Privacy Policy

Applies to the Shopify app LastMile. Last updated: September 20, 2026.

LastMile Inc. ("we") provides the LastMile app, which shows per-store inventory on a merchant's storefront, offers buy-online-pickup-in-store, sends restock alerts, shows delivery dates and shipping rates, and offers an optional order and fulfillment integration. This policy explains what the app stores, why, who it is shared with, and how long it is kept. For the personal data of a merchant's customers, the merchant decides how it is used and we process it on the merchant's behalf.

Merchant data

The following is merchant business data, obtained from Shopify with the merchant's consent when the app is installed, or entered by the merchant:

Customer data we process

Restock alerts

Only when a shopper signs up for a restock alert, we store:

We use this only to send a sign-up confirmation and a notification when the item is back in stock. Emails are delivered through Postmark and LINE messages through the LINE Messaging API (LY Corporation). For email, we keep delivery records (recipient address, delivery status and bounces) so we do not keep sending to addresses that bounce. Link click tracking in these emails is off unless the merchant turns it on.

When a shopper signs up with LINE, a sign-in session that expires after 10 minutes connects their LINE account to the sign-up. If the shopper is logged in to the store, their email address is filled into the form in their browser, but it is not sent to us unless they submit the form. Every notification includes a link to unsubscribe.

Purchases after a restock alert

The product link in a restock alert carries a code that identifies that alert, not the shopper. When a shopper opens the link, a Shopify web pixel saves the code in their browser (local storage and a first-party cookie named lm_rn). If that browser later completes a purchase, the pixel sends us the code with the order ID, the time of the order, the currency, the items bought (variant and quantity) with their prices and discounts, and the order's subtotal, tax, shipping and total.

We use this only to count purchases that followed a restock alert, which is how the LastMile fee for restock alerts is calculated. The pixel does not read the shopper's name, email address, phone number or address, and we do not link the purchase to a customer account. Where consent is required, the pixel runs only after the shopper has consented to analytics.

Order and fulfillment integration

Only when the merchant turns on the order integration and grants access to orders, we receive the shipping details of each order: the recipient's name, phone number, country, prefecture or state, city, postal code and street address, the contact email address for delivery updates (the email on the order, or the customer's email on the order when the order has none), the order number and the items.

These are the shipping details needed to fulfill the order. They are not customer account or membership data, and we do not create customer profiles from them. We use them to decide which location ships the order, to create shipping labels, to send shipping instructions to the merchant's warehouses, to check and correct shipping addresses and, if the merchant turns this on, to send delivery status emails. They are shared only with the carriers and warehouses the merchant uses and, for delivery status emails, Postmark.

Checkout

To calculate shipping rates and delivery dates, Shopify sends us the destination and the items in the cart. To help shoppers in Japan fill in their address, the checkout sends us the postal code, or the prefecture, city and street address being entered, and we look up matching postal codes in a public postal code database. We use this information only to answer the request and do not store it.

Information we do not collect

Shopper location, maps and browser storage

If a shopper chooses to sort stores by distance, their browser asks for location permission. Those coordinates are sent directly from the shopper's browser to Shopify's Storefront API to order the list of stores; they are not sent to, or stored on, our servers.

If the merchant adds a Google Maps link to a store, the map is loaded from Google when the shopper opens that store's details, and Google's privacy policy applies to that map.

The app saves the following in the shopper's browser (local storage, plus the one cookie described above): the store selected for pickup, a note that the shopper already signed up for a restock alert (removed after 48 hours), a note that the shopper has used LINE sign-up on this device, an unfinished LINE sign-up (removed after 15 minutes), the codes of the last few restock alert links the shopper opened, and a purchase that could not be sent yet (removed once it is sent).

Where data is processed

The app and the LastMile platform run on Fly.io and store data in Supabase-hosted PostgreSQL databases, both in the Tokyo (Japan) region. Access is restricted to the application services. Data is shared with the service providers named in this policy (Shopify, Postmark, LINE, and the carriers and warehouses the merchant uses) only to provide the features described. We do not sell data or share it with third parties for their own purposes.

Retention and deletion

Merchant rights

A merchant may request a copy or deletion of their shop's data at any time, and may revoke our access at any time by uninstalling the app from the Shopify admin.

Changes

If this policy changes materially, we will update the date above and, where appropriate, notify merchants in the app.

Contact

Questions about this policy can be sent to the support address listed on our Shopify App Store listing.