MultiNest ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that keeps inventory in step across two or more Shopify stores owned or operated by the same merchant. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
Contact / Data Protection: support@appnest.studio
1. Who the data belongs to
The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's Shopify store data solely to provide the store-to-store sync the merchant configured.
2. What we access and why
The App is installed on every store it links. On each store we request the minimum scopes needed:
| Scope | Why |
|---|---|
read_products |
Read SKUs, barcodes and variant titles so products can be matched between stores |
read_inventory, write_inventory |
Read stock levels on the source store; write the matching quantity on the destination store |
read_locations |
Resolve location names for location mapping |
The App does not request access to orders or customers. It never receives customer personal data.
3. What we store
| Data | Stored? | Notes |
|---|---|---|
| Shopify session / access token (per linked store) | Yes | Required to call the Admin API |
| Store links (which store pushes to which), pairing codes | Yes | Your configuration; codes expire within 15 minutes |
| Inventory cache: SKU, barcode, product/variant title, vendor, type, tags, location, available quantity | Yes | Used to match products between stores and to detect drift |
| Alert email / Slack webhook URL | Yes | Where to notify you on failure |
| Run history (which quantities were written, before/after), usage counts | Yes | Powers progress, undo and the audit trail |
| Order, customer or payment data | No | Never requested |
4. Data retention & deletion
- Configuration, links and the inventory cache are retained while the App is installed on that store.
- On app uninstall and on the Shopify
shop/redactcompliance webhook, we delete all data for that store, including its links. The other store keeps its own data and simply stops receiving updates. Nothing on it is changed. - We honour the Shopify
customers/redactandcustomers/data_requestcompliance webhooks. Because we hold no customer data, there is nothing to return or erase. - Run history is pruned after 90 days.
5. Subprocessors / third parties
| Provider | Purpose | Data shared |
|---|---|---|
| Hosting (Railway) + Postgres/Redis | Run the App | Stored data listed in §3 |
| Resend | Alert emails (if configured) | Your alert email + error summary |
| Slack | Alert messages (if configured) | Your webhook + error summary |
| Sentry | Error tracking (if configured) | Diagnostic error data |
We do not sell personal data or use it for advertising.
6. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
7. Security
- All API traffic is over HTTPS.
- Writes to a linked store are optimistic-concurrency checked and reversible (undo); removing a link never deletes or zeroes inventory on either store.
- We store the minimum necessary and no customer data.
8. Your rights
Merchants can export or delete their data by uninstalling the App (triggers full deletion for that store) or by contacting us at the address above. Data subjects should contact the merchant (controller) for GDPR/CCPA requests; we assist the merchant in fulfilling them.
9. Changes
We will update this policy as the App evolves and revise the "Last updated" date above.
MultiNest by AppNest Studio · support@appnest.studio