Keha Preorder & Back in Stock — Privacy Policy

Last updated: September 28, 2026

Keha Preorder & Back in Stock (“the App”) provides preorder, back-in-stock and low-stock features for Shopify stores. Keha (“we”) operates the App. This policy explains what information the App collects from merchants and their customers, why, who processes it, how long it is kept, and how to reach us. For customer data, the merchant is the data controller and we act as their processor.

Information we collect

From merchants: the store’s domain, name and email addresses, and an API access token received through Shopify’s standard authorization flow; the settings, preorder rules, email templates and translations the merchant creates; the plan and billing status of the App subscription; and, if the merchant connects Klaviyo, a Klaviyo access token or API key.

About the merchant’s customers: for orders that contain preorder items — the customer’s name and email address, the order reference, the items, deposit and balance amounts, payment status, market and checkout language. For back-in-stock sign-ups — the email address, and a phone number if the store asks for one and the customer gives it, the product the customer is waiting for, language, market, whether and when they ticked the consent box, and whether the notification was sent. The App does not send text messages; if the merchant chooses, back-in-stock sign-ups (email and phone) are saved to the merchant’s own Klaviyo account or as customers in their Shopify store, and the merchant can export them. Customer data is used only to run the features the merchant turned on.

Automatically: standard server logs (such as IP address and request time) kept by our hosting provider for security and troubleshooting. The storefront script does not use tracking cookies.

How we use information

Data is used only to provide the App to the merchant: running preorder campaigns, enforcing preorder limits, tagging preorder orders, sending the back-in-stock and preorder emails the merchant configures, and showing the merchant how their campaigns perform. We do not sell personal information or use it for advertising.

Service providers (subprocessors)

We share data only with the providers needed to run the App:

Data retention and deletion

We keep data while the App is installed. The App handles Shopify’s mandatory privacy webhooks: a customer data request is gathered and sent to the store owner to answer, and a customer deletion request removes that customer’s back-in-stock sign-ups (by email or phone) and removes their name and email from preorder records. When a merchant uninstalls the App, the access token stops working immediately and all stored data for that store is permanently deleted 48 hours later (unless the App is reinstalled within that time). Customers can stop back-in-stock emails with the unsubscribe link in every such email.

Security

Data is transmitted over HTTPS and stored with access limited to the App’s backend. Klaviyo tokens and API keys are encrypted at rest (AES-256-GCM) and are never shown again after they are saved.

Your rights

Customers of a store should contact that store to access, correct or delete their data; the store can make the request through Shopify, and the App carries it out. Merchants can contact us directly.

Contact

Privacy questions or requests: [email protected] (Keha).