Privacy policy
Effective July 31, 2026. This policy explains what the app processes, why it is needed, and how merchants can request help or deletion.
Information the app processes
- Shopify store identity, installation sessions, and authorized product and legal-policy data.
- Product titles, descriptions, prices, inventory, images, identifiers, variants, collections, and publication status needed to build the feed.
- Catalog coverage, validation results, sync history, billing-plan records, feed previews and retained delivery files, and promotion records.
- Optional expert-setup intake details, including the team contact, target country, budget range, notes, charge status, and fulfillment status.
- SFTP host, username, path, and encrypted password or private key supplied by the merchant.
The app does not request or store Shopify customer records, orders, payment card data, or advertising account credentials.
How information is used
Information is used to scan product eligibility, create the complete coverable product feed, test and operate the merchant-provided SFTP connection, schedule daily refreshes, provide activity history, secure the service, and respond to support requests.
If expert setup is made available and requested, intake details are used only to coordinate and fulfill that campaign service. Account passwords and private keys must not be submitted in the intake form.
Storage and sharing
Application data is hosted in the United States. SFTP credentials are encrypted at rest. Product feed data is transmitted to the SFTP destination configured by the merchant. Service providers may process data only to host, secure, monitor, or bill the app. Information is not sold.
Retention and deletion
Operational store data is retained while the app is installed. The app deletes store configuration, product index, sync records, billing ledger, expert-setup requests, promotion redemption, and Shopify sessions after an uninstall or Shopify shop-redaction request. Up to 30 delivered feed files and 10 feed previews are retained while the app is installed so the merchant can audit, download, compare, or redeliver a file. Older files are deleted automatically. Infrastructure logs may remain for up to 30 days.
Merchant choices
Merchants can replace or remove SFTP credentials, uninstall the app, or request access, correction, or deletion by emailing matt@craez.com.
Security and contact
We use access controls, encryption, TLS, least-privilege Shopify scopes, and restricted infrastructure access. No system is risk-free. Report privacy or security concerns to matt@craez.com.