Privacy policy
Last updated 4 August 2026
Inbound ETA is provided by Fleeta Limited. We process data only to connect inbound stock, preorder capacity, Shopify orders, customer dispatch promises and operational notifications for merchants that install the app.
Data we process
We process the merchant shop domain, encrypted Shopify access sessions, product and inventory identifiers, inbound shipment records, order and line-item identifiers, customer identifiers, and customer email addresses when needed for an enabled service notification. We do not request customer phone numbers, postal addresses, payment card data or marketing-profile data.
Why we process it
We use this data to provide the app, allocate incoming units to orders, prevent overselling, display fulfilment promises, handle delay and cancellation workflows, deliver merchant-authorised service messages, protect the service and meet legal obligations. We do not sell customer data or use it for third-party advertising.
Sharing and international processing
Data is shared only with Shopify, our secured hosting providers and, when a merchant enables live messages, our transactional email provider. Each provider is used only to deliver the service and is subject to appropriate contractual and security controls.
Retention
Active promise records are retained while needed to provide the installed service. Processed webhook payloads are deleted after 30 days. Direct customer identifiers on completed or released allocations and notification content are redacted after 180 days. Shopify customer data requests are completed immediately with a 30-day response deadline, and Shopify redaction requests promptly remove customer identifiers, message content, linked webhook payloads and exports. Security-only audit evidence is retained for up to 24 months after personal content is removed. All shop-scoped data is deleted when Shopify issues a shop-redaction request. Encrypted backups are retained for no more than 30 days.
Security
Data is protected in transit with TLS. Shopify tokens, session payloads and stored customer email addresses are encrypted with authenticated encryption at the application boundary. Access is restricted to authorised personnel, operational access is logged, backups are encrypted, and production data is not copied into local automated tests.
Your choices and rights
Merchants control whether customer messages are enabled. Customers can request a revised promise, fulfilment preference or cancellation through Shopify surfaces provided by the app. Requests to access, correct or delete personal data can be made through the merchant or sent to accounts@fleeta.co.uk.
Contact
Fleeta Limited, United Kingdom. Privacy and security enquiries: accounts@fleeta.co.uk.