Skip to main content

Privacy Policy

Last updated: August 12, 2026

This Privacy Policy explains how Fermyon Inc. (doing business as Link!, LinkToAny, and ShoppinPal) ("LinkToAny", "we", "us", or "our") collects, uses, stores, shares, and protects information in connection with the GoStock inventory management application for Shopify, together with any related extensions, point-of-sale components, documentation, and services we provide (collectively, the "App").

This policy applies to the merchants and authorized users who install and use the App ("you", "your", or the "Merchant"). It should be read together with our End-User License Agreement. By installing, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy.


1. Who We Are

The App is provided by LinkToAny. If you have any questions about this policy or how we handle data, contact us at gostock@linktoany.com.

For data we process on your behalf, you are the controller of the underlying business and personal data, and we act as your processor/service provider. For account and billing information about you as our customer, we act as a controller.

2. Information We Collect

We collect the following categories of information:

  • Account and installation information. When you install the App, we receive your Shopify store domain, store and account identifiers, the email associated with your store, and the access tokens Shopify issues so the App can operate on your behalf.
  • Merchant business data. To provide inventory management, the App reads from and writes to your Shopify store and stores operational data, including products, variants, SKUs, barcodes, costs, prices, vendors and suppliers, locations, inventory levels and movements, purchase orders, transfers, receiving records, stocktakes, replenishment rules, and reports.
  • Order and customer-adjacent data. To compute sales velocity, demand forecasts, and reporting, the App processes order and line-item data from Shopify. This may include limited customer-associated fields present on orders. We do not use this data for advertising and do not sell it.
  • Connected third-party data. If you connect an integration such as QuickBooks Online, we access data from that service as described in Section 7.
  • Usage and diagnostic data. We collect log data, error reports, device/browser information, and product-usage events to operate, secure, debug, and improve the App.
  • Communications. If you contact support, we retain your messages and related metadata to respond and improve our service.

We do not intentionally collect government IDs, full payment card numbers, or special categories of personal data. Billing is handled by Shopify (see Section 6); we do not receive or store your card details.

3. How We Use Information

We use the information described above to:

  • provide, operate, maintain, and secure the App and its features;
  • sync inventory bi-directionally with Shopify and keep records consistent;
  • generate reports, forecasts, replenishment suggestions, and analytics for your store;
  • process integrations you enable (for example, exporting purchase orders and bills to QuickBooks Online);
  • provide customer support and respond to your requests;
  • monitor performance, diagnose and fix problems, and prevent fraud and abuse;
  • comply with legal obligations and enforce our agreements.

We do not sell your data, and we do not use your Merchant Data or connected third-party data to serve advertising.

Where the GDPR or similar laws apply, we process personal data on the following bases: performance of our contract with you (to provide the App); our legitimate interests (to secure, maintain, and improve the App and prevent abuse); your consent (where required, for example when you connect an optional integration); and compliance with legal obligations.

5. How We Share Information

We share information only as needed to operate the App:

  • Shopify. The App runs on and integrates with Shopify. Data flows to and from Shopify through its APIs under your Shopify relationship.
  • Sub-processors and infrastructure providers. We use service providers for cloud hosting, databases, queuing, object storage, error tracking, product analytics, transactional email, and AI-assisted features to run the App. They process data only on our instructions and under confidentiality and data-protection obligations. The current list is set out in Annex A — Sub-processors below.
  • Integrations you enable. When you connect a third-party service such as QuickBooks Online, data is exchanged with that service at your direction (see Section 7).
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of LinkToAny, our users, or the public.
  • Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

Our commitments as a service provider. For personal information we process on your behalf, we commit that we will not: sell or share it; retain, use, or disclose it for any purpose other than providing the App to you, including outside our direct business relationship with you; or combine it with personal information we receive from any other source, except as permitted by applicable law to perform a business purpose. We do not share personal information for cross-context behavioral advertising, and we do not use Merchant Data to train AI models. We impose equivalent obligations on our sub-processors by written contract, and we will tell you if we determine we can no longer meet these obligations.

6. Billing

Subscriptions and fees for the App are billed through Shopify's billing system and appear on your Shopify invoice. We do not collect or store your payment card information; payment processing is handled by Shopify under Shopify's terms and privacy practices.

7. QuickBooks Online (Intuit) Data

If you choose to connect QuickBooks Online, you authorize the App to access your QuickBooks company data through Intuit's OAuth 2.0 authorization flow. This section describes how we handle that data.

