Privacy Policy — ShrinkGuard: Loss Ledger

Effective: 10 September 2026

Who we are. ShrinkGuard: Loss Ledger ("the app") is operated by Matthew Schafer (operating as ARO PCRM), reachable at support@aro-pcrm.com.

What we collect. The app stores only: your shop domain, the app's session tokens, your app settings, and the loss records you create — product/variant IDs and titles, SKUs, quantity removed, the per-unit cost and computed value at the time of the entry, the reason and any note you add, and the location. It also keeps a log of actions the app performed. The app requests the read_products, read_inventory, write_inventory and read_locations permissions. Inventory access is used to show available stock and each item's cost, and — only when you click "Record loss" or "Undo" — to adjust that variant's available quantity. We do not store a mirror of your inventory.

What we never collect. No customer names, emails, addresses, orders, payment data, or analytics identifiers. The app has no storefront component and sets no cookies for your shoppers.

How we use it. Solely to provide the features you use: recording losses, valuing them at your product cost, showing your loss reports, and emailing the periodic loss report to the address you chose. Nothing is sold, shared, or used for any other purpose.

Where it lives. On the app's server database, encrypted at rest. Report emails are delivered via our email provider. Data is encrypted in transit (TLS).

Retention & deletion. Uninstalling the app stops all processing. When Shopify sends the shop/redact webhook (48 hours after uninstall), every record for your shop is permanently deleted. You can also email us for immediate deletion.

GDPR/CCPA webhooks. customers/data_request and customers/redact are acknowledged automatically; since the app stores no customer data, there is nothing to return or erase. shop/redact triggers full deletion as above.

Changes. We'll update this page and the effective date if practices change.

Back to ShrinkGuard