Paienta

Terms of Service

Paienta — provided by Nurdan Ozturk trading as Paienta (ABN 86 372 519 314), 8 Braemar Avenue, Auburn NSW 2144, Australia ("we", "us", "our").

Effective 10 August 2026.

These terms are a contract between us and the business that installs the app ("you"). You accept them by installing Paienta on your Shopify store. If you are accepting on behalf of a company, you confirm you are authorised to do so. If you do not accept them, uninstall the app.

Our Privacy Policy forms part of these terms. Schedule 1 sets out the data processing terms required by data protection law; it is part of this contract, so no separate agreement needs to be signed.


1. What the app does

Paienta reads your Shopify order history and inventory levels, estimates how fast each product variant sells, and presents suggestions for what to reorder, how much, and by when. It can email you when a product is low, and it can record purchase orders you choose to create.

2. What the app does not do — read this one

Every number the app shows you is an estimate produced by a statistical model from your past sales. It is not a fact, not a guarantee, and not advice.

You should understand, specifically:

You are responsible for your purchasing decisions, including any stock you buy, do not buy, or buy too much of, after looking at the app.

3. Your Shopify account and your responsibilities

You need an active Shopify store. You are responsible for the accuracy of the settings you enter — particularly your lead time, which drives the reorder point, the buffer and the order-by date. A lead time that does not match reality will produce suggestions that do not match reality.

You must not: use the app unlawfully; attempt to access another merchant's data; reverse engineer, resell or sublicense the app; or use it in a way that damages or overloads it or Shopify.

4. Fees and billing

Paienta is billed through Shopify and appears on your Shopify invoice. We never see or handle your card details.

Every feature is included on every plan. The plans differ only by the size of the catalogue they are priced for:

Every plan begins with a 14-day free trial. You are not charged during the trial and you may cancel within it at no cost. There is no free plan: when the trial ends, an active subscription is required for the app to show forecasts.

The variant counts are what each plan is priced for, not a limit we enforce. If your catalogue grows past the count for your plan, nothing is hidden and no forecast stops — the app shows every variant and asks you to move to the plan that fits. We may ask you to move up; we will not truncate your data to make you.

5. Availability

We aim to keep the app available and will make reasonable efforts to fix faults promptly, but we do not promise a particular level of uptime. The app depends on Shopify's API, which we do not control. Maintenance may make it briefly unavailable.

If the app is unavailable, your Shopify store, your orders and your stock are unaffected — the app only reads from them.

6. Your data

You keep all rights in your data. We claim none. What we do with it, and what we never do with it, is set out in the Privacy Policy and Schedule 1.

We will not use your data to build a product for anyone else. We do not sell it, and we do not pool it across merchants for benchmarking or model training. If we ever want to do anything of that kind, we will ask you first.

7. Our intellectual property

We keep all rights in the app itself — its software, its forecasting method, its interface and its documentation. Installing it gives you a non-exclusive, non-transferable right to use it for your own business for as long as these terms are in force.

8. Suspension and termination

9. Warranties, and the limit of our liability

Please read this section. It limits what you can recover from us.

9.1 No warranty of accuracy

To the extent permitted by law, the app is provided "as is". We do not warrant that it will be uninterrupted or error-free, and — most importantly — we do not warrant that any forecast, suggested quantity, projected stockout date or reorder date is accurate. See section 2.

9.2 Australian Consumer Law

Nothing in these terms excludes, restricts or modifies any guarantee, right or remedy you have under the Competition and Consumer Act 2010 (Cth) or any other law that cannot lawfully be excluded. Where we are permitted to limit our liability for a breach of a consumer guarantee, our liability is limited, at our option, to resupplying the service or paying the cost of having it resupplied.

9.3 What we are not liable for

Subject to 9.2, we are not liable for: lost profits, lost revenue, lost sales, loss of goodwill, the cost of stock you purchased or failed to purchase, overstock, understock, stockouts, obsolete or written-down inventory, or any indirect or consequential loss, however it arises, even if we were told it was possible.

9.4 The cap

Subject to 9.2, our total liability to you for all claims arising out of or in connection with these terms or the app, in aggregate, is limited to the fees you actually paid us in the 12 months before the event giving rise to the claim — or AUD $100 if that is greater.

9.5 Indemnity

You will indemnify us against claims brought by third parties arising from your use of the app in breach of these terms or of the law.

10. Changes to these terms

We may update these terms. If a change is material we will give at least 30 days' notice by email to your store contact address, and continuing to use the app after it takes effect means you accept it. If you do not, uninstall.

11. General

Contact: support@paienta.com



Schedule 1 — Data Processing Terms

These terms apply where we process personal data on your behalf and the GDPR, the UK GDPR, or a comparable law applies. They satisfy Article 28(3) of the GDPR. In this Schedule, "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR.

You are the controller. We are the processor.

1. The unusual thing about this Schedule, stated up front

Paienta is built so that it does not process personal data about your customers at all. It requests no customer fields from Shopify; order and line identifiers that arrive in Shopify's responses are discarded as the response is read; and the webhook notifications whose bodies contain customer details are never parsed. What is stored is a count of units per product per day.

This Schedule is therefore written to be complete if that ever ceases to be true, while being accurate about the position today. Annex A records the categories of data actually processed, and it is deliberately short.

