Larderia App Privacy Policy
Last updated: October 5, 2026
Larderia is a Shopify app that forecasts demand from a store's sales history, suggests when and how much to reorder, prepares purchase orders for the merchant's suppliers, records in Shopify inventory the goods the merchant confirms as received and, if the merchant turns it on, sends a periodic digest by email or Slack. This policy explains what data the app processes when a merchant or their agency installs it, for what purpose, who it is shared with, where it is stored and for how long.
This policy covers the app only. The enric.app website has its own Website privacy and cookie policy.
1. Who is responsible
Santiago Gili Silvestre, a self-employed individual (autónomo), Spanish tax ID (NIF) 34764541H, address C/ Dels Montcada, 45, Local, 08203 Sabadell (Barcelona), Spain. ENRIC is the trade name under which he presents his apps; it is not a separate company. Contact for any privacy matter: [email protected], or by post to the address above.
We have not appointed a data protection officer because we are not required to: we are not a public body, our core activity does not consist of regular and systematic monitoring of people on a large scale or of processing special categories of data (GDPR Art. 37(1)), and we are not on the list in Art. 34(1) of the Spanish LOPDGDD.
2. Our role
- Your store data (catalog, inventory, sales derived from orders, order fulfillments, suppliers, purchase orders, forecasts and the app settings): you, the merchant, are the controller and Larderia is the processor (a "service provider" under California law; an "operador" under Brazilian law). We process it on your behalf and only to provide the service, under the Data Processing Agreement you accept with the Terms of Service.
- Data to manage our relationship with you (account, billing, support, service security and legal compliance): Larderia is the controller.
- Shopify is an independent third party: it has its own relationship with you and its own privacy policy, and it handles billing for the app.
3. What data we process
Permissions the app requests in Shopify. Read: read_products, read_inventory, read_locations, read_orders and read_fulfillments and, if Shopify approves it, read_all_orders (orders older than 60 days). Write, only one: write_inventory, which the app uses only when you confirm receipt of a purchase order, to add the received quantities to the inventory of the destination location, activate the item at that location if needed and, if you tick the box, update its unit cost. The app is not read-only, but it does not change your products, your customer orders or your locations.
| Category | Data | Source |
|---|---|---|
| Store | *.myshopify.com domain and store name, currency, time zone, Larderia plan, install and uninstall dates, status of the initial import and of the last recalculation, and the stored forecast accuracy (a numeric summary per store) | Shopify and the app |
| Store contact details | Store name, contact email and phone, read from Shopify for the purchase order PDF and email. Only the email is stored, as the copy and reply-to address in the log of each email sent to a supplier | Shopify |
| Catalog | Products and variants: title, SKU, barcode, vendor, price, unit cost and status | Shopify API and webhooks |
| Locations and inventory | Name and status of each location; available, incoming, on-hand and committed stock per variant and location, and the history of observed stock levels (to detect stockout days) | Shopify API and webhooks |
| Your customers' orders and their fulfillments (level 1 protected data) | See "What we do with orders" below | Shopify API and webhooks |
| Suppliers you enter | Supplier name, email, currency, document language, free-text notes, reorder parameters (lead time, minimum order, pack size, coverage and safety days) and the alternative names you merge into a supplier | You |
| Purchase orders | Reference, supplier and supplier email, destination location, status, dates, notes, shipping, duties and other costs, and lines (product, variant, SKU, barcode, ordered and received quantity, unit cost); the receipts you confirm; the log of each email sent to the supplier (recipient, copy, reply-to, subject, status and date; the email body is not stored); the logo you upload for documents; and the orders imported from a Stocky CSV export | You and the app |
| Digests | Chosen frequency, time and day, language, the email address where you want to receive them and the Slack incoming webhook URL you paste in Settings (stored encrypted); and the log of each digest sent (channel, recipient if email, subject, status and date) | You and the app |
| Forecasts | Results calculated per variant and location: average demand, confidence level and its reasons, order date, reorder point, suggested quantity, turnover, ABC class, coverage and dead stock; and a weekly snapshot per variant (forecast demand for 7 and 30 days and method) to measure later how accurate the forecast was | Calculated by the app |
| Activity log | Which action was taken in the app (create, send, receive or cancel an order, adjust inventory or cost, save or merge suppliers, import from Stocky, save settings, send a digest), when, the action details (references and quantities) and who did it. The app uses store sessions without a user, so "who" is always "app" and no person's name or email is stored | The app |
| Session | Store session identifier, the access token and refresh token issued by Shopify (stored encrypted) and the granted permissions. The app does not store the name or email of the person who opens it | Shopify |
| Shopify webhook log | Identifier of each webhook, topic, store, dates and processing result; its reduced content only while queued | Shopify |
| Support | What you write to [email protected] and our replies (in the Zoho mailbox and in its Gmail copy, section 6) | You |
| Billing | Plan, charges, credits and refunds for the app. We do not receive card or bank details | Shopify |
| Technical | IP address, date and time of requests and errors in server logs | Automatic |
What we do with orders. To forecast we need to know what was sold, when and from which location it shipped. From each order we read its identifier, its dates (created, processed and last updated), whether it is cancelled or a test, the location and the line items (variant, quantity, current quantity after edits and refunds, and the date and quantity of each refund). From each fulfillment we read its identifier, the order identifier, its status, the location it was fulfilled from and, for each line, its identifier, the variant and the quantity. Of all that we store only:
- each order's contribution to sales: order identifier, variant, location, day and units, used to recalculate that day if the order is edited, cancelled or refunded;
- the fulfillment lines: order, fulfillment and line identifiers, variant, location, quantity, status and dates, used to attribute each sale to the warehouse that actually fulfilled it; and
- daily sales per variant and location, which identify no order and no person.
