Effective September 13, 2026 · Version 1.2
Privacy
BackInStockBro processes information only to provide, secure, support, and measure merchant-authorized back-in-stock and product-availability notifications.
Information processed
We process Shopify shop and installation identifiers, product and variant references, inventory availability, merchant configuration, shopper email addresses, and—only when a shopper selects the disclosed text-message choice—a submitted mobile number and consent record. We also process delivery and engagement events and suppression records. We do not use purchased or scraped recipient lists.
Purpose and sharing
Information is used to record a shopper's request and choices, detect qualifying availability, deliver and measure the requested notification, prevent duplicates, honor opt-outs, and support the merchant. When a merchant connects Klaviyo and the shopper selects an optional marketing channel, BackInStockBro sends the applicable email address or mobile number, consent intent, and requested-item event to that merchant's Klaviyo account. We do not sell personal information or use one merchant's information for another merchant.
Service providers
- Shopify provides commerce and app authorization services.
- Amazon Web Services provides application hosting, storage and related infrastructure. Amazon SES may provide email delivery where configured.
- Twilio SendGrid provides email delivery for the public app. It processes recipient email addresses, sender details, message content and delivery information needed to send notifications and handle delivery events.
- Klaviyo processes the channel identifier, consent intent, requested-item event, message content, and delivery activity for a merchant that chooses to connect its Klaviyo account. Klaviyo controls its own sending eligibility, suppression, and delivery.
- Cloudflare Turnstile helps protect notification forms from automated abuse. When a challenge is loaded, Cloudflare processes browser, device and network information to assess the request. See Cloudflare's Turnstile privacy addendum.
Email or text delivery information may include message identifiers, delivery status, bounces, complaints, and opt-outs. A merchant's optional marketing-platform connection remains subject to that merchant's configuration and provider agreement.
Choice, suppression, and deletion
Optional email and text choices are separate and unchecked by default. A mobile number alone does not grant text-message consent. Email notifications include a signed opt-out link; text recipients can reply STOP where supported by the connected provider. Bounces, complaints, and applicable opt-outs suppress future delivery for that merchant and channel. Shopify privacy webhooks support customer and shop deletion obligations. An authorized merchant may request assistance through Support.
Security and retention
Tenant context is derived from verified Shopify authorization. Provider tokens are encrypted server-side, raw channel identifiers are excluded from queue messages and operational logs, and operational records use bounded retention where appropriate. Uninstall disables the installation and Shopify's privacy lifecycle governs deletion. Do not send credentials or unnecessary customer information in a support request.
Shared BroFam policies
This notice supplements BroFam's privacy, security, and subprocessor disclosures. The service-provider description above applies specifically to BackInStockBro.
Change history
Version 1.2 — September 13, 2026: disclosed optional Klaviyo email/SMS processing, mobile numbers, channel consent, and provider suppression responsibilities. Version 1.1 — September 10, 2026: clarified product-availability notifications and disclosed SendGrid email delivery and Cloudflare Turnstile. Version 1.0 — August 30, 2026: initial notice.