Legal

Privacy Policy

What Sortby reads from your store, what it keeps, where it is kept and for how long. Written from what the app actually does.

Last updated 19 August 2026

1. Who we are

Sortby is built and operated by inkOfPixel Srl, Piazza Castello 26, 20121 Milano, Italy. VAT number 09287730965.

For anything in this policy, including any request about your data, write to [email protected]. We answer within 30 days at the latest, and normally much sooner.

2. What this policy covers

Two things: the Sortby app installed on a Shopify store, and this website. They are described separately below, because they handle very different amounts of data — the website handles almost none.

3. Our role

When the app reads data from your Shopify store, we act as a data processor on your behalf: you decide what is in your store and what rules the app applies, and we process it only to provide the service. You are the controller of that data.

For your own merchant account details — which store installed the app, on which plan, and any correspondence with us — and for visitors to this website, we act as the controller.

4. What the app is allowed to access

Sortby requests exactly two Shopify access scopes: read_products and write_products. Nothing else. It does not request access to customers, orders, draft orders, checkouts, discounts, inventory locations, or any other part of your store.

Shopify shows you this list on the install screen and enforces it at the API level, so this is not a promise you have to take on trust — a request for anything else would be refused by Shopify.

5. What the app receives and stores

Store identity and installation state
Your myshopify.com domain, your Shopify shop ID, the access scopes you granted, the handle of your Shopify subscription plan, and whether the app is currently installed, together with the dates you installed and uninstalled it.
To tell stores apart, to call the Shopify API for the right one, to apply the limits of your plan, and to recognise a store that installs again after uninstalling.
Access credentials
The OAuth access token and refresh token Shopify issues when you install the app, and their expiry times.
To act on your store's behalf. Both tokens are encrypted at rest and are short-lived, refreshed automatically.
A copy of your product catalogue
For each product: Shopify id, handle, title, description, vendor, product type, tags, status, price and compare-at price range, currency, inventory total and whether inventory is tracked, featured image URL, product options, SEO title and description, and the created, updated and published dates.
Sorting scores every product in a collection against your rules. Holding a local copy is what makes that possible without querying Shopify on every sort.
Product metafields
Namespace, key, name, type and value of the metafields attached to your products.
So metafields can be used as sort criteria — the app's main feature.
Collections and your rules
Collection id, handle, title, image URL, product count, sort order, and the boost and sort rules you configured.
To know which collections to sort and in what order.
Computed sort values
The per-product values derived from your rules for each collection.
To reorder a collection without recomputing everything each time.
Operational records
Status, item counts, start and completion times and any error message for each import and sort run.
To show progress in the app and to diagnose failures.

6. What the app never receives

  • Customer records — names, emails, phone numbers, addresses
  • Orders, draft orders, carts or checkouts
  • Payment methods, card details or any financial instrument
  • Storefront visitor behaviour or tracking of your shoppers
  • Your Shopify staff accounts or their credentials

None of this is ever requested, so there is nothing to compile when one of your customers asks what you hold about them through us, and nothing to erase when they ask to be forgotten.

7. Personal data in a product catalogue

Almost everything the app stores is commercial information about products, not personal data about people. There are two exceptions worth naming.

Your store identity. A myshopify.com domain, and a vendor name, can identify a person when the merchant is a sole trader. We treat them accordingly.

Metafields. The app copies metafield values exactly as they are, because it cannot know in advance which ones you will want to sort by. If you store personal data in a product metafield, that data will be copied into the app. You control what goes in them; if you would rather it were not copied, do not put it in a product metafield.

8. Why we process it, and on what basis

To provide the app — importing your catalogue, scoring products, writing the new collection order back to Shopify. Basis: performance of the contract with you.

To apply your plan’s limits and bill you — we ask Shopify which subscription your store is on. Basis: performance of the contract.

To keep the service working and secure — logs, error records, abuse prevention. Basis: our legitimate interest in operating a reliable service.

