Privacy Policy

Last updated: October 4, 2026

SortKit is a Shopify app that automatically sorts a store's collections (by best sellers, revenue, margin, newest, price or stock). This policy explains what data the app processes, why, and how it is protected.

No shopper personal data. To rank best sellers, SortKit reads the store's orders, but only their line items (product, quantity and line total) and their dates. It never requests customers' names, emails, addresses or phone numbers. Orders are totalled per product in memory and discarded; no order or customer record is stored.

What we process

Why we process it

Solely to provide the app's functionality to the merchant. The store owner's email is used only for the emails described above. We do not use it for advertising, profiling, or sale.

Sharing

We do not sell data or share it for any other purpose.

Retention and deletion

Sort history is deleted after 30 days, and sales totals are replaced on each refresh. When the app is uninstalled, sessions are removed. Roughly 48 hours later Shopify sends a shop/redact request and we delete all data stored for that shop, including the store owner's email, in all cases within 30 days of uninstall. Because we hold no customer personal data, the customers/redact and customers/data_request webhooks have nothing to act on and are acknowledged.

Security

Data is stored on a DigitalOcean server, on an encrypted storage volume, with SSH-key-only administrative access. Backups are kept on the same encrypted volume for 7 days. All traffic uses HTTPS. App secrets are held only in the server environment.

Changes

We may update this policy; material changes will be reflected here with a new "last updated" date.

Contact

Questions about this policy or your data: support@nerdlabs.us.