Privacy policy
What Coverline stores, and what it never touches.
Coverline holds no personal data about your customers. Not their names, emails, addresses, phone numbers or payment details — none of it is read into our systems and none of it is stored. Our database has no customer table and no personal field anywhere in it, so this is a property of how the app is built rather than a promise about how we behave.
Who this covers
Coverline is an inventory forecasting and replenishment app installed by a Shopify merchant on their own store. This policy describes what the app does with that merchant’s store data. If you shopped at a store that uses Coverline, we hold nothing that identifies you.
What we store, exhaustively
From each order, five fields. This is the complete list — not a summary of a longer one.
| Field | Why we need it |
|---|---|
| Order id | Deduplication, so a webhook delivered twice does not count a sale twice |
| Order date | Date only, no time. Builds the daily demand series a forecast reads |
| Variant id | The unit being forecast — one product in one size and colour |
| Quantity | The value being forecast |
| Line total | Estimating the revenue at risk when a variant is about to run out |
Alongside these we store your product catalog (titles, SKUs, prices, inventory levels), supplier terms you enter yourself (lead times, minimum order quantities, case packs, unit costs), and the forecasts and purchase orders Coverline produces from them.
What we never store
Every other field in a Shopify order payload is discarded at the point of import, before anything is written to our database:
- Customer names
- Email addresses
- Shipping and billing addresses
- Phone numbers
- Payment details of any kind
- IP addresses, device identifiers and browsing behaviour
What we use it for
Forecasting demand for your store and planning your replenishment. That is the only purpose. Specifically, we do not:
- Use your data for advertising, or to build audiences
- Sell, rent or share it with anyone
- Pool it with other merchants’ data or train models across stores
- Use it for any purpose beyond serving the store it came from
Your forecasts are computed from your history alone. Nothing another merchant sells influences what Coverline tells you to order, and nothing you sell influences theirs.
If the weekly reorder digest is switched on, Coverline sends one email a week to your store’s contact address, listing what needs ordering. That address is read from Shopify each time a digest is sent and is never stored by us. The email carries no tracking pixel and no rewritten links, so we do not know whether you opened it. You can switch the digest off at any time from Coverline’s settings screen.
Where it lives, and who can reach it
- Transmitted over TLS 1.2 or higher, always
- Encrypted at rest, including the access token Shopify issues for your store
- Least-privilege access; production credentials are held by the app operator only
- No third-party sub-processor receives your order data
How long we keep it
Everything belonging to your store is deleted within 30 days of uninstalling Coverline. You can ask for earlier deletion at any time by emailing us, and we will action it rather than wait out the window.
Shopify also requires every app to honour three data requests automatically. Ours are unusually simple, for the reason at the top of this page:
| Request | What Coverline does |
|---|---|
| Customer data request | Returns nothing, because we hold nothing about any identifiable shopper |
| Customer erasure | Nothing to erase — there is no record keyed to a customer |
| Shop erasure | Permanently deletes every row belonging to that store, including the demand series |
Your rights
Depending on where you are, you may have the right to access, correct, export or delete the data we hold about you as a merchant, and to object to how we process it. Email us and we will answer. Because we hold no customer personal data, requests about your shoppers are answered by Shopify, who is the controller for that data.
Changes
If this policy changes materially, we will update the date at the top and notify merchants with an active installation before the change takes effect.
Contact
Privacy questions, data requests and security reports: hello@wenthura.lk.