Privacy Policy
Last updated: April 30, 2026
This Privacy Policy explains how Evenly (“we”, “our”, or “us”) collects, uses, and protects information when you install and use the Evenly app on your Shopify store.
Who we are
Evenly is an inventory rebalancing app for Shopify, operated by Super Spicy Apps, JZ s.p. For privacy questions, contact us at hello@runevenly.com.
What data we collect
From Shopify, automatically on install
- Your shop’s myshopify.com domain
- Shop owner name, email address, primary locale, and timezone
- Your current Shopify plan name
- An OAuth access token used to authenticate calls to Shopify’s Admin API (encrypted at rest)
From Shopify’s Admin API, on each analysis you run
- Product titles, IDs, and tags
- Product variants and their inventory item IDs
- Inventory locations and stock levels
- Subscription status (for billing reconciliation)
From you, when you configure the app
- Main location selection
- Rebalancing strategy (balanced or custom percentages)
- Minimum stock threshold and minimum transfer size
- Excluded locations, products, and product tags
- Analysis schedule
- Notification email address (if you enable email notifications)
- Slack webhook URL (if you enable Slack notifications)
Generated by the app
- Analysis run records (timestamps, status, summary statistics)
- Recommendations (which products, which quantities, which locations)
- References to Shopify transfer drafts created by the app
Anonymous usage analytics
We use Google Analytics 4 to understand how merchants navigate the Evenly admin interface and the runevenly.com marketing site — for example, which pages are viewed and which buttons are clicked. The data collected is aggregated and not used to identify individual people. IP addresses are anonymized by Google before storage. We do not use this data for advertising and we do not share it with third parties.
Live chat support
Inside the embedded Evenly app we include a Tawk.to chat widget so merchants can reach our support team. The widget script loads on app pages so the chat bubble can appear; if you don’t open a chat, no message content is sent. When you start a chat, your shop domain, plan tier, and message content are sent to Tawk.to so we can identify your store and respond in context. The chat widget is not present on the runevenly.com marketing site.
How we use this data
We use the data above only to:
- Authenticate your store and authorize Shopify Admin API calls
- Run inventory analyses and generate transfer recommendations
- Create transfer drafts in your Shopify admin (if you have enabled this)
- Send notifications by email or Slack about completed analyses
- Process billing through Shopify’s appSubscription APIs
- Diagnose errors and improve the service
We do not sell, rent, or share your data with third parties for marketing or advertising.
Subprocessors
We use the following third-party services to operate Evenly:
| Subprocessor | Purpose | Region |
|---|---|---|
| Railway | Application hosting and PostgreSQL database | United States |
| Sentry | Error monitoring (production only; aggregated diagnostics, no merchant data shipped) | Germany |
| Shopify | Source of merchant and inventory data; recipient of transfer drafts | United States |
| Slack | Notification delivery (only if you provide a webhook URL) | United States |
| Google Analytics 4 | Aggregate, anonymized usage analytics for the marketing site and embedded app (no merchant or customer PII) | United States |
| Tawk.to | Live chat support widget inside the embedded app (only processes data when a merchant initiates a chat) | United States |
Adding a new subprocessor would require an update to this Privacy Policy.
Data retention
- While Evenly is installed: data is retained for as long as the app remains installed on your store, plus 30 days after uninstall (during which you may reinstall and recover settings).
-
After 30 days post-uninstall: all shop records,
including settings, analysis history, and access tokens, are
permanently deleted. This deletion is automated and triggered by
Shopify’s
app/uninstalledandshop/redactwebhooks. - Aggregate analytics (anonymous counts of analyses run, app installs, etc.) may be retained without personally identifiable information for the operation of the service.
Security
- All access tokens are encrypted at rest in our database.
- Data transmission between Evenly and Shopify, between Evenly and your browser, and between Evenly and our subprocessors uses TLS encryption.
- Database access is restricted to internal systems; no public network access.
- We use Sentry for error monitoring in production only. Error reports are stripped of access tokens and sensitive headers before transmission.
Your rights under GDPR and similar laws
If you are based in the European Economic Area, the United Kingdom, California, or another jurisdiction with comparable data protection laws, you have the following rights:
- Access: request a copy of the data we hold about your store.
- Rectification: correct inaccurate data.
- Deletion: request deletion of your data (in practice, achieved by uninstalling the app).
- Portability: receive your data in a machine-readable format.
- Restriction or objection: limit how we process your data.
- Withdrawal of consent: withdraw consent for any processing based on consent (e.g., notifications).
To exercise any of these rights, email hello@runevenly.com. We will respond within 30 days.
We honor Shopify’s mandatory GDPR webhooks:
-
customers/data_request— because we do not store customer data, our response is to confirm no data exists. customers/redact— same.-
shop/redact— we permanently delete all data associated with the shop within the timeline Shopify specifies (currently 48 hours).
International data transfers
If you are located in the European Economic Area or the United Kingdom, your data may be transferred to and processed in the United States by our hosting and notification subprocessors. We rely on the Standard Contractual Clauses (SCCs) approved by the European Commission as the lawful basis for these transfers.
Cookies
The Evenly app, when used inside the Shopify admin, uses session cookies necessary for security (CSRF protection) and for displaying confirmation messages after actions.
We also use Google Analytics 4 cookies on the runevenly.com marketing site and inside the embedded app to measure aggregate usage (for example, which pages are visited most often). These cookies do not contain personally identifiable information and are not used for advertising. Most browsers and ad-blockers offer the option to block analytics cookies; doing so does not affect your ability to use Evenly.
This privacy policy page itself does not set any cookies.
Children’s data
Evenly is a B2B service for Shopify merchants. It is not directed at children under 16, and we do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent change. Material changes will be communicated to active merchants by email at least 30 days before they take effect.
Contact
If you have any questions about this Privacy Policy or our data practices, contact us at hello@runevenly.com.