Privacy Policy

Last updated: August 10, 2026

This Privacy Policy explains how PlaceStock (the “App”, “we”, “us”), operated by 67.644.899 JOAO PAULO ALVES, CNPJ 67.644.899/0001-56, located at Av. Rio Grande do Sul, 387, Vila Barbosa, Terra Rica/PR, CEP 87.890-000, Brazil, collects, uses, stores and protects information in connection with your use of the App.

PlaceStock is a distributed-consignment application embedded in the Shopify admin. It lets a merchant place their own stock with partner points of sale, track how much is at each point, and let those partners record sales and request restocks through a dedicated portal. By installing or using the App, you agree to this Policy.

1. Roles: controller and processor

For data about you, the merchant, and your store, we act as controller. The App is provided by 67.644.899 JOAO PAULO ALVES, CNPJ 67.644.899/0001-56, with address at Av. Rio Grande do Sul, 387, Vila Barbosa, Terra Rica/PR, CEP 87.890-000, Brazil.

For the personal data of the partners you register in the App, YOU are the controller and we act as processor on your behalf. You decide which partners to register and what information to enter about them; we only store and process it so the App can work. You are responsible for having a lawful basis to enter that data and for informing your partners that their data is processed through this App.

For any privacy-related request, contact us at jls.mkt25@gmail.com.

2. Information we store

Store / merchant data. Your store domain (your-store.myshopify.com) and the offline access token issued by Shopify for your store (the session), required for the App to read your catalog and, in advanced mode, move inventory.

Partner data (personal data of third parties). For each partner you register: business or personal name, contact person’s name, e-mail address, phone number, postal address, commission rate, the Shopify Location assigned to them in advanced mode, active/inactive status, and a password hash used to authenticate their access to the partner portal. Passwords are stored only as a scrypt hash — never in plain text.

Placements and their items. Which products and quantities were delivered to which partner, the delivery date, the optional expiry date, and the quantity remaining.

Sales. The sales your partners record: product, quantity, value, date, and the partner who recorded it. These are internal records — the App does not create orders in Shopify and does not process payments.

Restock requests. The items and quantities a partner asked for, the date, and the status of the request.

Store settings. Which tracking mode is enabled (simple or advanced), the consigned-location strategy, and the interface language you selected.

Internal team accounts. E-mail, name and password hash for the staff accounts that access the consolidated master panel. These are accounts you or we create for administration; they are not buyer data.

3. Information we do NOT collect

We do not collect personal data about your store’s buyers or end customers. The App has no storefront component: it does not run on your public store, sets no cookies there, and never sees who bought what.

We do not process orders, checkout or payments. Sales recorded in the App are internal records for consignment control.

We do not request access to your Shopify customers or orders. See the scopes below.

4. Permissions (scopes)

The App requests read_products (to let you pick items from your catalog when placing stock), and read_inventory, write_inventory and read_locations (used in advanced mode to move quantities into the Shopify Location dedicated to a partner, so your general stock reflects what is out on consignment).

The App does not request access to orders, customers, payment data or your storefront theme.

5. How we use the information

To operate the App: authenticate with Shopify, read the products you select, and — in advanced mode — move inventory between your locations.

To authenticate partners: verify the credentials used to sign in to the partner portal, and keep a signed session cookie while they are logged in.

To run the consignment workflow: record placements, sales, remaining quantities and restock requests, and compute commissions.

To remember your preferences: such as the admin panel language and the tracking mode.

6. Hosting and sub-processors

The App is hosted on our own server (VPS) with a local database (SQLite). We integrate with Shopify’s APIs. We do not use third-party analytics providers and we do not sell or share your data — or your partners’ data — with advertisers.

Data is transmitted over encrypted connections (HTTPS). Webhooks received from Shopify are verified by HMAC signature. Partner and staff session cookies are signed, HTTP-only, and scoped to their own path.

7. Data retention and deletion

Your data exists for as long as the App is installed. When you uninstall the App, Shopify sends the shop/redact webhook (approximately 48 hours after uninstall), and we delete all data associated with your store — including the partner records you created.

You can also delete an individual partner and their data at any time from the App admin.

We respond to Shopify’s mandatory compliance webhooks: customers/data_request (we hold no buyer data to return), customers/redact (we hold no buyer data to erase), and shop/redact (we erase all store data).

8. Rights of your partners (GDPR / LGPD)

Your partners are data subjects. They may request access to, correction of, or deletion of their personal data. Because you are the controller of that data, such requests should be directed to you in the first instance; you can fulfil them from the App admin.

If a partner contacts us directly at jls.mkt25@gmail.com, we will forward the request to the merchant who registered them and assist as processor.

We do not use partner data for any purpose other than operating the App for you. We do not use it to market to your partners.

9. Your rights as a merchant

Depending on your jurisdiction, you may have the right to access, correct or delete your data, among others. You can exercise deletion by uninstalling the App and/or by contacting us at jls.mkt25@gmail.com.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.

11. Contact

For any question about this Policy, contact us at jls.mkt25@gmail.com.