StackWatch · Last updated: 3 October 2026
StackWatch is operated by Sico Software Ltd, Suite 2/3, Floor 2, 48 West George Street, Glasgow, G2 1BP, United Kingdom (support@sico.software). This policy explains what data we collect when you connect your store to StackWatch, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.
When you connect StackWatch to your store, we collect and store:
read_apps permission) to let us query the Shopify Admin API on your behalf. StackWatch has no Shopify OAuth route, because Shopify does not grant read_apps to OAuth apps.StackWatch does not collect or store customer personal data (names, addresses, payment details, or order history). Order data is not accessed or stored.
We do not sell your data, use it for advertising, or share it with third parties for their own purposes.
We share data with the following sub-processors to operate the service:
| Processor | Purpose | Data shared |
|---|---|---|
| Shopify | Source platform; we read your app charges from its Admin API | Your access token, presented on each request |
| Hetzner Cloud | VPS hosting for the application and database | All data at rest (encrypted volume) |
| Resend | Transactional email delivery | Merchant email address, alert content |
| PostHog | Product analytics (PostHog Cloud) | Anonymised install and feature events; shop domain as tenant identifier |
| Sentry | Error monitoring | Error traces that may include shop domain; no customer PII |
| Data type | Retention period |
|---|---|
| Shopify access token | Deleted immediately when you disconnect your store |
| App billing history (charges, installed apps) | Retained while your account is active; deleted on request |
| Price alerts | Retained while your account is active; deleted on request |
| Usage events (PostHog) | 12 months rolling |
| Error traces (Sentry) | 90 days |
Because StackWatch connects with a token you paste rather than as an installed Shopify app,
Shopify sends us no uninstall or shop/redact webhook. Disconnecting your store
deletes the stored token straight away (you can also delete the Custom App in your Shopify admin
to revoke it). To have your billing history and alerts deleted, email support@sico.software.
You have the right to:
To exercise any of these rights, email support@sico.software. We will respond within 30 days. You also have the right to lodge a complaint with the ICO (UK supervisory authority).
Your Shopify access token is encrypted at rest using AES-256-GCM. All data is stored on Hetzner Cloud infrastructure within the EU (Falkenstein, Germany). Access to production systems is restricted to named administrators via SSH with key authentication only.
We may update this policy as the product changes. Material changes will be communicated via email to your merchant account address. The "Last updated" date at the top of this page reflects the most recent revision.
Sico Software Ltd · Suite 2/3, Floor 2, 48 West George Street, Glasgow, G2 1BP
support@sico.software