The order identifier does not reveal who bought, but inside Shopify it can be linked to the customer; we therefore treat it as pseudonymised personal data, delete it after 120 days and earlier if a customer asks for their data to be erased (section 10).
Your customers' data. We do not store your customers' names, emails, phone numbers or addresses, and we have not requested access to those fields from Shopify (level 2 protected data). Order, fulfillment and refund webhooks subscribe only to the fields the calculation needs, so that data does not arrive; if any other field arrived, the app would discard it in memory before anything is saved. We do not process your customers' payment data either. Digests, supplier emails and purchase order documents contain no customer data.
Do you have to give us this data? To use Larderia, Shopify has to give us access to the store data covered by the permissions above; without it the app cannot work. Supplier details, the digest email and the Slack URL are optional: without them only the features that use them stop working. If you do not write to us, we process no support data.
4. Why we use it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Calculate daily sales and attribute them to the warehouse that fulfilled each order, correct stockout days, calculate the forecast, order date, reorder point and suggested quantity; manage your suppliers; generate the "what to order" list, the purchase order CSV and dead stock reports | As processor, on the merchant's behalf (Art. 28) |
| Create purchase orders, generate their PDF and CSV, email them to the supplier when you tell us to, import orders from a Stocky export and, when you confirm a receipt, add the received quantities to Shopify inventory and, if you choose, update the cost | As processor, on the merchant's behalf (Art. 28) |
| Send you the daily or weekly digest by email or Slack, if you turn it on | As processor, on the merchant's behalf (Art. 28) |
| Measure and show you how accurate the forecast is (weekly snapshots) and show you the app's activity log | As processor, on the merchant's behalf (Art. 28) |
| Manage your account, plan, refunds and support | Performance of the contract (Art. 6(1)(b)). Contact details of people who work for the merchant or its agency, in their professional capacity: legitimate interest in maintaining the business relationship (GDPR Art. 6(1)(f) and LOPDGDD Art. 19) |
| Keep the service secure, prevent abuse and fix errors | Legitimate interest in protecting the service and its users (Art. 6(1)(f)) |
| Keep billing records and respond to requests from authorities | Legal obligation (Art. 6(1)(c)) |
| Inform you of material changes to the service, the terms or this policy | Performance of the contract (Art. 6(1)(b)) |
We do not sell or share data for advertising, we do not build commercial profiles and we do not use your store data to train artificial intelligence models. Forecasts are calculated with statistical methods on our servers, without third-party AI services. The calculations are about your inventory, not about people, and they produce no automated decisions with legal effects on anyone (GDPR Art. 22).
