Privacy Policy
Last updated June 6, 2026
The Backroom ("The Backroom," "we," "us") provides product-analytics and inventory-planning tools for independent product and retail businesses. This policy explains what we collect, how we use it, and the choices you have. We aim to collect only what we need to run the service for you, and never to sell your data.
Information we collect
- Account information — your name, email address, and business name when you sign up.
- Shopify store data — when you connect your store, we read (read-only) your orders and sales, products and variants, inventory levels, and store locations through Shopify's Admin API. We use this to build your goals, buy plan, reorder lists, and dead-stock reports.
- Usage & technical data — a secure, essential session cookie to keep you logged in, and basic logs needed to operate and secure the service.
How we use your information
- To provide the dashboard, analytics, forecasting, and recommendations for your business.
- To maintain, secure, and improve the service.
- To communicate with you about your account.
We do not sell your data, and we do not use your store data to advertise to you or others.
How your data is stored & protected
- Your Shopify access token is encrypted at rest (AES-256-GCM); your password is stored only as a salted hash (scrypt) — never in plain text.
- Each business's data is isolated per account (tenant) within the database.
- We use reputable infrastructure providers (hosting and a managed PostgreSQL database) that act as data processors on our behalf and do not use your data for their own purposes.
Data sharing
We share data only with the infrastructure providers needed to run the service, and only as required to provide it. We may disclose information if required by law. We never sell or rent your information.
Retention & deletion
- We keep your data while your account is active.
- If you uninstall the app from Shopify or disconnect your store, we stop syncing and deactivate the connection.
- You can request deletion of your account and associated data at any time by emailing us; we will delete it within a reasonable period, except where retention is required by law.
Your rights
Consistent with Canadian privacy law (PIPEDA) and similar regulations, you may request access to, correction of, or deletion of your personal information. Contact us and we'll help.
Cookies
We use a single essential, httpOnly session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.
Changes to this policy
We may update this policy from time to time. We'll revise the "last updated" date above, and material changes will be communicated where appropriate.
Contact
Questions about your privacy? Email megan@thelocalspace.ca.