  • What we access. We request the accounting scope (com.intuit.quickbooks.accounting) needed to create and reconcile records such as vendors/suppliers, bills, and bill payments that correspond to your purchase orders in the App. We access only the QuickBooks data necessary for these features.
  • Authorization and tokens. We do not receive or store your Intuit username or password. We store the OAuth access token, refresh token, and your QuickBooks company (realm) identifier so the App can maintain the connection you authorized. Tokens are stored securely and used solely to perform the actions you initiate.
  • How we use it. QuickBooks data is used only to provide the accounting-sync features you enable — for example, pushing a purchase order to QuickBooks as a bill, recording payments, and mapping vendors. We do not use QuickBooks data for advertising, and we do not sell it.
  • How we protect it. QuickBooks data and tokens are protected using the security measures described in Section 9, including encryption in transit and access controls.
  • Disconnecting. You can disconnect QuickBooks at any time from the App's Settings. On disconnect, we make a best-effort call to revoke the OAuth token with Intuit, delete the stored access and refresh tokens from our database, and mark the connection inactive so the App no longer accesses your QuickBooks data.
  • Deletion. Following disconnection, App uninstallation, or your request, stored QuickBooks tokens and connection records are deleted or anonymized in accordance with Section 10.

Your use of QuickBooks Online is also governed by Intuit's own terms and privacy policy. We are not responsible for Intuit's practices.

8. Data Location and International Transfers

Where your data is stored. Merchant Data is hosted in the United States, in the San Francisco (SFO3) region of our cloud infrastructure provider, and is stored at rest in that region. The sub-processors listed in Annex A are United States–based, except where noted.

Cross-border access. Our engineering and support personnel — including team members located in India — may access Merchant Data remotely in order to operate, support, and troubleshoot the App. Such access is made through authenticated, access-controlled channels into the hosted environment described above; it does not change where your data is stored.

Where personal data is transferred across borders, we rely on appropriate safeguards as required by applicable law. If you require a data-processing agreement or specific transfer terms, contact us at gostock@linktoany.com.

9. Data Security

We use technical and organizational measures designed to protect information, including encryption of data in transit (HTTPS/TLS), encryption at rest provided by our infrastructure provider, access controls and tenant isolation so each store's data is segregated, secure secret and token storage, and monitoring and error tracking. These measures are described in more detail in Annex B — Technical and Organizational Measures.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security; you are responsible for keeping your Shopify and integration credentials secure.

If there is a security incident. If we become aware of a breach of our security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Merchant Data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. Our notice will describe, to the extent known at the time, the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the steps we have taken or propose to take. We will provide reasonable cooperation to help you meet your own notification obligations. Unsuccessful attempts and routine events that do not compromise Merchant Data are not security incidents. Notifying you is not an admission of fault or liability.

Demonstrating compliance. On reasonable written request, we will make available information reasonably necessary to demonstrate our compliance with this policy — for example a completed security questionnaire or a summary of our controls.

10. Data Retention and Deletion

We retain information for as long as your installation is active and as needed to provide the App, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Shopify data-protection webhooks. We support Shopify's mandatory data-protection webhooks for customer data requests, customer redaction, and shop redaction, and process each as a live code path rather than an acknowledgement only.
  • Shop redaction — deleted within 30 days. When Shopify sends a shop-redaction request, we mark your shop for deletion and permanently delete your Merchant Data within 30 days. The deletion is a hard delete (not an archive or a flag) executed as a single database transaction scoped to your store, and it covers purchase orders, receiving records and goods-receipt notes, transfers, stocktakes, inventory records and the full inventory-movement ledger, products, suppliers, locations, replenishment rules and suggestions, import and sync records, AI usage and conversation records, staff records, audit and error logs, and any stored QuickBooks tokens and connection records.
  • Customer redaction. When Shopify sends a customer-redaction request, we remove or de-identify the corresponding customer-associated fields we hold for that store.
  • Deletion certification. On written request, we will confirm in writing that deletion has been completed.
  • Getting your data out. While your installation is active you can export your operational data from within the App (for example inventory, purchase order, and report exports). If you need an export at or after termination, contact us within 30 days of termination and we will provide your data in a commercially reasonable format.
  • Backups and logs. Residual copies may persist in encrypted backups and in operational logs after deletion from our active systems, and are removed in the ordinary course of backup rotation. Backups and logs are used only for disaster recovery, security, and debugging.

11. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at gostock@linktoany.com. We will respond as required by applicable law. You may also have the right to lodge a complaint with your local data-protection authority.

For personal data we process on your behalf as a processor, we will direct requests we receive to you and assist you in responding as required.

