Privacy Policy
Last updated: October 4, 2026
SortKit is a Shopify app that automatically sorts a store's collections (by best sellers, revenue, margin, newest, price or stock). This policy explains what data the app processes, why, and how it is protected.
No shopper personal data. To rank best sellers, SortKit reads the store's orders, but only their line items (product, quantity and line total) and their dates. It never requests customers' names, emails, addresses or phone numbers. Orders are totalled per product in memory and discarded; no order or customer record is stored.
What we process
- Merchant / store data: the store's
myshopify.comdomain, an expiring Shopify access token, and the subscription plan tier. - Store owner's email: the email address on the store owner's Shopify account (as set in Shopify, not the store's public contact email), its admin language, and whether it is a development store — used only to email the store owner: account alerts, a one-time welcome note on upgrading to a paid plan, and a one-time note after uninstalling asking what we could improve.
- App settings: which collections to sort, the sort rule and pinned products.
- Catalog data: products in those collections, their prices, unit costs, inventory and creation dates, read at sort time. We store product IDs only (for pins and sales totals).
- Sales totals: units sold and revenue per product for the last 7, 30 and 60 days, derived from order line items and refreshed at most every 6 hours.
- Sort history: a 30-day log of sort runs (collection, products moved, outcome).
Why we process it
Solely to provide the app's functionality to the merchant. The store owner's email is used only for the emails described above. We do not use it for advertising, profiling, or sale.
Sharing
- Shopify — the platform APIs the app is built on.
- DigitalOcean — hosts the server and database.
- Mailgun — our email provider; delivers our emails to the store owner (sent from support@nerdlabs.us), using the store owner's email above.
We do not sell data or share it for any other purpose.
Retention and deletion
Sort history is deleted after 30 days, and sales totals are replaced on
each refresh. When the app is uninstalled, sessions are removed. Roughly 48
hours later Shopify sends a shop/redact request and we delete all
data stored for that shop, including the store owner's email, in all cases
within 30 days of uninstall. Because
we hold no customer personal data, the customers/redact and
customers/data_request webhooks have nothing to act on and are
acknowledged.
Security
Data is stored on a DigitalOcean server, on an encrypted storage volume, with SSH-key-only administrative access. Backups are kept on the same encrypted volume for 7 days. All traffic uses HTTPS. App secrets are held only in the server environment.
Changes
We may update this policy; material changes will be reflected here with a new "last updated" date.
Contact
Questions about this policy or your data: support@nerdlabs.us.