Privacy Policy
LastMile Inc. ("we") provides the LastMile app, which shows per-store inventory on a merchant's storefront, offers buy-online-pickup-in-store, sends restock alerts, shows delivery dates and shipping rates, and offers an optional order and fulfillment integration. This policy explains what the app stores, why, who it is shared with, and how long it is kept. For the personal data of a merchant's customers, the merchant decides how it is used and we process it on the merchant's behalf.
Merchant data
The following is merchant business data, obtained from Shopify with the merchant's consent when the app is installed, or entered by the merchant:
- Shop identifiers and settings: the shop domain, shop name, primary locale, currency, time zone and the app plan the shop is on.
- Access credentials: the offline access token issued by Shopify, used only to call the Shopify Admin API on the shop's behalf. The app does not use staff (online) sessions, so it does not store the name or email address of the merchant's staff.
- Store (location) records imported from Shopify, plus details the merchant adds: business hours, phone numbers, photos, access notes, map links, visibility, pickup availability and sort order.
- Inventory quantities per location, cached for a short period (60 to 300 seconds, configurable by the merchant) so product pages stay fast.
- App configuration: display settings, custom CSS, pickup, restock alert and delivery settings, the storefront access token used for pickup availability, subscription records and webhook event IDs used to avoid duplicate processing.
Customer data we process
Restock alerts
Only when a shopper signs up for a restock alert, we store:
- The email address or LINE user ID the shopper chose to be notified at.
- The product and variant, the page the shopper signed up from, the shopper's storefront language, the destination they chose (the online store or a pickup store), and the dates and status of the sign-up, notification and cancellation.
We use this only to send a sign-up confirmation and a notification when the item is back in stock. Emails are delivered through Postmark and LINE messages through the LINE Messaging API (LY Corporation). For email, we keep delivery records (recipient address, delivery status and bounces) so we do not keep sending to addresses that bounce. Link click tracking in these emails is off unless the merchant turns it on.
When a shopper signs up with LINE, a sign-in session that expires after 10 minutes connects their LINE account to the sign-up. If the shopper is logged in to the store, their email address is filled into the form in their browser, but it is not sent to us unless they submit the form. Every notification includes a link to unsubscribe.
Purchases after a restock alert
The product link in a restock alert carries a code that identifies that alert, not the shopper. When a shopper opens the link, a Shopify web pixel saves the code in their browser (local storage and a first-party cookie named lm_rn). If that browser later completes a purchase, the pixel sends us the code with the order ID, the time of the order, the currency, the items bought (variant and quantity) with their prices and discounts, and the order's subtotal, tax, shipping and total.
We use this only to count purchases that followed a restock alert, which is how the LastMile fee for restock alerts is calculated. The pixel does not read the shopper's name, email address, phone number or address, and we do not link the purchase to a customer account. Where consent is required, the pixel runs only after the shopper has consented to analytics.
Order and fulfillment integration
Only when the merchant turns on the order integration and grants access to orders, we receive the shipping details of each order: the recipient's name, phone number, country, prefecture or state, city, postal code and street address, the contact email address for delivery updates (the email on the order, or the customer's email on the order when the order has none), the order number and the items.
These are the shipping details needed to fulfill the order. They are not customer account or membership data, and we do not create customer profiles from them. We use them to decide which location ships the order, to create shipping labels, to send shipping instructions to the merchant's warehouses, to check and correct shipping addresses and, if the merchant turns this on, to send delivery status emails. They are shared only with the carriers and warehouses the merchant uses and, for delivery status emails, Postmark.
Checkout
To calculate shipping rates and delivery dates, Shopify sends us the destination and the items in the cart. To help shoppers in Japan fill in their address, the checkout sends us the postal code, or the prefecture, city and street address being entered, and we look up matching postal codes in a public postal code database. We use this information only to answer the request and do not store it.
Information we do not collect
- No customer accounts or profiles. The app does not store a merchant's customer accounts, order history for marketing, or any customer data beyond what is described above. Requests from the storefront are authenticated by shop, and the customer identifier that Shopify can attach to app proxy requests is not read or retained.
- No advertising or profiling. The app runs no advertising scripts and does not build shopper profiles. The only cookie it sets is the restock alert code described above.
- No payment data. Billing is handled entirely by Shopify; we never receive card or bank details.
Shopper location, maps and browser storage
If a shopper chooses to sort stores by distance, their browser asks for location permission. Those coordinates are sent directly from the shopper's browser to Shopify's Storefront API to order the list of stores; they are not sent to, or stored on, our servers.
If the merchant adds a Google Maps link to a store, the map is loaded from Google when the shopper opens that store's details, and Google's privacy policy applies to that map.
The app saves the following in the shopper's browser (local storage, plus the one cookie described above): the store selected for pickup, a note that the shopper already signed up for a restock alert (removed after 48 hours), a note that the shopper has used LINE sign-up on this device, an unfinished LINE sign-up (removed after 15 minutes), the codes of the last few restock alert links the shopper opened, and a purchase that could not be sent yet (removed once it is sent).
Where data is processed
The app and the LastMile platform run on Fly.io and store data in Supabase-hosted PostgreSQL databases, both in the Tokyo (Japan) region. Access is restricted to the application services. Data is shared with the service providers named in this policy (Shopify, Postmark, LINE, and the carriers and warehouses the merchant uses) only to provide the features described. We do not sell data or share it with third parties for their own purposes.
Retention and deletion
- Cached inventory is short-lived and is replaced or expired automatically.
- When the app is uninstalled, the shop is marked uninstalled immediately and the app stops calling Shopify.
- When Shopify sends the shop data erasure request that follows an uninstall, we permanently delete the shop's restock alerts, store and app settings, address correction records and the app's records for that shop. If the shop has installed the app again by then and is using it, that data is in use and is kept.
- When Shopify sends a customer data erasure request, we delete the restock alerts registered with that customer's email address and the address correction records for the orders named in the request. LINE restock alerts are not linked to a Shopify customer; shoppers can stop them with the unsubscribe link, and the merchant can cancel them.
- Restock alerts are otherwise kept until they are deleted as described above. Unsubscribing stops the alerts and keeps the record as cancelled.
- A purchase that followed a restock alert is held in the app only until it has been passed to the LastMile platform (at most 30 days), where the order ID, item, amount and time are kept as a billing record. Anything still waiting is deleted with the shop data erasure request.
- Order shipping details received through the order integration, and email delivery records, are kept as part of the merchant's fulfillment records under our agreement with the merchant. They are not removed by the erasure requests above.
- When Shopify forwards a customer data request, we provide the merchant, on request, with the restock alerts and order shipping details we hold for that customer.
Merchant rights
A merchant may request a copy or deletion of their shop's data at any time, and may revoke our access at any time by uninstalling the app from the Shopify admin.
Changes
If this policy changes materially, we will update the date above and, where appropriate, notify merchants in the app.
Contact
Questions about this policy can be sent to the support address listed on our Shopify App Store listing.