Dropskip™
Log inBack to site
Legal

Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how Dropskip™ (“Dropskip”, “we”, “us”), operated by Redefined Logistics, collects, uses, discloses, retains, and protects information when a Shopify merchant installs and uses the Dropskip app for demand forecasting, reorder planning, and lost-sales analysis. Dropskip requests read-only access to Shopify data and never requests permission to create, edit, or delete anything in your store.

Contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. Shopify Protected Customer Data
  5. How we use information
  6. Legal bases (GDPR)
  7. How we share information
  8. Sub-processors
  9. International data transfers
  10. Data retention
  11. Data deletion & uninstalling
  12. Security
  13. Your rights & choices
  14. Shopify compliance webhooks
  15. Cookies & tracking
  16. Children's data
  17. Changes to this policy
  18. Contact us

1. Who we are

Dropskip is a Shopify application operated by Redefined Logistics. For data that Dropskip receives from your Shopify store — including any personal data relating to your customers — you (the merchant) are the data controller and Dropskip acts as a data processor / service provider processing that data on your behalf and on your instructions. For the account and billing information you provide to us directly, Dropskip is the controller.

If you have any question about this policy or how your data is handled, contact us at support@redefinedlogistics.com.

2. Scope of this policy

This policy covers the Dropskip embedded app inside the Shopify admin, the Dropskip web workspace at dropskip.app, and the backend services that sync and store your store’s data. It does not cover Shopify itself (see Shopify’s own privacy policy) or any third-party website or service you may link to Dropskip separately.

3. Information we collect

3.1 Store data synced from Shopify

When you connect your store, Dropskip uses the OAuth scopes you grant to read the following data through Shopify’s Admin API. All access is read-only.

Products & variants
Title, SKU, price, images, options and variant details. Used to build per-SKU demand forecasts and product-level views.
Orders & order history
Line items, quantities, totals, discounts, currency, fulfillment status and order timestamps — including up to approximately 36 months of historical orders on first connect. Used for forecasting and lost-sales analysis only.
Customer details on orders
Name, shipping address, email address and phone number attached to synced orders. This is Shopify Protected Customer Data — see section 4.
Inventory levels
Per-location on-hand quantities for locations you have mapped to a warehouse. Keeps stock positions current for forecasting and reorder timing.
Locations
Your Shopify fulfillment locations, mapped to warehouses in Dropskip so inventory is attributed correctly.
Fulfillments & returns
Fulfillment and return records, used to reconcile what actually shipped and what came back.
Payment disputes, store credit (requested, not yet active)
These scopes are requested for planned returns- and dispute-aware forecasting. Nothing from these scopes is synced into or stored in your workspace today.
Shopify access token
A long-lived, read-only OAuth access token issued for your shop, stored so Dropskip can refresh the data above in the background. It is never used to write to your store.

3.2 Account & workspace information

When you create or link a Dropskip workspace we collect the information needed to set up your account: your name, work email address, organization / company name, the Shopify shop domain, and (for teammates you invite) their names and email addresses. Billing is handled through Shopify or our billing provider; we receive plan, subscription status and usage data, not full card numbers.

3.3 Information collected automatically

Like most web applications, our servers automatically log technical information such as IP address, browser and device type, pages requested, timestamps, and error diagnostics. We use this for security, debugging, and to keep the service reliable.

4. Shopify Protected Customer Data

Some order data Dropskip receives is classified by Shopify as Protected Customer Data, including customer name, email, phone, and shipping address. We handle it under Shopify’s Protected Customer Data requirements:

  • We collect it only where it is required for the app’s function — producing accurate shipping, fulfillment and lost-sales records tied to an order.
  • We do not use customer personal data for marketing, advertising, profiling of individuals, or any purpose unrelated to the forecasting and planning features you installed the app for.
  • We do not sell customer personal data or share it with third parties for their own purposes.
  • Access is restricted to the minimum staff and systems needed to operate the service, encrypted in transit and at rest, and retained only as long as described in section 10.
  • You can ask us to stop processing, or to delete, customer data at any time (see sections 11 and 14).

5. How we use information

We use the information described above to:

  • Generate demand forecasts, reorder recommendations, stockout-risk scores and lost-sales analysis for your store.
  • Display dashboards, reports and product-level views in Dropskip.
  • Answer questions you ask Dropskip’s in-app assistant about your own inventory and sales.
  • Set up, authenticate, secure and support your account.
  • Keep the sync healthy — refreshing tokens, retrying failed pulls, and notifying you if the connection needs attention.
  • Maintain security, prevent abuse, debug problems, and meet legal obligations.
  • Produce aggregated, de-identified statistics that do not identify you, your store, or any individual, to improve our forecasting models and the product.

We never use your data, or your customers’ data, to train models that are shared across unrelated merchants in a way that could expose your individual store or customer records, and we never sell your data.

