LotTrack Privacy Policy

Last updated: July 11, 2026

LotTrack is a Shopify app for lot/batch inventory tracking and recall management (the “App”), provided by TGProd (“we”, “us”). The merchant who installs the App is the data controller of their store and customer data; we act as a data processor on their behalf and use data only to provide the App’s functionality.

1. What we access

Using only the least-privilege Shopify access scopes a merchant grants, the App accesses: products, inventory, and locations; orders and fulfillments; and customer name and email, read only when building recall reports or sending recall notices.

2. What we store — and what we don’t

We do not store customer personal data. Customer names and emails are fetched live from Shopify when needed and are not saved to our database. We store, per shop: your lot/batch records (lot numbers, dates, supplier references, QC status, quantities); order–lot links that contain Shopify order/line-item/fulfillment identifiers only — no customer names, emails, or addresses; recall cases, lot audit history, notifications; app settings (including your alert notification email and, if connected, a Telegram chat ID); Shopify session tokens; and webhook payloads — stripped of customer names, emails, phone numbers and addresses before storage — kept temporarily for reliable processing.

3. How we use data

We process data solely to provide App functionality to the merchant: to track lots and sync inventory with Shopify, allocate lots to fulfillments (FIFO/FEFO/LIFO), send expiration and low-stock alerts, build recall traceability, send recall notices to affected customers at the merchant’s explicit instruction, maintain a compliance audit trail, and operate, secure, and improve the App. We do not sell personal data or use it for advertising or profiling.

4. Sub-processors

ProviderPurpose
ShopifySource platform hosting the merchant’s data
RailwayApplication hosting and database
ResendTransactional email delivery (merchant alerts, and customer recall notices when a merchant sends them)
TelegramOptional alert delivery, only if the merchant connects it

We may disclose data if required by law. We do not otherwise share personal data with third parties.

5. Data retention and deletion

We retain data while the App is installed and needed to provide functionality; stored webhook payloads are kept for up to approximately 90 days, then removed. When a store uninstalls the App, Shopify sends a shop/redact request (about 48 hours later), on receipt of which we permanently delete all records we hold for that shop. We also honor Shopify’s customers/data_request and customers/redact webhooks; because we store no customer personal data, there is no customer PII to erase.

6. Security

We apply protections appropriate to Shopify’s Protected Customer Data requirements: encryption in transit (HTTPS/TLS) and at rest, including encrypted backups; HMAC signature verification on inbound Shopify webhooks; secret management for tokens and API credentials; and limited staff access to production data.

7. International data transfers

Data may be processed in the United States and other regions where our infrastructure providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards as required by applicable law.

8. Your rights

Depending on your jurisdiction (e.g. GDPR, UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, restrict, or port personal data. Customers should contact the merchant they purchased from, who can action requests through Shopify. Merchants can delete their data by uninstalling the App or by contacting us at tom@tgprod.dev.

9. Children’s data

The App is a business tool not directed to children and does not knowingly process children’s personal data.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

11. Contact

TGProd — tom@tgprod.dev