TransferWatch privacy policy
TransferWatch is provided by Craig Stables, a Spanish sole trader trading as Calm Utility, at Calle Alejandro Dumas, 17 – Oficinas, 29004 Málaga, Spain. Contact us at privacy@calmutility.com about privacy or support@calmutility.com for app support.
TransferWatch reads native Shopify inventory-transfer and shipment information to identify operational exceptions. It processes your shop domain, authentication/session information, transfer identifiers, names and statuses, shipment quantities, observed timing and state, exception history, settings and an optional digest recipient address. Shopify's session adapter may retain store-user identity fields associated with authentication. Merchants control transfer names and other source values, so those values may contain personal information.
For merchant-directed inventory monitoring, we process store information on the merchant’s instructions. For our own account, support and security administration, Calm Utility determines the purposes of processing. The bases for that administration are performing the service contract where applicable and legitimate interests in securely operating and supporting the service; statutory obligations apply where required. Optional digest settings control sending and do not authorise marketing. Enabling a digest does not resolve every data-protection obligation.
The app uses this information to authenticate your store, monitor transfers, display exceptions and send notifications you enable. It does not create transfers, move stock, receive shipments, forecast inventory demand or create purchase orders. It does not intentionally request customer or order records, sell merchant data, or use merchant data for advertising. Tracking numbers and URLs are read when needed to evaluate tracking exceptions but are not retained in new monitoring snapshots.
Email digests are optional and can be switched off in Settings. If enabled, Resend processes the recipient address and email content, including transfer references. Email delivery may fail, and provider acceptance does not guarantee receipt or inbox placement. Disabling the digest stops future scheduled digests; it does not recall an email already delivered or queued with the provider.
Railway hosts the application and database in EU West. Resend provides optional email delivery, and its configured sending infrastructure uses Ireland. Cloudflare R2 stores encrypted service-recovery backups in a bucket restricted to the European Union. These providers may involve international processing. We do not claim that all processing remains within the EU or that regional hosting or encryption eliminates international processing. Contact privacy@calmutility.com for information about safeguards applicable to your data.
Encrypted backups created before the provider change remain in Backblaze B2 in US East until their existing retention lifecycle completes. New backups are stored in Cloudflare R2.
Relevant exception records remain available while monitoring continues. Resolved issues are pruned after 90 days and stored digest records after 30 days when the worker runs. Uninstall/redaction handling removes app-local records after confirming the installation is inactive; verification failures are retried. Shopify inventory records remain in Shopify. Encrypted backups are maintained for service recovery, and isolated restoration has been tested. The configured lifecycle expires recovery snapshots after 15 days, subject to provider processing. Independent erasure instructions are retained separately under the recovery safeguards described below.
Before any restored database is used, later erasure instructions must be reconciled and recovered sessions must not be reused without the recovery procedure. Authenticated pseudonymous erasure instructions are held independently, with at least 30 days retention and longer while an affected backup remains recoverable. A complete fresh inventory is required before expiry. Missing or unreconciled evidence blocks recovery.
Contact privacy@calmutility.com to request access, correction or deletion relating to your store. We verify your authority before disclosing store information. Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may complain to a competent supervisory authority, including Spain’s Agencia Española de Protección de Datos (AEPD). Where we process information for a merchant, we assist that merchant with the request. We aim to respond within the applicable legal time limit. Data necessary for a legal obligation or legal claim may be retained only for that purpose and applicable period. Never send passwords, access tokens or authentication codes to support.