Privacy Policy
LastMile Inc. ("we") provides the LastMile BOPIS & Stock app, which shows per-store inventory on a merchant's storefront and offers buy-online-pickup-in-store. This policy explains what the app stores, why, and how it is deleted.
Information we store
All of the following is merchant business data, obtained from Shopify with the merchant's consent when the app is installed:
- Shop identifiers and settings: the shop domain, shop name, primary locale, currency, time zone and the app plan the shop is on.
- Access credentials: the offline access token issued by Shopify, used only to call the Shopify Admin API on the shop's behalf.
- Store (location) records imported from Shopify, plus details the merchant adds in the app: business hours, phone numbers, photos, access notes, visibility and sort order.
- Inventory quantities per location, cached for a short period (60 to 300 seconds, configurable by the merchant) so product pages stay fast.
- App configuration: display settings, custom CSS, pickup settings, the storefront access token used for pickup availability, subscription records and webhook event IDs used to avoid duplicate processing.
Information we do not collect
- No shopper personal data. The app does not store names, email addresses, phone numbers, addresses or order history of a merchant's customers. Requests from the storefront are authenticated by shop, and the customer identifier that Shopify can attach to app proxy requests is not read or retained.
- No tracking. The app sets no cookies, runs no analytics or advertising scripts on the storefront, and does not build shopper profiles.
- No payment data. Billing is handled entirely by Shopify; we never receive card or bank details.
Shopper location and browser storage
If a shopper chooses to sort stores by distance, their browser asks for location permission. Those coordinates are sent directly from the shopper's browser to Shopify's Storefront API to order the list of stores; they are not sent to, or stored on, our servers. When a shopper picks a store for pickup, only the selected store's ID is saved in that browser's local storage so the choice is remembered.
Where data is processed
The app runs on Fly.io and stores data in a Supabase-hosted PostgreSQL database, both in the Tokyo (Japan) region. Access is restricted to the application services. We do not sell data or share it with third parties for their own purposes.
Retention and deletion
- Cached inventory is short-lived and is replaced or expired automatically.
- When the app is uninstalled, the shop is marked uninstalled immediately and the app stops calling Shopify.
- When Shopify sends the shop data erasure request that follows an uninstall, all records belonging to that shop are permanently deleted.
- Because no customer personal data is held, requests for customer data or customer erasure are answered with confirmation that we hold none.
Merchant rights
A merchant may request a copy or deletion of their shop's data at any time, and may revoke our access at any time by uninstalling the app from the Shopify admin.
Changes
If this policy changes materially, we will update the date above and, where appropriate, notify merchants in the app.
Contact
Questions about this policy can be sent to the support address listed on our Shopify App Store listing.