Privacy policy
Last updated September 29, 2026
Mint Back in Stock is a Shopify app made by Mint Labs ("we", "us"). It lets shoppers on a merchant's Shopify store ask to be emailed when a sold-out product is back in stock (or, if the merchant offers it, when its price drops), and sends those emails. This policy explains what the app handles about merchants and about the merchant's shoppers, why, and when it's deleted. For shopper data we act as a service provider (processor) to the merchant, who is the controller.
The short version
- For each request we store the shopper's email address (encrypted), the product variant, the date and whether they ticked the optional marketing box.
- A request is deleted as soon as its alert email has been sent, or after 180 days if the item never comes back. Shoppers can unsubscribe from every email in one click.
- We use the email address only to send the alert the shopper asked for. We never sell or share data, use it for advertising, or combine it across stores.
- No cookies and no tracking pixels. We count clicks on the email's links to show the merchant how alerts perform.
Information about merchants
| Information | Why |
|---|---|
| Store domain and a Shopify access token | To check stock and prices of the items shoppers wait for, receive inventory, product and order notifications, and save the storefront settings. |
| Store name, store email, contact email, currency, money format and primary domain | The store name is the sender name of alert emails, the contact email is their reply-to address and appears in the footer, the store email receives test emails, and the domain is used for links back to the store. |
| Settings (button and form texts, colours, sending rules, email texts, logo link) | To show the button and send emails the way the merchant set them up. |
| Plan and subscription status | Read from Shopify to decide which features apply. Payments are handled entirely by Shopify. |
| Product and variant details for items shoppers wait for (title, image link, price, stock that can be sold online) | To decide when an item is back and to show it in the email and the demand report. Not personal data. |
Information about the merchant's shoppers
| Information | How it's used | Kept |
|---|---|---|
| Alert requests: email address (encrypted with AES-256-GCM), a keyed one-way hash of it, the variant, the date, for price-drop requests the price at the time, and whether the shopper ticked the marketing box | To send the one email the shopper asked for, avoid duplicates, and show the merchant who is waiting (the merchant can see and export these). | Until the alert is sent, or 180 days; a request whose address the email service rejects is removed after 30 days |
| Sent alerts: product, variant, time sent, whether and when a link was clicked, and — if an order followed — the order ID, order number and the amount of the alerted product in it | To show the merchant clicks and orders from alerts. No email address is kept. | 13 months |
| The keyed hash of the email on a sent alert | To recognise an order placed by the same shopper within 7 days of clicking the alert (the order's email is hashed the same way and never stored). | 30 days after sending |
| Unsubscribes: the keyed hash of the email | So we never email that shopper about that store again unless they ask for a new alert. | While the app is installed, until the shopper's data is erased |
| Rate-limit keys: keyed hashes of the shopper's IP address and email | To stop automated or repeated sign-ups. | Up to 24 hours |
| Marketing consent (only if the shopper ticks the optional, unticked box) | We create or update the shopper's customer record in the merchant's Shopify store with email marketing consent and the tag mint-back-in-stock. We don't keep a copy. | In the merchant's store, under their control |
| Order notifications from Shopify (orders/create) | Only the order ID, number, date, currency, line items and the alert cart attribute are read; the email is only hashed for matching. Nothing else is stored or logged. | Not stored |
| Browser storage on the shopper's device | The storefront script saves the date in local storage so it tells us "the button is live" at most once a day. No cookies. | On the device |
Emails we send
Alert emails are sent through Cloudflare Email Service from our sending domain (mail.stickermint.com), with the store's name as the sender and the store's contact email as the reply-to address. Each email says why the shopper got it, includes a one-click unsubscribe link, and is sent once per request. Links in the email go through our server so we can count the click; they then take the shopper straight to the store.
Customer privacy requests
- Access requests (Shopify's
customers/data_request): the app home shows the request and the merchant downloads everything we hold about that shopper as a file to send them. - Erasure requests (
customers/redact): we permanently delete the shopper's requests and unsubscribe record, and remove the link between them (and the listed orders) and any sent alerts. - Store deletion (
shop/redact, sent 48 hours after a merchant uninstalls): we permanently delete everything we hold for the store. - Shoppers can also unsubscribe at any time with the link in every email, which deletes everything they're waiting for at that store.
Where data is processed and how it's protected
The app runs on Cloudflare (hosting, database, message queue and email sending) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest; shopper email addresses are additionally encrypted by the app with a key kept separately from the database. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers. See our security policy.
Retention
Requests are deleted once their alert is sent or after 180 days. Sent-alert statistics are kept for 13 months, without email addresses. Access tokens are deleted as soon as the app is uninstalled, and everything else 48 hours later when Shopify asks us to delete the store's data. Short-lived server logs kept by Cloudflare don't contain email addresses.
Your rights
Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly; shoppers can unsubscribe from any email, contact the store they asked for alerts from, or email us and we'll pass the request on. We respond within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com