Kestori
Pricing Migrate from Stocky

Kestori Privacy Policy

Effective date: 2026-06-04

Operator: Forethought Studio

Contact: [email protected]

What Kestori is

Kestori is a Shopify app that helps merchants spot SKUs at risk of stockout. It sends a daily low-stock digest email and surfaces an embedded dashboard inside the Shopify admin. Kestori operates as a data processor on behalf of the installing merchant store.

What we access

When a merchant installs Kestori, Shopify grants the app a set of API scopes. Kestori reads:

  • Products and variants (read_products): SKU, title, variant identifiers, product/variant metadata necessary to display low-stock candidates and accept per-SKU configuration.
  • Inventory levels (read_inventory): on-hand quantity per variant per location, polled and updated via webhooks (inventory_levels/update, products/update, products/delete).
  • Order line items (read_orders, pending Shopify approval for protected customer data access): unit counts and timestamps for sold variants, used solely to compute 28-day sales velocity. Kestori does not read customer names, addresses, emails, phone numbers, payment details, or any other order field beyond line-item quantity and time. Until this scope is granted, velocity is unavailable and Kestori falls back to a configuration-only forecast.

Kestori does not read:

  • Customer personal data (names, addresses, contact info, payment instruments).
  • Storefront browsing or session data.
  • Anything outside the granted scopes above.

What we collect from the merchant

  • Account email: from the Shopify session, used as the default recipient of the daily digest. The merchant can change or add recipients in the app's settings page.
  • Configuration: lead-time days, safety-buffer days, per-SKU overrides, digest recipients, and digest pause state. Entered by the merchant in the app.
  • In-app feedback: when the merchant uses the "Send feedback" control in the embedded app, Kestori stores the message text they write, an optional topic, the app screen they were on, the shop's plan, and the app version. The message is merchant-authored and may contain personal data; it is stored first-party and forwarded only to Kestori's internal support inbox ([email protected]), never to any third party. It is treated as shop personal data for retention and deletion (see below).
  • Post-uninstall survey: after the merchant uninstalls Kestori, we send the store owner one email asking why they left, with a few pre-written reasons plus an optional free-text box. If they answer, Kestori stores the reason they pick, their optional free-text note, the shop domain, and which channel the answer came from. This outreach relies on Kestori's legitimate interest in understanding why merchants leave; it is a single message, it is stored first-party and never shared with any third party, and it is treated as shop personal data for retention and deletion (see below). Every such email carries a one-click opt-out that Kestori honors.

How data is stored

  • Location: a managed MySQL 8 database on a Hetzner Cloud server in Nuremberg, Germany (EU).
  • Encryption in transit: TLS 1.2+ for all browser, Shopify API, and email-relay connections.
  • Encryption at rest: the host disk uses LUKS full-disk encryption.
  • Access: limited to the operator account (Forethought Studio) and Shopify webhook ingest via HMAC verification. No analytics, advertising, or third-party data brokers receive Kestori data.

Product analytics

Kestori measures a small, fixed set of activation milestones to understand what share of installs finish setting the app up. This is first-party and privacy-preserving by design:

  • First-party and self-hosted: analytics run on a self-hosted Umami instance operated by Forethought Studio on the same Hetzner infrastructure in Germany (EU). No third-party analytics provider (Google Analytics, Mixpanel, PostHog, or similar) is used, and no analytics data leaves Kestori's own infrastructure or the EU.
  • Cookieless: Kestori sets no analytics cookies and uses no browser local storage for analytics. There is no analytics script in the embedded app, so nothing runs in the merchant's browser and no consent banner is required.
  • Server-side and IP-free: events are emitted from the Kestori server, not the merchant's browser, so the merchant's IP address is never sent to or stored by the analytics system.
  • No personal data: the only events recorded are a fixed funnel set (app installed, first catalog sync completed, settings opened, a per-SKU threshold adjusted, the digest set up to send, and a digest sent). No operator email, merchant name, or raw shop domain is recorded. Where a per-shop measure is needed, Kestori uses an opaque keyed hash of the shop domain that cannot be reversed to the domain and that Kestori does not store anywhere in its own database.
  • Lawful basis: legitimate interest in aggregate, pseudonymous product-activation measurement. Because the data is pseudonymous, aggregate, and free of personal identifiers, it is not used to profile or target individuals.
  • Retention: analytics events are retained for a bounded period (180 days) and then deleted.
  • On uninstall: because Kestori stores no analytics identifier of its own and the shop domain it is derived from is erased on uninstall (see below), no residual analytics linkage to the shop remains in Kestori; the pseudonymous events age out under the retention window above.