5. How long we keep it
| Data | Period |
|---|---|
| Full order | Not stored. Shopify webhooks arrive trimmed and are reduced in memory to the data in section 3 before anything is saved. The initial history import is streamed from Shopify and never written to disk; the file is hosted by Shopify and expires on Shopify's schedule |
| Reduced content of a Shopify webhook (in the processing queue) | Cleared once processed and, in any case, after 24 hours (automatic hourly clean-up) |
| Log of each Shopify webhook (identifier, topic, dates and result, without content) | 30 days after processing. Those of privacy webhooks (customers/data_request, customers/redact and shop/redact) are kept as a record (see below) |
| Each order's contribution (with its identifier) | 120 days; earlier if Shopify asks us to erase that customer's data (section 10) |
| Order fulfillment lines | 120 days from arrival; earlier if Shopify asks us to erase the data of that order's customer |
| Observed stock-level history | 25 months (two full seasons) |
| Forecast snapshots, activity log and log of digests sent | 400 days |
| Daily sales, catalog, inventory, suppliers, purchase orders (with their receipts and email log), forecasts, stored accuracy, logo and digest settings (including the Slack URL) | While the app is installed. The Slack URL is deleted earlier if you remove it in Settings |
| Session and access tokens | Deleted on uninstall, as soon as Shopify notifies us |
| All store data on uninstall | Shopify notifies us about 48 hours after uninstall (shop/redact) and we delete the data when we receive it. If the notice never arrives, the app deletes the data automatically 22 days after uninstall. Technical database backups (encrypted, see section 8) are overwritten on rotation within 7 days at most and, until then, are used only for disaster recovery. So, in every case, the store's data is gone from the database and its backups within 30 days at most of uninstall. Export anything you need first |
| Copy of the emails sent by the app (at Resend) | Resend keeps the content and log of each email for 30 days after it is sent, and its backups for 7 more days; then they are deleted |
| Record of deletion | We keep only the *.myshopify.com domain, the uninstall date and the log of privacy webhooks (without their content; only the counts), to be able to demonstrate compliance (GDPR Art. 5(2)) |
| Support (emails to [email protected]) | While you are a customer and up to 1 year after the last contact, both in the Zoho mailbox and in the Gmail copy (section 6). Gmail does not delete messages by age automatically: once a month we delete by hand, permanently (including from the trash), the copies that have passed that period. According to Google, completely removing deleted data from its systems takes around 2 months, and its encrypted backups may keep it for up to 6 months. If a claim is open, what is needed is kept blocked (LOPDGDD Art. 32) until it is resolved or time-barred |
| Billing records (charges, credits and refunds) | 6 years (Art. 30 of the Spanish Commercial Code, which also covers the 4-year tax limitation period of Art. 66 of the General Tax Law) |
| Server logs | 30 days at most, depending on our hosting provider's plan |
6. Who we share it with
The providers we need to deliver the service, under a processor or sub-processor agreement, are:
| Provider | Purpose | Where |
|---|---|---|
| Render Services, Inc. | App servers, scheduled jobs and PostgreSQL database | Frankfurt region (Germany, EU); US company |
| Plus Five Five, Inc. ("Resend") | Sending the emails you order (purchase orders to your suppliers, digests to your email and the reply to a customer's data request) | Sent from Ireland (EU); the data it keeps (content and sending logs) is stored in the US; US company |
| Zoho Corporation B.V. (Zoho Mail, Utrecht, Netherlands; EU data centre) | Support mailbox [email protected]: receives the emails you send us. It receives no app data. The data processing agreement was requested from Zoho on October 2, 2026 and is pending Zoho sending it for signature | Netherlands (EU) |
Copy of the support mailbox in Gmail. The [email protected] mailbox automatically forwards a copy of every email it receives to a personal Gmail account of the owner, for the same purpose: handling support. Zoho also keeps the original. For users in the European Economic Area and Switzerland, Gmail is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). As it is a personal account, not a Google Workspace one, there is no data processing agreement with Google: Gmail is governed by Google's terms and privacy policy, which names Google Ireland Limited as the controller of its EEA users' information. The forwarding only affects support emails, never the data the app processes. That is why we ask you not to include personal data of your customers or suppliers in your emails: we do not need it to support you (section 6.7 of the Data Processing Agreement). You can ask us at any time to delete the Gmail copy of your emails.
In addition, recipients you choose:
- Your suppliers, when you send them a purchase order by email: they receive the order (products, quantities, costs, delivery location and the store details shown on the document: name, contact email and phone, and logo), with a copy to your contact email. Never your customers' data.
- Slack, if you paste an incoming webhook URL of your workspace in Settings: the app sends the digest there, which contains replenishment figures (what to order per supplier with units and amount and some product names, upcoming seasons, overdue purchase orders with their reference and supplier, and new dead stock) and a link to the app; never your customers' data. Slack is a service you choose and contract; the app only sends to
https://hooks.slack.com/addresses. - The digest email goes to the address you enter in Settings, with the same content.
And also:
- Shopify receives the information its platform needs to bill for the app and, when you confirm a receipt, the inventory and cost adjustments you order.
- Authorities, when the law requires it.
- If the business were transferred to another person or company, the data would pass to the new owner, who would be bound by this policy; we would notify you first.
You download a purchase order's CSV and PDF yourself; the app sends them to no one except the supplier email you order.
7. International transfers
Store data is kept in Render's Frankfurt (EU) region. There are two cases in which it may leave the European Economic Area:
- Render (US) may access the data for support or security. Render is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework (official register at dataprivacyframework.gov, checked on October 5, 2026). The European Commission considers that framework adequate (Implementing Decision (EU) 2023/1795). If it stopped applying, Render's data processing agreement includes the Commission's standard contractual clauses (Decision 2021/914).
- Resend sends from Ireland but keeps the content and sending logs in the US. It is certified under the EU-US Data Privacy Framework and its UK Extension (same register and date), and its data processing agreement also includes the standard contractual clauses, which are the safeguard for data subject to Swiss law.
