Expiry Manager
Privacy Policy
Last updated: August 12, 2026
1. Introduction
This Privacy Policy describes how Expiry Manager (“the App”), operated by Origin Apps (“we”, “us”, or “our”), collects, uses, and shares information when merchants install the App on their Shopify store.
Expiry Manager tracks inventory at the batch level — batch numbers, quantities, and expiry dates per variant — allocates orders to batches earliest-expiry-first (FEFO), and gives merchants batch-to-order traceability and near-expiry visibility. By installing or using the App, you agree to the collection and use of information as described in this policy.
2. Information We Collect
When the App is installed, we access certain Shopify store data through the permissions (scopes) granted during installation, and we store the batch records merchants create in the App:
- Store information: your shop domain, store name, and the authentication tokens required for the App to communicate with Shopify on your behalf, along with the name and email address of the store staff account that installs or uses the App.
- Product and inventory information: products, variants, and inventory items, referenced so batches can be attached to the right variant and stock levels kept in sync.
- Batch records: the data you enter for each batch — batch number, quantities received and remaining, received date, expiry date, and any notes you add.
- Order and fulfillment information:order, line item, and fulfillment identifiers with their quantities and statuses, used to allocate orders to batches, restore stock on cancels and refunds, and provide batch-to-order traceability. These records are kept as Shopify identifiers only — they never include a customer’s name, email, or address.
- Settings: the expiry thresholds and preferences you configure in the App.
We store no customer personal information.The App’s records are inventory and allocation data keyed by Shopify order, variant, and batch identifiers — not by people.
We do not collect or store payment or credit card information. Payments are handled entirely by Shopify.
3. How We Use Your Information
We use the information we collect to:
- provide the App’s core functionality — recording batches, computing expiry status from today’s date, allocating orders to batches earliest-expiry-first, and restoring allocations on cancels and refunds;
- display batch health, near-expiry warnings, and batch-to-order traceability to the merchant in Shopify admin;
- respond to support requests and troubleshoot issues; and
- improve the reliability and performance of the App.
We do not sell, rent, or trade your data, and we do not use it for advertising or marketing to your customers.
4. Data Storage and Security
Batch, allocation, and session data are stored in a secured database operated by us. All data is transmitted over encrypted connections (HTTPS/TLS), and access to production systems is restricted to authorized personnel who need it to operate and support the App.
While we take commercially reasonable measures to protect your information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
5. Data Sharing and Disclosure
We only share information in the following limited circumstances:
- Service providers: with infrastructure providers (such as cloud hosting and database services) strictly as needed to run the App;
- Shopify: data flows between the App and Shopify as required for the App to function; and
- Legal requirements: when required to comply with applicable law, regulation, legal process, or enforceable governmental request.
6. Data Retention and Deletion
We retain store, batch, and allocation data for as long as the App is installed on your store. When you uninstall the App, we delete the store’s data immediately, and Shopify’s mandatory privacy webhooks provide a second guarantee:
- Customer data requests and erasure — because we store no customer personal information, there is nothing to compile or erase for these requests beyond confirming that fact;
- Shop data erasure — after uninstallation, Shopify issues the shop redact request and we verify that every record held for the store has been deleted.
Merchants can also request deletion of their data at any time by contacting us directly.
7. Your Rights
Depending on where you are located, you may have rights under data protection laws such as the GDPR (European Economic Area / United Kingdom) or the CCPA (California), including the right to:
- access the personal information we hold about you;
- request correction of inaccurate information;
- request deletion of your personal information; and
- receive a copy of your data in a portable format.
To exercise any of these rights, contact us using the details below. If you are a customer of a store using Expiry Manager, note that we hold no personal information about you — the App’s records reference orders by Shopify identifiers only.
8. Cookies
The App uses session tokens and strictly necessary cookies solely to authenticate merchants inside Shopify admin and keep the App working securely. We do not use advertising, analytics, or cross-site tracking cookies in the App.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App or in applicable law. When we do, we will revise the “last updated” date at the top of this page. Significant changes will be communicated to merchants through the App or by email.
10. Contact Us
If you have questions about this Privacy Policy or how your data is handled, contact us at support@originapps.zephron.ai.