12. Children's Privacy

The App is a business tool intended for use by merchants and is not directed to children. We do not knowingly collect personal information from children under the age of 16.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide notice within the App or by other reasonable means. Your continued use of the App after changes take effect constitutes acceptance of the revised policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Fermyon Inc. (DBA LinkToAny) Email: gostock@linktoany.com


Annex A — Sub-processors

This Annex lists the third parties we engage to process data on our behalf in order to provide the App, as referenced in Section 5. Each is bound by confidentiality and data-protection obligations no less protective than those in this policy, and processes data only on our instructions.

We may add or replace a sub-processor as the App evolves. When we do, we will update this Annex and the "Last updated" date above before the new sub-processor begins processing Merchant Data. Before engaging any sub-processor we carry out due diligence and put a written contract in place imposing data-protection obligations no less protective than those in this policy, and we remain responsible for their performance.

If you would like advance notice of sub-processor changes, or wish to raise a data-protection objection to a particular sub-processor, contact us at gostock@linktoany.com and we will work with you in good faith.

Sub-processorService / PurposeLocation
Shopify Inc.The platform the App runs on. Store, product, inventory, location, and order data flows to and from Shopify through its APIs under your Shopify relationship.Canada / United States
DigitalOcean, LLCCloud hosting (managed Kubernetes), the managed PostgreSQL database in which Merchant Data is stored, and object storage (Spaces) for file attachments and report exports.United States (SFO3, San Francisco)
Amazon Web Services, Inc.Message queuing for background jobs (SQS), container image hosting (ECR), and email delivery (SES) where used as a fallback to our primary email provider.United States (us-west-2, Oregon)
PostHog, Inc.Product analytics and usage instrumentation, including page views, feature-usage events, and session recording of App screens, used to understand how merchants use the App and to diagnose problems. In session recordings, the contents of everything you type are masked by default; only a small set of explicitly allowlisted fields (such as search boxes) is recorded in readable form, and password fields are never recorded. Identified by store domain, not by named individuals.United States
Sentry (Functional Software, Inc.)Application error reporting and performance monitoring, including stack traces and request context.United States
ResendOur primary transactional email provider — for example, purchase orders emailed to your suppliers and scheduled report digests.United States
Slack Technologies, LLCReceives internal operational notifications about App events, which identify your store by domain and name. Used by our team to monitor and support the App; no customer-associated order data is sent.United States
Anthropic PBCAI-assisted features (the in-app assistant and CSV/data interpretation). Only the data needed to answer a given request is sent, and it is not used to train models.United States
Google LLC (Google Workspace)Business email and document handling for support correspondence.United States
GitLab Inc.Source control and CI/CD for the App. Does not receive Merchant Data in the ordinary course.United States

Integrations you enable are not sub-processors. Third-party services that you choose to connect — for example QuickBooks Online (Intuit Inc.), label printers, or other tools — are independent recipients determined by you, not our sub-processors. Data is exchanged with them at your direction, under their own terms and privacy policies. See Section 7 and Section 5.


Annex B — Technical and Organizational Measures

These are the measures we maintain to protect Merchant Data, as referenced in Section 9. We may update them provided the overall level of protection is not materially reduced.

AreaMeasures
Tenant isolationThe App is multi-tenant. Every record belonging to your store carries your store identifier, and every query, guard, and deletion path is scoped by it, so one store's data cannot be read alongside another's.
Access controlRole-based access and least-privilege provisioning for production systems; authentication of App requests via Shopify-issued session tokens; access limited to personnel who require it to operate or support the App.
EncryptionEncryption in transit via HTTPS/TLS, with certificates managed and rotated automatically. Encryption at rest for the managed database and storage volumes, provided by our infrastructure provider.
Secrets handlingCredentials, API keys, and Shopify and QuickBooks tokens are held in managed secret storage, not in source code, and are not exposed to the browser.
Network and infrastructureThe App runs on managed Kubernetes behind a reverse proxy and ingress controller. The production database is not publicly exposed and is reachable only from within the private network.
Monitoring and error trackingApplication errors and performance are monitored continuously, with centralized logging and metrics for the production environment.
ResilienceManaged database backups on the provider's rolling cycle; queue-based background processing so transient failures are retried rather than lost; append-only inventory ledger so stock history can be reconstructed.
OrganizationalConfidentiality obligations for personnel; code review on changes to the App; automated checks in the build pipeline before changes reach production.

This Privacy Policy should be read together with the End-User License Agreement.