Privacy Policy

This policy covers Soon: Preorder & Back in Stock, and any other Shopify app published by Drozium.

Last updated 29 July 2026

Who we are

Drozium builds Shopify apps. In this policy, “we” means Drozium, “merchant” means a Shopify store owner who installs one of our apps, and “shopper” means a customer of that store.

For data that shoppers give us through a merchant's storefront, the merchant is the data controller and we act as their processor. For the merchant's own account data, we are the controller.

What shoppers give us

When a shopper asks to be notified about a sold-out product, we store only what is needed to send that one notification:

  • the email address or phone number they typed into the notify-me form;
  • which product and variant they are waiting for, and the store it belongs to;
  • the status of the alert we sent them (queued, sent, delivered, failed, and the reason if it failed).

A shopper only ever gives us this by choosing to sign up. We do not build profiles, track shoppers across stores, or use their contact details for anything other than the alert they asked for. We never sell or rent data, and we do not use it for advertising.

What we read from Shopify

Our apps request the minimum Shopify access needed to work: products, inventory levels, orders and purchase options. From an order we read only the line items, totals, currency and the cart attributes our own storefront script set.

We do not request or store Shopify protected customer data — no customer names, email addresses, phone numbers or shipping addresses. Sales are credited back to the alert that caused them using an anonymous identifier we generated ourselves, never by matching the shopper's identity.

What the merchant gives us

Store domain, plan, sender name, reply-to address, and any preorder or alert settings the merchant configures. If a merchant connects WhatsApp, their access token is encrypted before it is stored.

Browser storage on the storefront

Our storefront script stores one value in the browser's localStorage for up to 30 days: the anonymous identifier from the alert link a shopper clicked. It carries no name, email or phone number, and exists only so the merchant can see which sales their alerts produced. It is also written as a cart attribute on that shopper's cart.

Inside the Shopify admin, our app uses session cookies required for Shopify authentication. We set no advertising or analytics cookies.

Who else processes the data

We use a small number of sub-processors, all under contract:

  • Render — application hosting (United States).
  • Neon — PostgreSQL database (United States).
  • Resend — email delivery (United States).
  • Meta Platforms — WhatsApp Cloud API, only for merchants who enable WhatsApp alerts.

Data is encrypted in transit (TLS) and at rest. Access to production data is limited to the people who operate the service.

How long we keep it

  • Waitlist signups — until the shopper is notified or unsubscribes, and then only as an audit record of the alert we sent. A shopper can unsubscribe from any alert email.
  • Delivery logs — kept so merchants can see failures rather than silent drops.
  • Merchant settings — deleted when the store asks us to erase its data.

Deletion and data requests

We implement Shopify's mandatory compliance webhooks. When a merchant or Shopify sends a customers/data_request, customers/redact or shop/redact request, we respond to it automatically: redaction deletes the shopper's signups and contact details and strips them from any related records.

Shoppers and merchants can also write to rangaswamyvikass@gmail.com to ask what we hold, correct it, or have it deleted. Depending on where you live you may have rights under the GDPR, UK GDPR or CCPA/CPRA — including access, correction, deletion, and objecting to processing. We honour these regardless of where you live, and we do not discriminate against anyone for exercising them.

International transfers

Our infrastructure is in the United States, so data from other countries is transferred there. Transfers out of the EEA and UK rely on the European Commission's Standard Contractual Clauses with our sub-processors.

Children

Our apps are business tools sold to merchants, and are not directed at children. We do not knowingly collect data from anyone under 16.

Changes

If we change this policy we update the date at the top of the page. Material changes affecting merchants are announced by email to the address on the store's account.

Contact

rangaswamyvikass@gmail.com — for privacy questions, data requests, or anything else in this policy.