To keep a record of stores that installed the app after they uninstall, in the reduced form described in section 9. Basis: our legitimate interest in recognising a returning store, keeping a record of the relationship, and preventing the free trial from being reset by repeated uninstalls and reinstalls. You can object to this and ask us to erase the record.

We do not sell data, we do not share it for advertising, and we do not use it to train machine-learning models.

9. How long we keep it

When you uninstall. Shopify sends an app/uninstalled webhook and the app immediately destroys the credentials it holds for your store — the access token, the refresh token and their expiry times. From that moment it can no longer reach your store at all, and it stops processing it: your store is skipped by every scheduled job.

Your catalogue copy, metafields, collections and rules are kept for a short window, so that reinstalling picks up where you left off instead of making you import everything and rebuild every rule.

When that window closes. Shopify sends a shop/redact request about 48 hours after uninstall. On receiving it the app deletes all of it: every product, metafield, collection, rule, computed value and job record. If that request never arrives, a daily job does the same thing for any store uninstalled more than 30 days earlier. Either way, your store’s data is gone within 30 days of uninstalling, and usually within two days.

What is left afterwards is a single row holding four things: your myshopify.com domain, the fact that the app is no longer installed, and the dates you installed and uninstalled it. No credentials, no catalogue, no rules, nothing about your products. We keep it to recognise a store that comes back, to keep a record of the relationship, and to stop the free trial being reset over and over by uninstalling and reinstalling. If you would rather we did not keep even that, ask us and we will delete it — see section 14.

Background job records are deleted as soon as each job finishes.

Server logs are kept for a limited period to operate and secure the service. Tokens, secrets, keys and email addresses are filtered out of them automatically.

10. Where the data is kept

On a dedicated server operated by Hetzner Online GmbH in their Helsinki, Finland data centre — inside the European Union. The database runs on the same host, on a private network, with no port open to the internet.

Data processed by the app is not transferred outside the European Economic Area, other than back to Shopify itself, which is where it came from.

11. Who else is involved

Shopify. Both the source of the data and its destination: the app reads your catalogue from Shopify and writes the new collection order back to it. Shopify also handles all billing — we never see a card number. Shopify’s own privacy terms apply to what it does with your data.

Hetzner Online GmbH. Hosting, as described above. They provide the infrastructure and do not process the data for their own purposes.

That is the complete list. The app contains no analytics, no error tracking service, no email provider, no advertising network, no AI service and no payment processor.

12. This website

The pages you are reading are served from Vercel. Standard server logs, including IP addresses, are generated in the course of serving them and are used only to deliver and secure the site.

This site sets no cookies and runs no analytics or tracking of any kind. That is why you are not being asked to accept anything.

13. How it is protected

  • Shopify access tokens and refresh tokens are encrypted at rest in the database.
  • Tokens are short-lived and refreshed automatically, so a leaked one would not stay valid.
  • All traffic is served over HTTPS, with HSTS enabled.
  • Incoming webhooks are verified by HMAC signature, so the app acts only on requests genuinely from Shopify.
  • The database is not reachable from the internet, and internal operational dashboards are behind authentication.
  • Sensitive parameters are filtered out of application logs automatically.

14. Your rights

Under the GDPR you can ask us for access to your personal data, for it to be corrected or erased, for processing to be restricted, for a portable copy, or you can object to processing based on legitimate interest. Write to [email protected].

For data belonging to your store, uninstalling the app is the fastest route: it destroys our credentials at once and everything else follows within 30 days, as described in section 9. To have the remaining record — your domain, the installation state and the two dates — deleted as well, ask us and we will remove it entirely.

If one of your customers exercises a right against you, we support the requests Shopify forwards to us. Because the app holds no customer data, the honest answer to those requests is that we hold nothing about that person.

If you think we have handled your data badly, you can complain to your local supervisory authority. In Italy that is the Garante per la protezione dei dati personali.

15. Changes to this policy

If what the app does with data changes, this page changes with it, and the date at the top is updated. Material changes affecting merchants will also be announced through the app or by email.

A shorter, plain-language summary of the same facts is on the data handling page. Where the two differ, this policy is the binding one.