Privacy Policy

Costfold · Last updated: July 20, 2026

Costfold (“we”, “us”) is a Shopify app that allocates landed costs — freight, duty, insurance and fees — across the lines of a receiving, and writes the resulting cost back to Shopify’s cost per item. This policy explains what we process and why.

We never access customer data

Costfold requests four scopes and no others: read_products, write_products, read_inventory, and write_inventory.

We do not request access to orders, customers, checkouts, or any other part of your store. It is therefore not technically possible for this app to read your customers’ names, emails, phone numbers, addresses, or purchase history. Costfold handles no protected customer data of any kind.

What write access is used for

Write access has exactly one purpose: updating an inventory item’s cost per item (inventoryItem.cost) when you explicitly click the write-back button. We change no other field — not prices, titles, descriptions, inventory quantities, or product status. Before every write we store the previous value, so you can roll the entire receiving back from within the app.

What we store

Supplier names are business records you enter. If you enter the name of an individual (for example a sole trader), that is the only field in which personal data could appear; you control what goes in it, and you can delete the receiving at any time.

Your Stocky API key is not stored

If you import from Stocky, the API key you paste is used only to make the import request during that same operation. It is never written to our database and never persisted after the request completes. To import again, you enter it again.

The same holds for the free Stocky exporter at /stocky-export, which anyone can use without installing the app or creating an account. The key and the store domain you enter there are used inside that one request to call Stocky’s API and are then discarded: no database record, no log entry, no email capture. The exported file is streamed straight to your browser and we keep no copy of it. You are welcome to rotate the key in Stocky immediately afterwards.

How we use it

Solely to provide the app’s features to you, the merchant: allocating landed costs across receiving lines, writing the result back to cost per item, and showing your margin report. We do not sell this data, we do not use it to train anything, and we share it only with the subprocessors below, who process it on our behalf.

Subprocessors

Costfold sends no data to any AI or analytics provider, and embeds no third-party trackers.

Retention and deletion

Data is retained while the app is installed. When you uninstall Costfold, your store record and every receiving, cost component, and write-back log attached to it are deleted, along with your session credentials — triggered by Shopify’s app/uninstalled webhook. We also implement Shopify’s mandatory compliance webhooks (customers/redact, customers/data_request, shop/redact) and act on each verified request. Because we hold no customer data, the two customer webhooks have no personal data to return or erase.

Uninstalling does not revert costs already written to your products. Roll back from within the app before uninstalling if you want the previous values restored.

Security

Data is encrypted in transit (TLS) and at rest by our hosting providers. Access is limited to the app operator under least-privilege credentials.

Contact

Questions about this policy? Email thoopring@gmail.com.