Last updated 19 September 2026
ShelfFlow ("the app") is a Shopify app that keeps products a customer can still buy above products that have sold out, in the collections a merchant chooses. This policy explains what the app accesses, what it stores, and who it shares data with.
ShelfFlow stores no personal data. It cannot read customers, orders, carts or checkouts, and it does not ask for permission to. What it keeps is a record of the shop's collections and what it changed in them.
When a merchant installs ShelfFlow they grant it two permissions, and it uses each one only for the purpose given.
It requests nothing else. It has no access to customers, orders, themes, discounts, fulfilment or checkout, and cannot read them.
ShelfFlow keeps a small database so it can run on a schedule without a browser open. For each shop it stores:
.myshopify.com domain and time zone;It stores no customer names, email addresses, orders, or anything else identifying a shopper. Product and collection information is the merchant's own commercial data, not personal data.
Nobody. ShelfFlow sells nothing, shares nothing, and uses no advertising or analytics trackers. The app talks to Shopify and to nothing else.
The app runs on Cloudflare Workers, which processes requests and stores the database on the operator's behalf as a hosting provider.
Billing is handled entirely by Shopify, through Shopify App Pricing. The app never sees a payment method or any billing detail. It reads only which plan a shop is on, so it knows what that shop is entitled to.
When a merchant uninstalls ShelfFlow, Shopify notifies the app and it immediately deletes the shop's access token and stops all scheduled work. The shop's settings and run history are deleted within 30 days. Nothing the app did to a collection is undone by uninstalling: the products stay where they were last placed, and the merchant remains free to reorder them.
ShelfFlow subscribes to the data request, customer redaction and shop redaction webhooks Shopify requires. Because the app holds no customer data, a data request returns nothing and a customer redaction has nothing to erase. A shop redaction removes everything the app holds for that shop.
A merchant can ask for their data or its deletion at any time by emailing the address below, without waiting for a request through Shopify.
If what the app accesses or stores changes, this page changes with it and the date at the top is updated. A change that widens what the app can read also requires merchants to approve the new permission in Shopify before it takes effect.