nextstock. Our postal address is available on request at [email protected]. When this page says "we" or "us", it means BROJAS LLC. You can reach us at [email protected].

What we take from your store

When you install Nextstock, you give it permission to read your orders, products, inventory levels, and locations. We use that access to pull:

Order history. A good forecast needs at least a year of sales, so it can see seasonal swings. That is why we ask Shopify for your older orders, not just the last 60 days.

About your store. To run your account we keep your store's Shopify address and ID, store name, the contact email Shopify lists for your store, your timezone and currency, which permissions you granted, when you installed or uninstalled, sync status, your forecast settings, and the access keys Shopify gives us so we can read your store. Those keys are stored encrypted. We also keep a short log of the notices Shopify sends us about your store (what kind, when, and which store), so we can show we acted on them.

Things you give us directly. If you email us for help, we keep that conversation so we can help you.

Files you email us. Some stores get a one-off reorder list by hand before they install the app. If you email us Shopify export files for that, please delete the customer columns first. We use the files only to make your list. If a file still has customer details in it, we do not use it and we ask you to send it again without them. We delete your files, and the copies in our email, within 30 days of sending your list back, or sooner if you ask.

Technical logs. Like almost every web service, our hosting and network providers keep short logs of requests: your IP address, browser type, and the time. We use them only to keep the app secure and to fix problems. When our software hits an error, a report goes to Sentry, an error-tracking service, so we can fix it. A report holds technical details and your store's ID. If the error happened while we were handling one of your records, the report can also hold a piece of that record, such as a product title, a SKU or a quantity. It never holds your customers' details, because we never have them.

What we never take: your customers' details

We do not store or use your customers' names, emails, addresses, phone numbers, IP addresses, or anything else about who they are. We do not even ask Shopify for those fields. If Shopify sends us an order update or a notice that includes them, we discard those parts and keep only what sold, how many, when, and where. We only need to know what sold and how much stock is left, not who bought it.

Shopify's install screen may say Nextstock can view "device and activity data." That label comes with order access, because an order can include the shopper's IP address and browser. We do not read or keep those fields.

Why we need it

We use this data to work out what you will sell next and tell you when to reorder. That's the whole job of the app. We do not sell your data, and we do not use it for advertising.

Our forecasts are suggestions for you, built from totals of what sold and what is in stock. They are not decisions about any individual shopper.

How long we keep it

We keep your store data for as long as Nextstock is installed.

The moment you uninstall, we stop reading your store and erase the keys that gave us access. About 48 hours after you uninstall we delete your shop record, settings and all of the sales, product and stock data we pulled. Shopify also sends us a deletion request around the same time; whichever comes first wins. If you reinstall before the deletion runs, your history stays where it is. Want it gone sooner? Email [email protected] and we will delete it.

A couple of records outlast that deletion: the notice that you uninstalled, and Shopify's request to delete your data if one arrived. They are how we show the deletion happened. Each one holds your store's Shopify address, the kind of notice, and the time, nothing else. We keep them only as long as we may need to show that we deleted your data.

Backups. Once a night we take a copy of our whole database and store it with Cloudflare, in a storage bucket set to North America. Each copy is kept for 27 days and then deleted. So after we delete your store data, it can still sit inside those nightly copies for up to 27 days. We only ever open a backup to recover from a failure, never to look at a store we have deleted.

Who else sees it

No outside AI service sees your data. We run our forecasting model on our own servers. We download the model from Hugging Face when we build our software, never while the app is running, and none of your data goes there. We do not send your data to any AI company, and we do not use it to train or improve models for anyone else.

If we add a provider, we will name it on this page and change the date at the top before it handles your data.

We do not share your data with anyone else, except: if the law requires it, such as a valid court order; if we need to protect our rights or someone's safety; or if Nextstock is sold or merges with another company, in which case the new owner takes over this policy and we will tell you first.

We do not sell or share your data, or your customers' data, for money or for advertising, including as those words are defined by California law. For your store data we act as your service provider. Our Data Processing Agreement sets out the promises that go with that.

How we protect it

Traffic between your store, Shopify, and our servers is encrypted (HTTPS). The connection between our servers and our database is encrypted as well, and both sit inside the same private hosting network. The access keys Shopify gives us are encrypted with our own key before they are saved, and that key is kept separately from the database.

If we learn of a security breach that affects your data, we will tell you without undue delay, explain what happened, and say what we are doing about it.

Where your data lives, and your rights in the UK and EU

We store your data in the United States. If you are in the UK, EU, or Switzerland, that is an international transfer. Our Data Processing Agreement applies to you automatically and covers it with the EU Standard Contractual Clauses (and the UK and Swiss versions of them). Email us if you want a signed copy.

Your store's sales, product, and inventory data belongs to you. We process it only to run the app for you. In privacy law terms, we are a "processor" (or "service provider") for that data, and you are the "controller". For the account details we need to run your account (store name, address, contact email, timezone, currency, settings), we are the controller.

If you are in the UK, EU, or Switzerland: we process your account details because we need them to provide the app to you (performance of a contract). We keep short technical logs because we have a legitimate interest in keeping the service secure and working. We email your store's contact email only about your account and the service, such as billing, changes to our terms, or security. We do not send you marketing emails from the app.

How to see, fix, or delete your data

Email [email protected] from your store's contact email and include your store's Shopify address. Ask for any of these:

If you are in the UK, EU, or Switzerland you can also ask us to limit how we use your account details, to object to how we use them, or to give them to you in a file you can take elsewhere.

We reply within 30 days, usually much faster. Uninstalling the app also starts deletion, as described above. If you are in the UK or EU, you can also complain to your local data protection authority.

Requests from your customers. When one of your customers asks you to see or delete their data, Shopify passes that request to us automatically. Because we store nothing about individual customers, there is nothing to hand over or erase. We log that the request arrived and reply to Shopify. If you need written confirmation for your records, email us.

If we emailed you first

We sometimes email local store owners to tell them about Nextstock. We only use a business email address that the store shows in public, such as on its own website. We keep your store's name, that address, and a note of what we sent and what you replied, so we do not bother you twice. We do this because we have a legitimate interest in telling stores about a tool that may help them. Reply "no" or "stop" and we will not email you again. We will delete our notes about you if you ask.

Cookies

We do not use advertising or analytics cookies, and we do not track you across other sites. The app runs inside your Shopify admin. Shopify may set cookies or browser storage to keep you signed in; those belong to Shopify and are covered by its privacy policy.

A few more things

Questions?

Email [email protected]. If you need to write to us by post, ask there for our postal address.

For the technical folks

Shopify sends three compliance notices: customers/data_request, customers/redact, and shop/redact. The first two are logged and acknowledged; there is no customer data to return or erase. shop/redact deletes the shop row, which cascades to every table holding that store's data, and it is skipped when the store has reinstalled and has a live token. A scheduled job runs hourly and does the same deletion for any store uninstalled more than 48 hours ago, so deletion does not depend on shop/redact arriving. Traffic is encrypted in transit with HTTPS/TLS, including the application-to-Postgres connection (sslmode=require, checked at startup). Shopify access tokens are encrypted at rest with AES-256-GCM.