- Who we are
- Our role: processor for your store, controller for your account
- What each app stores
- Your customers and site visitors
- Your staff
- Why we process data (legal bases)
- Where data is hosted and who processes it
- How long we keep data
- Uninstalling and deletion requests
- Security
- Cookies and tracking
- Emails we send
- Your rights
- Changes to this policy
1. Who we are
Merchant Tools is the trade name of a French sole proprietorship (micro-entreprise) operated by Renaud Pothin, France. We publish back-office apps for online stores on the Shopify App Store and the Wix App Market.
Contact for anything related to personal data: support@merchanttools.eu. We answer within one business day (Europe/Paris).
2. Our role
- For the data of your store or site (products, prices, inventory, orders references, count sessions), you, the merchant, are the data controller and we act as your data processor: we process it only to run the app you installed, on your instructions, and never for our own purposes.
- For your account and support data (store or site identifier, plan, the email address you write to us from, support conversations), we are the data controller.
3. What each app stores
Every app keeps only the data it needs to do its one job, always scoped to your store or site. None of our apps reads or stores the names, addresses, emails or payment details of your customers.
Common to all apps
- Shopify apps: your store domain, an access token encrypted at rest, the store's contact email (used for two onboarding emails after installation and for support replies), your plan, your app settings, and a log of every write the app makes to your store.
- Wix apps: the app instance identifier and site identifier issued by Wix, the catalogue version of your site, your plan, your app settings, and a log of every write the app makes to your site. We do not store an access token: Wix issues short-lived tokens on each request.
| App | Platform | Data stored |
|---|---|---|
| MT: SKU & Part Number Search | Shopify | Product and variant titles, SKUs, barcodes, an optional manufacturer-reference metafield, tags, prices and availability; anonymous storefront search strings that returned no result (no visitor identifier). |
| MT: Stock Count & Scan | Shopify and Wix | Locations, variants (titles, SKU, barcode, unit cost), current stock levels, count sessions with expected and counted quantities, a log of scans with the device name typed by the person counting, shrinkage entries with the free-text note you enter, and a log of inventory adjustments sent to the platform. On Wix, a journal of stock movements received from Wix (quantity before and after, reason, and the Wix user identifier of the person who made a manual change, see section 5). |
| MT: Serial & Lot Tracking | Shopify | Serial numbers, lot numbers, expiry dates, and the order identifier and order number of the lines they were assigned to. No customer name, email or address. |
| MT: Omnibus Price History | Shopify and Wix | Product and variant identifiers, product names, a dated log of selling prices and compare-at prices, the currency, and the computed lowest price of the reference period. The app never changes your prices. |
4. Your customers and site visitors
Our storefront components (the search bar and the Omnibus price line on Shopify themes, the Omnibus site plugin on Wix product pages) set no cookies and do not identify visitors. On Wix, the Omnibus plugin asks our server for the lowest price using a short-lived visitor token issued by Wix; we use that token only to identify which site is asking and discard it. Our hosting provider keeps technical access logs (IP address, browser user agent, requested URL) for a short period for security and debugging, then deletes them.
Barcode scanning in Stock Count and Serial & Lot Tracking is decoded on the phone itself. No camera image ever leaves the device.
5. Your staff
Some data relates to the people who work in your store rather than to your customers:
- The device name a person types when opening the phone counting page (for example “Warehouse 2”). It is stored with each scan so you can see who counted what.
- On Wix, the stock-movement journal stores the Wix user identifier (a technical ID, not a name) that Wix sends with each manual inventory change, so the journal can distinguish manual edits from orders. We do not look this identifier up or link it to a name.
- The Stock Count phone page keeps an offline queue of scans in the phone's browser storage until they are sent; nothing else is stored on the device.
You are responsible for informing your staff that these tools record their activity in the store.
6. Why we process data
- Performance of a contract (GDPR Art. 6(1)(b)): providing the app you installed and the plan you subscribed to.
- Legitimate interest (Art. 6(1)(f)): security, abuse prevention, debugging, and answering your support requests.
- Legal obligation (Art. 6(1)(c)): keeping billing-related records where the law requires it. Billing itself is handled entirely by Shopify or Wix; we never see card or bank details.
We do not sell data, do not use it for advertising, and do not use it to train machine-learning models.
7. Where data is hosted and who processes it
All application data is hosted in the European Union. Our sub-processors are:
| Provider | Purpose | Location |
|---|---|---|
| Fly.io, Inc. | Application servers | Paris, France (EU region). US company; transfers covered by Standard Contractual Clauses. |
| Neon, Inc. | PostgreSQL databases | Frankfurt, Germany (EU region). US company; transfers covered by Standard Contractual Clauses. |
| OVHcloud | Email (support mailbox and outgoing app emails) | France |
| Shopify Inc. / Wix.com Ltd. | The platform your store runs on; provides the data to the app through its APIs and webhooks | Per their own privacy policies |
No other third party receives your data.
8. How long we keep data
- While the app is installed: catalogue, inventory and settings data is kept up to date and old entries are pruned. Price history is kept as long as needed to compute the lowest price of the reference period and for the reports of your plan. Completed count sessions and shrinkage entries are kept 30 days on free plans and up to 2 years on paid plans; the Wix stock-movement journal is capped at 2 years.
- Technical logs (webhook receipts, job queue): 7 to 30 days.
- Support emails: kept for up to 3 years after the last exchange, then deleted.
9. Uninstalling and deletion requests
- Shopify: all data for your store is deleted immediately when you uninstall the app, and again when Shopify sends its
shop/redactrequest 48 hours later. We also honourcustomers/data_requestandcustomers/redact; as we hold no customer data, these return an empty record, except Serial & Lot Tracking, which returns and anonymises the order numbers it holds. - Wix: when you remove the app, Wix notifies us, the app stops serving your site at once, and all data for your site is permanently deleted within 30 days. Reinstalling within that window restores your settings.
- On request: email support@merchanttools.eu from the address linked to your store or site and we delete everything within 7 days, or send you an export of what we hold.
10. Security
All traffic is encrypted in transit (TLS). Shopify access tokens are encrypted at rest. Webhooks are verified by signature before being processed. Each app runs in its own isolated server and database. Access to production systems is limited to the publisher and protected by two-factor authentication. Every write an app makes to your store is logged and visible to you inside the app.
11. Cookies and tracking
This website sets no cookies and uses no analytics. Our apps' admin pages run inside the Shopify admin or the Wix dashboard and rely only on the session cookies of those platforms; we set none of our own. Storefront components set no cookies.
12. Emails we send
After installation, a Shopify app may send up to two onboarding emails to the store's contact address, then only replies to your support requests and notices required to operate the service (for example, a plan limit reached or an expiry alert you configured). We send no marketing emails. Outgoing emails are sent from @merchanttools.eu addresses through OVHcloud.
13. Your rights
Under the GDPR you may ask for access, rectification, erasure, restriction, portability of your data, and object to processing based on legitimate interest. Write to support@merchanttools.eu; we answer within one month. You may also lodge a complaint with your supervisory authority, in France the CNIL (cnil.fr).
If you are a customer of a store that uses our apps, please contact the store directly: the merchant is the controller of their store's data and we act on their instructions.
14. Changes to this policy
We may update this policy when our apps or providers change. The date at the top indicates the current version; material changes are announced inside the affected app.
Our Omnibus Price History apps help you display price information required by EU rules. They are not legal advice.