Material Tracking
Effective date: June 1, 2026 · Last updated: June 2, 2026
Material Tracking ("the App") is a Shopify embedded application operated by Silva ("we," "us," "our"). This policy describes what data we collect from merchants and their stores, how we use it, how long we keep it, and your rights regarding that data.
When a merchant installs the App, we collect and store the following:
orders/fulfilled webhook, used exclusively to deduct material stock in Auto mode. Shopify fulfillment webhook payloads may contain additional order information, but the App uses and stores only the product variant IDs and quantities required to deduct material stock.We do not intentionally store customer names, email addresses, phone numbers, billing addresses, or shipping addresses.
The App stores operational data created by the merchant:
This data is scoped to the installing shop. It is not shared with other merchants and is disclosed only to service providers required to host and operate the App, as described in this policy.
All data collected and stored is used solely to provide the App's core functionality:
We do not use any data for analytics, advertising, personalization, or any purpose beyond operating the App.
When a merchant enables Auto mode on a product configuration, the App subscribes to theorders/fulfilled Shopify webhook. When an order is fully fulfilled, we receive the order payload and extract only the variant ID and quantity from each line item. This information is used to deduct the corresponding raw material stock.
Material stock deducted by Auto mode is not automatically restored if an order is cancelled, refunded, or returned. Merchants can manually adjust stock in the App if needed.
All shop data (materials, configurations, stock activity, and build history) is retained for as long as the App is installed on the merchant's store.
Approximately 48 hours after the App is uninstalled, Shopify sends us a shop data deletion request through the shop/redact compliance webhook. We use that request to delete the shop's materials, product configurations, stock activity, build history, Shopify access credentials, and other shop-specific data from our active PostgreSQL database.
The App uses a Render PostgreSQL database with point-in-time recovery. Deleted records may remain temporarily recoverable in Render's managed backups for up to 7 days. These recovery copies are maintained for disaster recovery and are not used for any other purpose.
The App and its PostgreSQL database are hosted by Render Services, Inc. in Render's Frankfurt region. Render processes data on our behalf to provide application hosting, database hosting, networking, logging, and related infrastructure services.
Although the App's primary services and database are hosted in Frankfurt, Render is a United States-based service provider and data may be processed by Render or its authorized subprocessors in other jurisdictions where permitted by applicable law.
The App uses Sentry (Functional Software, Inc.) for server-side error monitoring. When application errors occur, Sentry receives error reports containing technical details such as stack traces and error messages. Sentry's ingest endpoint is located in Germany. Sentry is a United States-based company. Error events are retained for up to 90 days. Sentry is configured to exclude request headers and IP addresses from error reports.
We do not sell or rent merchant or customer data. Data is shared only with Render and Sentry as described above, solely to operate and maintain the App.
All data is transmitted over HTTPS. The App and its PostgreSQL database are hosted in Render's Frankfurt region. Access to production systems is restricted to authorized personnel. Render provides infrastructure safeguards including encrypted storage and network security for our hosted services. Application logs are retained by Render for up to 7 days. No internet service can guarantee absolute security.
The App responds to the following Shopify privacy compliance webhooks:
shop/redact: triggers deletion of all shop-specific data from our active database, as described in Section 5.customers/data_request: the App does not store customer personal data, so there is no customer data to provide in response to these requests.customers/redact: the App does not store customer personal data, so no customer records are deleted in response to these requests.Merchants may request a description of the data we hold for their store at any time by contacting us at the address below. As noted in Section 5, uninstalling the App initiates permanent deletion of all associated active data.
We may update this policy from time to time. The effective date at the top of this page will reflect the most recent revision. Continued use of the App after an update constitutes acceptance of the revised policy.
Questions about this policy or data handling practices:
support@silvaapps.com