LotTrack Privacy Policy
Last updated: July 11, 2026
LotTrack is a Shopify app for lot/batch inventory tracking and recall management (the “App”), provided by TGProd (“we”, “us”). The merchant who installs the App is the data controller of their store and customer data; we act as a data processor on their behalf and use data only to provide the App’s functionality.
1. What we access
Using only the least-privilege Shopify access scopes a merchant grants, the App accesses: products, inventory, and locations; orders and fulfillments; and customer name and email, read only when building recall reports or sending recall notices.
2. What we store — and what we don’t
We do not store customer personal data. Customer names and emails are fetched live from Shopify when needed and are not saved to our database. We store, per shop: your lot/batch records (lot numbers, dates, supplier references, QC status, quantities); order–lot links that contain Shopify order/line-item/fulfillment identifiers only — no customer names, emails, or addresses; recall cases, lot audit history, notifications; app settings (including your alert notification email and, if connected, a Telegram chat ID); Shopify session tokens; and webhook payloads — stripped of customer names, emails, phone numbers and addresses before storage — kept temporarily for reliable processing.
3. How we use data
We process data solely to provide App functionality to the merchant: to track lots and sync inventory with Shopify, allocate lots to fulfillments (FIFO/FEFO/LIFO), send expiration and low-stock alerts, build recall traceability, send recall notices to affected customers at the merchant’s explicit instruction, maintain a compliance audit trail, and operate, secure, and improve the App. We do not sell personal data or use it for advertising or profiling.
4. Sub-processors
| Provider | Purpose |
|---|---|
| Shopify | Source platform hosting the merchant’s data |
| Railway | Application hosting and database |
| Resend | Transactional email delivery (merchant alerts, and customer recall notices when a merchant sends them) |
| Telegram | Optional alert delivery, only if the merchant connects it |
We may disclose data if required by law. We do not otherwise share personal data with third parties.
5. Data retention and deletion
We retain data while the App is installed and needed to provide functionality; stored webhook payloads are kept for up to approximately 90 days, then removed. When a store uninstalls the App, Shopify sends a shop/redact request (about 48 hours later), on receipt of which we permanently delete all records we hold for that shop. We also honor Shopify’s customers/data_request and customers/redact webhooks; because we store no customer personal data, there is no customer PII to erase.
6. Security
We apply protections appropriate to Shopify’s Protected Customer Data requirements: encryption in transit (HTTPS/TLS) and at rest, including encrypted backups; HMAC signature verification on inbound Shopify webhooks; secret management for tokens and API credentials; and limited staff access to production data.
7. International data transfers
Data may be processed in the United States and other regions where our infrastructure providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards as required by applicable law.
8. Your rights
Depending on your jurisdiction (e.g. GDPR, UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, restrict, or port personal data. Customers should contact the merchant they purchased from, who can action requests through Shopify. Merchants can delete their data by uninstalling the App or by contacting us at tom@tgprod.dev.
9. Children’s data
The App is a business tool not directed to children and does not knowingly process children’s personal data.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
11. Contact
TGProd — tom@tgprod.dev