RefillPilot

Privacy Policy

Last updated: June 25, 2026

RefillPilot is a Shopify app that helps merchants identify customers who may be ready to reorder consumable products. This Privacy Policy explains what information RefillPilot collects, how we use it, and how merchants can contact us about privacy requests.

Information we collect from Shopify

When a merchant installs and uses RefillPilot, the app accesses Shopify data only through the permissions granted by the merchant. RefillPilot currently uses Shopify product and order data to provide its refill opportunity workflow.

  • Product data, such as product and variant identifiers, product titles, variant titles, SKUs, vendors, product types, prices, and currency codes.
  • Order data, such as order identifiers, order names, processed dates, line item identifiers, purchased products, variants, SKUs, quantities, and item prices.
  • Customer-related order data, such as a Shopify customer identifier and customer email address when Shopify provides it and the merchant has granted the required access.
  • Store and app installation data, such as shop domain, app session records, installation status, app settings, sync status, and webhook processing records.

RefillPilot does not request customer addresses or phone numbers for its first release.

Information merchants provide in the app

Merchants may configure refill products, expected reorder cycles, reminder lead windows, overdue grace windows, export preferences, and other app settings. If a merchant contacts us for support, we may collect the information included in that support request.

How we use information

RefillPilot uses collected information to:

  • sync selected products and recent order activity;
  • estimate when a customer may be ready to reorder a consumable product;
  • create merchant-facing dashboards, reorder opportunity lists, and action queues;
  • generate CSV exports when a merchant chooses to download them;
  • operate, secure, troubleshoot, and improve the app; and
  • respond to support, privacy, and compliance requests.

RefillPilot does not automatically send marketing messages, create subscription contracts, create automatic subscription orders, charge customers, or sell customer data.

Customer email handling and CSV exports

RefillPilot uses customer email addresses only when they are needed to connect order history with merchant follow-up workflows. The app stores a hashed email value for matching and may store an encrypted email value when CSV exports are enabled. Customer labels shown in the app are masked where possible.

CSV exports are generated only when a merchant requests a download. Exported files may include customer email addresses if Shopify provided them, the merchant has the necessary access, and the merchant has enabled email export behavior.

Cookies and tracking

RefillPilot is an embedded Shopify app. We do not place tracking cookies on shoppers' devices, and we do not track shoppers across stores. The app may use technical cookies or session mechanisms that are necessary for authentication, security, and normal app operation.

How we share information

We do not sell personal information. We may share information only with service providers that help us host, operate, secure, or support RefillPilot; with Shopify as required to operate the app; or when required to comply with applicable law, legal process, or enforceable government requests.

Data retention and deletion

RefillPilot retains app data for as long as needed to provide the app to the merchant, comply with legal obligations, resolve disputes, and maintain security. When Shopify sends mandatory privacy webhooks, RefillPilot processes them to support customer redaction and shop data deletion. The app is designed to handle those webhook requests idempotently.

Security

We use technical and organizational safeguards designed to protect app data, including access controls, encrypted handling of customer emails where retained for export, and minimized logging of personal data. No system can guarantee absolute security, but we work to limit collection and retention to what the app needs.

Merchant and customer requests

Merchants can contact us to ask questions about this Privacy Policy or request help with access, deletion, or other privacy-related requests. Shopify may also send privacy webhook requests directly to RefillPilot, including customer data requests, customer redaction requests, and shop redaction requests.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the date at the top of this page.

Contact

For privacy questions or requests, contact RefillPilot at madelynhunter1727@hotmail.com.