This policy explains what information Zelari ("we," "us") collects when you visit zelari.io and when you use the Zelari app for Shopify, why we collect it, and what you can do about it. Questions are welcome through our Contact Us page.
1. Who this applies to
This policy covers visitors to our website, merchants who install or use Zelari in Shopify Admin, and anyone who emails us.
2. Our website (zelari.io)
Contact form. If you send us a message through our contact form, we collect your first name, last name, email address, subject, and message. We use them only to reply to you, and we don't add you to any mailing list. The message is delivered to our inbox by our email provider, Resend.
Analytics. To understand how people use the site, we run our own simple analytics. When you visit, we record:
- A random ID that lasts only for your current visit. It is kept in your browser's session storage, cleared when you close the tab, and does not identify you by name.
- Pages and sections viewed, buttons clicked, how far you scroll, and how long you stay
- The site that referred you and any campaign tags in the link (UTM parameters)
- Whether you are on a mobile or desktop device
- Your approximate location (country, region, and city), worked out by our hosting provider from your IP address. We do not store your IP address in our analytics.
We do not use advertising cookies or third-party tracking scripts, and we do not sell or share this information for advertising. Because the ID lasts only for one visit, we can't recognize you when you come back.
Like most websites, our hosting provider (Vercel) keeps standard server logs (such as IP address, browser type, and request time) for security and operations. Our fonts load from Google Fonts, which means Google receives your IP address when the page loads.
If you joined our earlier waitlist (before September 2026), we keep that email address only to contact you about Zelari. You can ask us to delete it at any time.
3. The Zelari app: what we collect
When you install Zelari, we access your store's data through Shopify's APIs and webhooks, limited to the permissions you approve at install. We store:
- Store details and settings: shop domain, plan, time zone, and the settings you choose (such as low-stock threshold and reorder lead time)
- Catalog and inventory: products, variants, locations, and stock quantities
- Inventory history: every stock change we receive and what triggered it
- Order data used for sales math: up to 90 days of orders imported at install, including order IDs, dates, products, quantities, and the numeric Shopify customer ID attached to an order. We do not store customer names, email addresses, phone numbers, or shipping addresses.
- Results we calculate: sales velocity benchmarks, detected anomalies, and AI explanations
- Your activity in Zelari: for example, when you acknowledge, confirm, or dismiss an anomaly
- Email alert settings: the alert email address you enter in Settings and which emails you want to receive
- Billing status: your plan and subscription status from Shopify. Payments are handled by Shopify. We never see your card details.
We do not sell your store's data.
4. How we use information
- To detect inventory anomalies using rules and math
- To write plain-English explanations for anomalies our rules have flagged
- To calculate inventory metrics such as velocity, days on hand, and reorder points
- To send the alert and digest emails you turn on
- To reply to messages you send us
- To run, secure, support, and improve Zelari
- To understand how visitors use our website
- To meet legal obligations and enforce our Terms
5. Service providers
We use a small number of providers to run Zelari. They process data on our instructions and under their own security and privacy terms.
- Shopify: platform, sign-in, billing, and the source of your store data
- Supabase: application database
- Vercel: hosting for the app and website
- Inngest: background jobs, such as running anomaly detection
- Anthropic: AI that writes anomaly explanations
- Resend: delivery of alert and weekly digest emails, and of messages sent through our contact form
- Google Fonts: website fonts
6. How we use AI
Anomalies are detected by fixed rules and statistics, not by AI. AI is only used to explain an anomaly after our rules have flagged it. For that, we send Anthropic the details needed to explain the event, such as product and variant names, stock levels, sales figures, and which rules fired. We do not send customer personal information. Under Anthropic's commercial terms, this content is not used to train their models. AI never changes your inventory or makes decisions for you.
7. Emails from the app
If you turn them on in Settings, Zelari sends instant emails for high and critical anomalies and a weekly digest. You can turn either off at any time in Settings.
8. How long we keep data
We keep store and inventory data while Zelari is installed, and as needed for the history features of your plan. If you uninstall Zelari, we stop collecting data and deactivate your store in our systems. You can ask us to delete your store's data at any time through our Contact Us page, and we will confirm once it is done. When Shopify tells us a customer has asked to be forgotten, we remove that customer's ID from our records. Some logs may be kept longer when needed for security or legal reasons.
9. Security
We use encrypted connections, access controls, and server-side-only access to our production database. No system is perfectly secure, but we work to protect the data we hold in proportion to its sensitivity. If an incident happens, we follow our Security Incident Response Policy. Merchants can also read our Data Processing Agreement.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, or to object to certain uses of it. Send your request through our Contact Us page and we will respond. If you shop at a store that uses Zelari, please contact that store first. We process store data on the merchant's behalf.
11. International transfers
We and our providers may process data in the United States and other countries. When data moves across borders, we rely on our providers' standard safeguards.
12. Children
Zelari is a business tool for merchants and is not directed at children under 16.
13. Changes to this policy
When we update this policy, we change the version number and date at the top, add a line to the version history below, and keep every previous version available on our Documents page. We may also tell merchants about important changes in the app or by email.
14. Contact
Version history
| Version | Effective | Summary |
|---|---|---|
| 2.0 Current | September 27, 2026 | Removed beta and waitlist references. Added the contact form, website analytics, order data, AI, email alerts, new providers, and links to our DPA and incident policy. |
| 1.0 Archived | June 5, 2026 | Initial version. |