Replenora Privacy Policy
Effective date: 2026-07-21
Replenora is a purchase-order and replenishment app for Shopify, operated by HJB CodeForge, a sole proprietorship based in Ottawa, Canada (“we”, “us”). This policy explains exactly what data the app touches, what it stores, and what happens to that data when you leave. It is written to be read, not skimmed past.
What we store
When you use Replenora, we store the following on our servers:
- Suppliers you create — names, contact email and phone, currency, lead times, and notes.
- Purchase orders and their line items — quantities, costs, statuses, freight/duty/other costs, and related notes.
- Receiving records — what was received, when, at which location, and the sync state of each inventory write.
- Aggregate per-variant sales statistics — units sold per product variant over the standard 60-day order window, used to compute sales velocity for the replenishment report. These are aggregate counts only.
- App settings and session data — your per-shop preferences (such as your last receiving location) and the Shopify session needed to run the app.
We never read or store your customers’ names, email addresses, phone numbers, or shipping addresses. When we read orders to compute sales velocity, we use only line items, dates, and quantities; the customer object is never requested and never persisted.
What we access from Shopify
Replenora requests the minimum Shopify permissions it needs to work:
- Products and locations (read) — to link purchase order lines to your catalog and receive stock at the right location.
- Inventory (write) — to update inventory quantities when you receive a purchase order, track incoming stock, and optionally write landed unit costs. Every inventory change is made at your direction and is audit-trailed in the app.
- Orders (read, standard 60-day window) — to compute per-variant sales velocity for the replenishment report. Replenora operates at protected customer data Level 1 only, for the purpose of store management, and does not request access to customer-identifiable fields.
When you choose to email a purchase order to a supplier, we send that email through Resend, our email delivery provider. The email contains the purchase order you chose to send and goes to the supplier email address you entered. We do not send marketing email through the app, and we never email your customers.
Where data lives and who can see it
App data is hosted on Fly.io infrastructure. We do not sell, rent, or share your data with anyone. The only third parties that process data on our behalf are our hosting provider (Fly.io) and our email delivery provider (Resend, only when you send a purchase order email).
Cookies and tracking
Replenora uses Shopify session tokens to keep you signed in inside the Shopify admin. We do not use advertising or cross-site tracking cookies.
Data deletion
When you uninstall Replenora, Shopify sends us a mandatory deletion request (shop/redact), and we permanently delete all data we hold for your store — suppliers, purchase orders, receipts, sales statistics, settings, and sessions. We also honor Shopify’s customer data request and customer redaction webhooks; because we store no customer-identifiable data, there is nothing to hand over or redact, and we confirm each request accordingly.
Changes to this policy
If we change this policy, we will update this page and the effective date above. Material changes will be called out in the app.
Contact
Questions about privacy or data handling: support@hjbcodeforge.com.
HJB CodeForge (sole proprietorship)
Ottawa, Canada