Legal
Privacy policy
Last updated: 27 August 2026
This policy describes what the Datima.ai Expiry Management app ("the app") stores when a merchant installs it on a Shopify store, and what happens to that data afterwards.
What we store
- Shop profile — your shop domain, name, contact email, timezone, and currency, as provided by Shopify at install.
- Access token — the credential Shopify issues the app, stored encrypted (AES-256-GCM) and bound to your shop.
- Catalog mirror — products, variants, locations, and inventory levels, synced from your store so the app can work without calling Shopify on every screen.
- Data you create — batches (expiry dates, quantities, lot codes, bins, notes), import files, and an audit trail of edits.
- Order-derived records — for each fulfillment or refund, the order and line-item identifiers and quantities needed to attribute stock movements to batches. We do not store customer names, addresses, emails, or payment details.
What we don't do
- We don't sell or share your data with third parties.
- We don't use your data to train models or profile your customers.
- We don't read more of your store than the app's declared Shopify scopes allow.
Where it lives
Data is stored on infrastructure operated for Datima.ai, isolated per shop at the database layer (row-level security). Access tokens are encrypted at rest with rotating keys.
Deletion
- Uninstall — background processing stops immediately. Your data is retained for a grace period so a reinstall restores it, then purged on the schedule Shopify's data-protection webhooks mandate.
- GDPR requests — the app implements Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. Because we hold no customer personal data, customer requests are answerable with an empty disclosure; shop redaction deletes everything.
- Export first — you can export every batch you've recorded as CSV at any time, on any plan, in any subscription state.
Contact
Privacy questions: support@datima.ai.