6. Legal bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract — to provide the app and workspace you signed up for.
  • Legitimate interests — to secure, debug, and improve the service, and to produce aggregated analytics, balanced against your rights.
  • Legal obligation — to comply with tax, accounting and lawful requests.
  • Your instructions as controller — for the customer personal data we process on your behalf, our processing is governed by your instructions and our data processing terms.

7. How we share information

We share information only in these limited circumstances:

  • Within our own systems. The embedded app passes data to Dropskip’s backend (control-tower and its order and inventory services) which store and process it to power the features described above. Shopify Admin API calls are made by our provider service on your behalf.
  • Service providers / sub-processors. Infrastructure, hosting, database, logging and error-monitoring vendors that process data under contract, only on our instructions (see section 8).
  • Legal and safety. Where required by law, valid legal process, or to protect the rights, property or safety of Dropskip, our users, or the public.
  • Business transfer. If Dropskip or Redefined Logistics is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this policy.

We do not sell personal data, and we do not share it with advertisers or data brokers.

8. Sub-processors

We use a small number of infrastructure providers to run the service — cloud hosting and compute, managed databases, and logging / error-monitoring. Each is bound by a data processing agreement and may only process data to provide services to us. A current list of sub-processors is available on request by emailing support@redefinedlogistics.com. We will give notice of material changes so you can object.

9. International data transfers

Dropskip and its providers may process data in countries other than the one where you or your customers are located. Where we transfer personal data internationally, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), or rely on an adequacy decision.

10. Data retention

  • Synced store data (products, orders, inventory, locations, customer details on orders) is retained for as long as your store is connected, so historical context stays available for forecasting.
  • On uninstall, syncing stops immediately and the stored Shopify access token is revoked. Your synced store data and store configuration are deleted from our systems as part of the uninstall clean-up, and in any case within 30 days, except where we must retain limited records to comply with law or resolve disputes.
  • Shopify’s shop-redaction request, which Shopify sends 48 hours after uninstall, is used to confirm the purge has completed.
  • Account and billing records are retained for the life of the account plus the period required for tax and accounting.
  • Technical logs are retained for a short period (typically up to 90 days) then deleted or de-identified.

11. Data deletion & uninstalling

You can disconnect Dropskip at any time by uninstalling it from your Shopify admin (Settings → Apps and sales channels). Uninstalling immediately revokes Dropskip’s access token and stops all syncing. To request deletion of any remaining data, or deletion of a specific customer’s data, email support@redefinedlogistics.com and we will action it, typically within 30 days.

12. Security

We protect data with measures appropriate to its sensitivity, including encryption in transit (TLS) and at rest, scoped and least-privilege access controls, HMAC verification of every Shopify webhook, short-lived internal service credentials, network isolation of backend services, and monitoring and logging. No method of transmission or storage is completely secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

13. Your rights & choices

Depending on where you or your customers are located, applicable law (including the GDPR, UK GDPR, and US state privacy laws such as the CCPA/CPRA) may provide rights to:

  • Access the personal data we hold and receive a copy.
  • Correct inaccurate data.
  • Delete data, subject to legal retention exceptions.
  • Restrict or object to certain processing.
  • Data portability.
  • Not receive discriminatory treatment for exercising these rights.

Because Dropskip processes customer personal data on behalf of the merchant, a customer wishing to exercise rights over their data should contact the merchant (the store they purchased from). We will assist the merchant in responding. Merchants and individuals can reach us directly at support@redefinedlogistics.com. You also have the right to complain to your local data protection authority.

14. Shopify compliance webhooks

Dropskip implements the mandatory Shopify privacy webhooks. Each is verified by HMAC before processing:

  • customers/data_request — when a merchant forwards a customer’s request for their data, we compile the store-scoped data Dropskip holds for that customer and provide it to the merchant.
  • customers/redact — we erase or de-identify that customer’s records from Dropskip’s stored copies.
  • shop/redact — sent 48 hours after uninstall; we confirm the shop’s configuration and synced data have been deleted.

15. Cookies & tracking

The embedded Shopify app uses only strictly necessary cookies and session storage required for authentication and to run inside the Shopify admin. The dropskip.app workspace uses cookies needed to keep you signed in and to remember basic preferences. We do not use third-party advertising cookies or cross-site tracking.

16. Children’s data

Dropskip is a business tool and is not directed to children. We do not knowingly collect personal data directly from children. Any customer personal data contained in a merchant’s orders is processed on the merchant’s behalf under their own privacy practices.

17. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you in the app or by email. Continued use of Dropskip after an update means you accept the revised policy.

18. Contact us

Redefined Logistics — operator of Dropskip™

Email: support@redefinedlogistics.com

For privacy requests, please include your Shopify shop domain and a description of your request.

Dropskip™  — forward-looking demand forecasting for Shopify merchants
Privacy policy