Zoho keeps the support mailbox in its EU data centre (Netherlands); any access from outside the EU would rely on the standard contractual clauses of Zoho's data processing agreement (pending signature, see section 6).
Google (the Gmail copy of the support mailbox, section 6) has servers around the world and may process those emails outside the EEA. Its privacy policy says that for those transfers it relies on European Commission adequacy decisions, the EU-US Data Privacy Framework and standard contractual clauses. Google LLC is certified under that framework, its UK Extension and the Swiss-US framework (official register at dataprivacyframework.gov, checked on October 5, 2026). These are safeguards Google applies to all its users: we have not signed any processing or transfer agreement with Google.
You can ask us for a copy of the Render, Resend and Zoho safeguards at [email protected]. Google's are on its page on legal frameworks for data transfers (policies.google.com/privacy/frameworks).
If your store is outside the European Economic Area, your data returns to you through Shopify and the exports, with the safeguards of the Data Processing Agreement.
8. Security
Encryption in transit (HTTPS, with TLS 1.2 or higher); encryption at rest of the database with AES-256, which Render also applies to its replicas and to all its backups; Shopify access tokens and the Slack URL are stored encrypted in the database with AES-256-GCM, with the key kept outside the database; the database is not reachable from the internet; Shopify permissions limited to what is needed (a single write permission, write_inventory, which only acts when you confirm a receipt); signature verification and duplicate filtering on every Shopify webhook; order webhooks trimmed and reduced before storage; data separated per store; size limits on forms; and restricted production access with two-factor authentication. No system is completely secure: if a security breach affected your data, we would notify you without undue delay and notify Shopify within 24 hours at most, as its developer terms require. Details in Annex II of the Data Processing Agreement.
9. Protected customer data (Shopify requirements)
Larderia uses level 1 protected customer data (order and fulfillment lines) only to calculate sales and forecasts. It meets Shopify's requirements as follows:
- Data minimisation: only what section 3 describes; no level 2 fields (name, email, phone or address), and order, fulfillment and refund webhooks subscribe only to the necessary fields.
- Merchant transparency: this policy explains what data we use and why, and it is linked from the app listing before install.
- Limited use: only for the purposes in section 4.
- Customer consent and opt-outs: the app sends no communications to your customers and makes no decisions about them; it handles the requests Shopify forwards (section 10).
- Data protection agreement: the Data Processing Agreement you accept with the Terms of Service.
- Retention periods: section 5.
- Encryption at rest and in transit: section 8.
10. Shopify notices about your customers
customers/redact(a customer's data must be erased): we delete the contribution of the orders Shopify lists (identifier, variant, location, day and units) and their fulfillment lines. Aggregated daily sales identify no one and are kept. From the notice we keep only the number of orders and rows deleted.customers/data_request(a customer asks for their data): we do not store data that directly identifies the customer (name, email, phone or address). The app automatically gathers the stored contribution and fulfillment lines of the orders Shopify lists (order ID, variant, location, day and units) and emails them, with a machine-readable attached file, to your store's contact email so you can answer the customer; if there is nothing, the email says we hold no data about that customer. Only the record of the webhook and the counts (orders, rows and whether the email was sent) are kept.shop/redact(after uninstalling the app): we delete all store data within the periods in section 5.
Shopify asks us to complete these actions within 30 days of the notice; the app does them as soon as it processes the notice.
11. Your rights
Everyone. You can request access, rectification, erasure, objection, restriction of processing and portability of your data by writing to [email protected]. We will reply within one month (extendable in the cases allowed by GDPR Art. 12(3)). If the data belongs to a merchant's store (for example, you are a store's customer or a supplier's contact person), we will pass the request to the merchant, who is the controller, and help them handle it.
Complaints. You can complain to the Spanish Data Protection Agency (www.aepd.es) or to the data protection authority of your country of residence or work (in the UK, the ICO).
California (CCPA/CPRA). For store data, Larderia is the merchant's "service provider": requests should be sent to the merchant and we will help them respond. For data we process as a controller, you can ask to know what personal information we hold, access it, correct it and delete it, without discrimination. We do not sell or share personal information and we do not use sensitive personal information. You may act through an authorised agent; we will verify the request reasonably.
Brazil (LGPD). You can exercise your LGPD rights, including confirmation of processing, access, correction, anonymisation or deletion, portability and information about who we share data with, by writing to [email protected].
Canada (PIPEDA) and Australia. You can request access to and correction of your information, and complain to us and, if not satisfied, to the Office of the Privacy Commissioner of Canada or the Office of the Australian Information Commissioner.
12. Children
Larderia is a business service and is not directed at minors.
13. Changes to this policy
We will notify you in the app and by email of any material change at least 30 days in advance, unless a law or authority requires a shorter period. For example, we will notify you before adding a new provider to section 6 or requesting new Shopify permissions. Previous versions are available on request.