Last updated: 2026-08-29
Foreshelf collects the data required for inventory analysis: your Shopify store domain, products, variants, aggregated sales history (order line items: quantity, price, date), inventory levels, batches and expiry dates, and the merchant contact email.
Foreshelf does not collect your end customers' names, addresses or payment details for its inventory analysis.
Shopify may provide limited device and activity data, such as IP address, approximate geolocation, browser and operating system, for authentication, security and service diagnostics. Foreshelf does not use this data for advertising.
Data is used to produce forecasts, alerts, Marcus recommendations, audit logs, inventory reports and maker features such as recipes, raw-material lots and production traceability. It is never sold or shared with third parties for advertising.
Questions asked to Marcus, together with aggregated inventory context, may be processed by an AI provider configured by Foreshelf or by the merchant (bring-your-own-key). Prompts are limited to inventory-relevant data; no end-customer personal data is sent to AI providers.
The mandatory customers/data_request, customers/redact and shop/redact webhooks are implemented. After uninstall, store data is queued for deletion when Shopify's shop/redact request is received and is removed from the service within 48 hours, subject to backups expiring on their normal retention cycle.
All traffic is encrypted in transit (HTTPS). Merchant-provided API keys are encrypted at rest. Access to production data is restricted to the operator of the service.