This policy explains how the Z Reports app ("the App", "we", "us"), provided by Stock Atlas (based in the United Kingdom), handles information when you install and use it on your Shopify store. Stock Atlas is the data controller for the merchant data described below; you remain the controller of your own store and customer data.
This policy is for the Shopify merchants (store owners and staff) who install and use Z Reports. Z Reports is a point-of-sale tool that runs inside the Shopify POS app; it does not interact with the shoppers who visit your online storefront.
Z Reports produces an end-of-day "Z report" — a cash-up summary of your sales, payments, refunds and transaction and customer counts for a chosen period. To build that summary it reads your Shopify orders; it does not write to, or change, your store in any way.
The App requests only the Shopify permissions it needs: read access to your orders
(read_orders), to customers (read_customers, solely to count
customers on the report), and to locations (read_locations, so a report can be
broken down by POS location). It requests no write access and makes no changes to your
products, theme or store.
Because the report includes a customer count, the App uses Shopify's Protected Customer Data Access under the minimum level required for that feature. The App reads only what it needs to count customers for the report; it does not display, export or store shopper names, email addresses, phone numbers or addresses.
We do not sell your data, and we do not use it for advertising.
We share data only with the infrastructure providers needed to run the App, each under their own security and privacy commitments:
zreports@stockatlas.app.We do not sell your data. We may disclose information if required by law.
The App does not keep its own copy of your order history — it reads orders from Shopify each time it generates a report. Generated reports are saved on our server on both plans and kept until you delete them or uninstall; what differs is how much of that history the App shows you (your 5 most recent on Free, all of it on Z Reports Plus). You can delete saved reports at any time on Plus. Your settings and report recipients are also stored on our server.
When you uninstall the App, your access token is revoked and the App can no longer read your orders. Shopify then sends us an erasure request for your store — this normally arrives about 48 hours after uninstalling — and on receiving it we delete your saved report history, your report recipients and your support messages, and clear your store and contact details from your account record (see section 8). Your orders, products and store are not altered by uninstalling.
As required by Shopify, the App implements the mandatory compliance webhooks
customers/data_request, customers/redact and
shop/redact. Because the App does not store shopper personal data, the two
customer webhooks confirm we hold no such data; the shop/redact webhook redacts
your account record (clearing your store and contact details) and deletes the saved report
history, the report recipients and the support messages the App stored for your store.
Access tokens are held securely, data is transmitted over HTTPS, and access to our systems is restricted. No system is perfectly secure, but we take reasonable measures to protect the data we handle.
Depending on where you are based (for example under UK/EU GDPR), you may have rights to access, correct or delete data we hold about you, or to object to certain processing. To exercise these rights, contact us using the details below. Stock Atlas is the data controller for the merchant data described above.
We may update this policy as the App evolves. We'll change the "last updated" date above and, for material changes, make reasonable efforts to notify merchants.
Stock Atlas, United Kingdom
Email: hello@stockatlas.app