TELCOMA Global / Tallyo / Privacy policy
What the app reads, what it keeps, and what it never does.
This policy describes what Tallyo does with your data.
1
What the app is
Tallyo: Stocktake & Counts ("the app") is a Shopify App Store app that runs inside the Shopify admin. It records the on-hand quantity of every tracked item at one of your locations, lets your staff count the physical stock by barcode or by hand, shows every difference for review, writes the accepted differences back to Shopify, and can roll a count back. Shopify does not host apps, so the app runs on a server operated by TELCOMA Technologies Private Limited ("we", "us").
2
What the app asks Shopify for
At installation Shopify shows the three permissions the app requests. They are the only access it has:
- Products (read_products): product and variant titles, SKUs, barcodes, product images and the unit cost recorded on each variant, to build the list of items to count.
- Locations (read_locations): the names of your active locations, so you can choose the one being counted.
- Inventory (write_inventory): reading on-hand quantities, and setting them from the reviewed count when you click Apply. This is the only permission that changes anything in your store.
The app does not request, and therefore cannot read, customers, orders, draft orders, checkouts, discounts, staff accounts, payouts or any other part of your store. It requests no access to your storefront and injects nothing into your theme.
3
What the app stores
The app keeps the following on its server, for your store only:
- Your store's identity: its .myshopify.com domain and the store-level API access token Shopify issues at installation, which the app needs to act for your store. The token belongs to the store, not to a person.
- Each count: its name, the optional note, the product filter text, the location's id and name, its status and timestamps.
- Each item in a count: Shopify's ids for the product, variant and inventory item; the product and variant titles; SKU; barcode; the product image URL; the unit cost and currency if one is recorded in Shopify; the expected quantity (on hand when the count started) and the counted quantity.
- Each entry: the quantity, whether it added to or replaced the running count, whether it came from a scan or was typed, the time, and the optional counter tag.
- On the Standard plan: the id and name of the one location the plan covers.
- Each adjustment written to Shopify: the quantity before, the quantity after, when it was written, and whether and when it was rolled back. The app also keeps a record of each batch it sends to Shopify, so an interrupted apply can be completed without writing anything twice.
Whether your store has an active plan is read from Shopify when the app loads and kept in memory for one minute; it is not written to the database. Only the Standard plan's licensed location above is.
4
What the app never stores
- Customer data. None. The app has no permission to read customers or orders, and no field in its database could hold them.
- Staff identities. The app signs in at the store level. It does not use per-person logins, so it does not use or store the Shopify account id, name or email of whoever is using it.
- Sales, prices or order history. The app reads quantities, not transactions.
About the counter tag. On the counting screen a person can type a short tag such as "Aisle 3" or "Till 2" so entries can be traced to a shelf or station. The tag is free text chosen by you. The app asks for a zone or station name rather than a person's name, and it is saved in the browser of the device that typed it and attached to that device's entries. If you type a person's name, it is stored with those entries as typed, until your store's data is deleted under section 8. You control what goes in it.
5
Where the data is
The app and its database run on Fly.io, on a single server in Fly's Ashburn, Virginia region in the United States. The database lives on a persistent volume attached to that server. Fly.io creates volumes with encryption at rest enabled by default and takes daily snapshots of them, which it keeps for five days. All traffic between your browser, the app and Shopify is encrypted with TLS.
Your data leaves that server only to go to Shopify's own systems, when the app reads your products and quantities or writes an adjustment through Shopify's Admin API.
6
Who else handles it
There is no one else. The app uses no analytics service, advertising network, error-tracking service or email tool that receives your data, and it makes no network requests other than to Shopify.
7
What the app does not do
- It does not change any quantity in Shopify until you click Apply, and then only for the items you reviewed. Counting, reviewing and cancelling are read-only.
- It does not set uncounted items to zero.
- It does not use your data for anything other than running the app for your store and answering your support requests.
- It does not sell, rent, share or transmit your data to any third party, and does not use it to train models.
- It does not email you. Billing emails come from Shopify; anything else comes only in reply to a message you sent us.
8
Retention and deletion
Everything in section 3 is kept for as long as the app is installed, so that counts, their audit trail and the ability to roll back stay available to you.
- When you uninstall, Shopify notifies the app and it deletes every row it holds for your store, including the access token, at once. Shopify sends a second, mandatory deletion request 48 hours after uninstallation; the app honours it the same way, and in any case within 30 days.
- On request, email support@telcomaglobal.com from an address at your store and we will delete your store's data, or send you a copy of it, within 30 days.
- Backups: Fly.io's daily snapshots of the volume are kept for five days, so deleted data can remain in a snapshot for up to five days after deletion, after which it is gone.
- Shopify's own privacy webhooks for customer data requests and customer data erasure are implemented and acknowledged. Because the app holds no customer data, there is never anything to return or erase.
Quantities you applied in Shopify remain in Shopify; they are your inventory, not the app's data. Support emails stay in our support mailbox.
9
Legal basis and roles
You (the merchant) are the controller of the data in your store. TELCOMA Technologies Private Limited is a processor acting on your instructions, which consist of installing the app, starting counts and applying them. Where the GDPR or the UK GDPR applies, the processing is performed on your instructions as described on this page; a data processing agreement on these terms is available on request. Because the app holds no customer data and no staff identities, the only personal data it could hold is a name typed into the counter tag, which section 4 explains how to avoid.
10
Security
- The app is served over HTTPS only, and every request from the admin carries a Shopify session token that the app verifies before doing anything.
- Every database query is scoped to the store making the request; one store cannot reach another store's counts.
- Webhooks from Shopify are verified with Shopify's signature before they are acted on.
- Every write to Shopify is a compare-and-set: it names the quantity it expects to replace, and Shopify refuses it if the quantity has changed. Each write is recorded with the value it replaced.
- Credentials for Shopify and Fly.io are held in Fly's secret store, not in the code. Access to the server and database is limited to the TELCOMA staff who operate the app.
Security issues may be reported to support@telcomaglobal.com; please do not post them publicly.
11
Support and contact
support@telcomaglobal.com — we respond within one business day (Monday to Friday, 09:00–18:00 IST). See the support page and the merchant guide. Postal address: TELCOMA Technologies Private Limited, SCO 124, 4th Floor, Feroze Gandhi Market, Ludhiana, Punjab 141001, India.
12
Changes
We will update this policy when the app's data handling changes and note the new effective date above. A change that widens what the app reads or stores would also appear as a new permission request from Shopify, which you would have to approve.