2. Scope and instructions

2.1 We will process personal data only on your documented instructions, including as to transfers, unless required otherwise by law — in which case we will tell you first, unless the law forbids it.

2.2 Your instructions are: these terms, the Privacy Policy, and your use of the app's features. The purpose is limited to providing inventory forecasting and the related features described in section 1 of the terms, and to nothing else.

2.3 We will tell you if, in our opinion, an instruction infringes data protection law.

3. Duration

Processing lasts for as long as the app is installed, and ends on uninstall.

4. Confidentiality

Anyone we authorise to process personal data is bound by an obligation of confidentiality.

5. Sub-processors

5.1 You give general authorisation for us to engage sub-processors. Those engaged as at the effective date are listed in Annex C.

5.2 We will give you at least 30 days' notice before adding or replacing one, by email to your store contact address and by updating the Privacy Policy. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may terminate by uninstalling and we will refund fees covering the unused period.

5.3 Each sub-processor is bound by written terms offering protection equivalent to this Schedule, and we remain fully liable to you for their performance.

6. Security

We implement appropriate technical and organisational measures under Article 32. They are described in Annex B, and we will not materially reduce them during the term.

7. Data subject requests

7.1 We answer Shopify's mandatory compliance webhooks for customer data requests, customer erasure and shop erasure.

7.2 If a data subject contacts us directly, we will not respond to the substance ourselves — we will refer them to you and tell you promptly.

7.3 Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures in meeting your obligations to respond. Given Annex A, that assistance will usually consist of confirming that we hold no personal data about the individual concerned.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information you reasonably need to meet your own notification obligations.

9. DPIAs and prior consultation

We will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking account of the nature of the processing and the information available to us.

10. Deletion

On uninstall we delete the personal data we hold for your shop, and we act on Shopify's shop erasure request as a backstop. We do not keep a copy except where the law requires it. Because everything we hold is derived from your Shopify data, return of the data is not necessary — it remains in your Shopify store — but you may export your purchase orders from the app at any time before you uninstall.

11. Audit

We will make available the information reasonably necessary to demonstrate compliance with this Schedule, and will allow and contribute to audits by you or an auditor you appoint, no more than once in any 12 months unless a supervisory authority requires otherwise or there has been a breach. Audits must be on reasonable notice, during business hours, subject to confidentiality, and must not unreasonably disrupt our business. Where independent certifications or reports from us or our sub-processors can reasonably answer your questions, they may be used instead.

12. International transfers

Where personal data protected by the EU or UK GDPR is transferred outside the EEA or UK, the transfer is made under the Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum), which are incorporated into this Schedule by reference, with:

13. Precedence

If this Schedule conflicts with the rest of the terms, this Schedule prevails on data protection matters.


Annex A — Details of the processing

Subject matter: provision of the Paienta inventory forecasting app.

Duration: the period the app is installed.

Nature and purpose: reading order and inventory data from Shopify; aggregating order lines to daily per-product totals; computing demand rates and reorder suggestions; storing settings and purchase orders; sending low-stock emails.

Categories of data subjects:

Types of personal data:

Category Data Stored?
Merchant identity Shop domain, time zone, currency Yes
Merchant contact Store contact email address No — fetched from Shopify when an alert is sent, not retained
Merchant contact Alert email address, if you enter one Yes
Credentials Shopify API access and refresh tokens Yes, encrypted
Business records Supplier names and notes you type on purchase orders Yes
Customer personal data None No

Special categories: none. The app processes no special category data and no criminal conviction data.

Frequency: continuous while installed.

Annex B — Technical and organisational measures

  1. Data minimisation by design. Customer fields are not requested from Shopify. Order lines are aggregated to {product, day, quantity} as responses are read; identifiers are discarded and never persisted. This is enforced at a single point in the code, and is covered by an automated test that feeds a fully-populated order through it and asserts that nothing identifying survives.
  2. Least privilege. The app holds read-only Shopify permissions for orders, products, inventory and locations, and requests no permission to read customers. It cannot modify anything in your store.
  3. Encryption in transit. TLS for all connections, to Shopify, to our servers and to sub-processors.
  4. Encryption at rest. Shopify access and refresh tokens are encrypted with AES-256-GCM (authenticated encryption, so tampering is detected) using a key held outside the database. Remaining data is on encrypted storage provided by our hosting sub-processor.
  5. Tenant isolation. Every query is scoped to a single shop; requests for another shop's records are rejected.
  6. Deletion. Uninstall triggers immediate deletion of all data for the shop, with Shopify's shop erasure request acting as a backstop 48 hours later. Sales history older than the forecasting window is deleted automatically.
  7. Access control. Administrative access to production systems is limited to personnel who need it, and protected by multi-factor authentication.
  8. Logging. Operational logs record the shop and the outcome of operations and contain no customer data.
  9. Resilience. Because all forecasting data is derived from Shopify and recomputable, recovery from loss consists of resynchronising from Shopify.

Annex C — Sub-processors

Sub-processor Purpose Location
Fly.io Application hosting and database storage Ashburn, Virginia, United States (Fly.io region iad)
Resend (Plus Five Five, Inc.) Sending low-stock alert emails United States