How long we keep data

Kestori retains shop data only while the app is installed.

  • On uninstall (app/uninstalled webhook): the merchant's products, variants, inventory snapshots, order rollups, settings, in-app feedback, sessions, and billing state are queued for deletion and removed within 48 hours.
  • On Shopify privacy webhooks:
    • customers/data_request: Kestori does not store customer-identifying data; we acknowledge and respond with confirmation that no customer-identifying records exist.
    • customers/redact: same as above (no records to redact).
    • shop/redact: a final sweep removes any residual rows for the shop within 30 days of the webhook, per Shopify's published GDPR compliance window.
  • Post-uninstall survey reasons: on shop/redact the personal parts of any post-uninstall survey (shop domain, recipient email, and free-text note) are erased; only a single non-identifying reason category may be retained in aggregate to understand why merchants leave.
  • Product analytics: pseudonymous, aggregate activation-funnel events (see "Product analytics" above) are retained for a bounded period of 180 days, then deleted. They contain no personal identifiers and no per-shop identifier that Kestori stores.
  • Operational logs: structured log lines (without customer-identifying content) are retained for 30 days for debugging and security review, then rotated out.

Third parties

Kestori uses Shopify as the app data source and a small, fixed set of subprocessors:

  • Shopify (data source): the merchant's Shopify store, accessed via Admin GraphQL.
  • Hetzner Online GmbH / Hetzner Cloud (hosting): operates the server that runs the Kestori application and database in Germany. Hetzner handles Shopify sessions, product records, variant records, inventory snapshots, sales velocity source data, merchant settings, merchant email records, operational logs, and encrypted backups.
  • Amazon Web Services EMEA SARL / Amazon Web Services Simple Email Service (SES) (email delivery): sends the daily low-stock digest email to the merchant's configured recipients. Recipient email addresses, message headers, delivery metadata, and digest contents (product titles, SKUs, quantities) transit SES; SES retains transient delivery metadata per AWS's own retention policy.
  • Cloudflare, Inc. (DNS, reverse proxy, and TLS termination): handles request and response metadata for traffic to Kestori, including client IP addresses, request headers, session cookies, and the request and response bodies exchanged with the embedded Shopify admin app.
  • Functional Software, Inc. dba Sentry (application exception and error monitoring): handles error events, stack traces, runtime environment metadata, and the request context attached to a failing operation, from both the Kestori server and the embedded admin UI running in the merchant's browser. The browser-side reporter is configured to scrub personal data before sending: it does not attach user identity, cookies, request bodies, form input values, or fields whose names indicate personal data (email, phone, address, and similar). Kestori does not deliberately send shopper personal data to Sentry; merchant shop domains and operator email addresses may appear in error context.

What the merchant can do

  • View or export data: contact [email protected]; we will provide a copy of every row Kestori stores for the shop in JSON.
  • Delete data on demand: uninstalling Kestori from the Shopify admin triggers the deletion path described above. Alternatively, email [email protected] to request immediate deletion without uninstalling.
  • Pause the digest: the settings page in the embedded app exposes a digest pause toggle that takes effect on the next scheduled send.
  • Opt out of the post-uninstall email: every post-uninstall survey email includes a one-click opt-out link; using it stops further Kestori emails to that address.

Changes to this policy

Material changes will be announced in the embedded dashboard at least 30 days before they take effect, and the effective date above will be updated.

Contact

Questions, deletion requests, or privacy concerns: [email protected].

Kestori, a Forethought Studio product.
Pricing Migrate Privacy Terms Legal DPA Subprocessors