Privacy policy
Version 2.1 · Last updated 15 September 2026
This describes what Importrr (“the app”) stores about your store, who else sees it, and how to have it deleted. It covers the app only. Shopify’s own handling of your data is governed by Shopify’s privacy policy.
We decide what the app collects and why, which makes us the controller of it. Reach us about any of this at hassantaabi@gmail.com.
1. What the app never sees
The app asks Shopify for access to two things and no others: reading and writing your products, and reading and writing which sales channels those products are published to, so that an imported product appears in your Online Store. It therefore has no access to, and never stores:
- your customers, their names, addresses or contact details;
- your orders, carts, or checkout data;
- payment or card details, which are handled entirely by Shopify;
- your Shopify staff accounts beyond who used this app.
Shopify requires every app to answer requests about customer data. When Shopify sends the app such a request, the honest answer is that it holds none, and that is what the app replies.
2. What the app stores
About your store:
- your myshopify domain, store name, contact email, country, currency and timezone, read from Shopify so imported prices are converted into the right currency;
- an access token for your store, held encrypted, which is what lets the app create products on your behalf;
- which member of your staff used the app, and when.
About your use of it:
- your settings: pricing rules, defaults, brand voice, contact number;
- the source addresses you import from, and a record of each import: how many products, which succeeded, which failed and why;
- your rights confirmations — which source, when, by whom, under which version of the terms, together with the IP address and browser the confirmation was given from. This is kept as evidence that the confirmation was made, and is the one place the app stores an IP address;
- AI description drafts: the original description, what the AI proposed, and what you approved, kept so a change can always be undone;
- how much of your plan’s allowance you have used, and your current subscription;
- an audit record of significant actions. Values that look like secrets or personal details are masked before they are written.
3. Who else sees it
The app shares data with these services and no others:
- Shopify — the app reads and writes your products through Shopify’s API, and all billing runs through Shopify.
- Groq, our AI provider — when you ask for an AI description, the product’s title and current description, and the brand-voice text you have written, are sent to Groq to generate the draft. Nothing else is sent. Under our agreement with Groq they are not permitted to use it to train or fine-tune any model, and we do not use it for any other purpose ourselves. If you never use the AI feature, nothing reaches them.
- Exchange-rate services — to convert prices the app requests published rates from open.er-api.com, jsdelivr.net and frankfurter.app. These requests contain currency codes only. No information about you or your store is sent.
- The source stores you choose — the app requests pages that those stores publish publicly, as any visitor would. It sends them nothing about you.
- Our hosting and database providers, who store the data described above on our behalf and do not use it for anything else.
The app does not sell data, does not share it for advertising, and carries no third-party analytics or tracking.
4. How long it is kept
Settings and import history are kept while the app is installed, so you can see what a past import did and undo it.
Uninstalling stops all work immediately and discards your access token. Shopify then sends a deletion request, on its own schedule, and everything the app holds about your store is erased when it arrives.
Rights confirmations are the exception while the app remains installed: they are kept for as long as the import they belong to, because a record of what was confirmed is only worth having if it outlives the configuration it referred to. They are erased with everything else on deletion.
5. Why we are allowed to hold it, and your rights
We hold it to perform the contract you entered into by installing the app: without your store details, your settings and a record of your imports there is no app. Some of it — the audit record, and the rights confirmations — we hold because we have a legitimate interest in being able to show what was done and what was agreed to, and because keeping it protects you as much as us.
Where the UK GDPR or the EU GDPR applies to you, you may ask us to:
- give you a copy of what we hold about you;
- correct anything that is wrong;
- erase it, which the app can do for you directly;
- give it to you, or to someone else, in a machine-readable form;
- restrict what we do with it, or object to our holding it on the basis of legitimate interest.
Ask at hassantaabi@gmail.com and we will answer within one month. If you think we have got it wrong you can complain to your data protection regulator — in the United Kingdom, the Information Commissioner’s Office.
6. Where it goes
The database is hosted in the United States, and the AI provider processes description text there. If you are in the United Kingdom or the European Economic Area, that means your data is transferred outside it. Those transfers are made under the standard contractual clauses approved for the purpose, which is the mechanism that requires the recipient to protect it to the same standard.
7. Having it deleted
You can have everything erased in any of three ways:
- uninstall the app, and Shopify’s deletion request follows;
- ask from inside the app, under Settings, without uninstalling. The request is recorded and carried out within 30 days;
- email us at the address below.
Products already created in your store are yours and are not removed by any of these. Deleting them is done from your own Shopify admin, or with the app’s undo before you uninstall.
8. Security
Access tokens and anything else sensitive are encrypted before being stored. Values that look like credentials or personal details are masked out of logs at the point they are written rather than filtered afterwards. Data is held on managed infrastructure with access limited to those who need it.
9. Your own customers
Product descriptions the app imports may contain a supplier’s contact details. Where you turn the clean-up rules on, those are replaced with yours or removed. What you publish afterwards is yours, and your own privacy policy governs it.
10. Changes
The version and date at the top change when this policy does. Material changes will be notified in the app.
11. Contact
Questions, or a deletion request: hassantaabi@gmail.com