Privacy Policy - #ProductCreator

Last updated: 19 August 2026

This policy explains what data #ProductCreator ("the app", "we", "us") collects from your Shopify store, how we use it, and your rights.

What we collect

When you install #ProductCreator, Shopify grants the app access to your store's products (read_products, write_products). We only read and store what's needed to enrich supplier product data and generate Shopify-ready product listings:

  • Store identifier: your *.myshopify.com domain and an offline access token issued by Shopify.
  • Catalog samples: titles, descriptions, tags, SEO title and description, vendor, product type, and product category from existing products we read to learn your catalog's writing style. We also read product and variant metafield definitions (namespace, key, type, name) so you can map supplier columns to them, plus distinct vendor and product-type values used as filters.
  • Supplier and generated product data: CSV/Excel files you upload, the column mappings you configure, and the enriched product fields we generate (titles, descriptions, SEO text, tags, categories, image alt text, and mapped metafields). Each import job stores the source rows, the generated output, and status metadata.
  • Operational logs: timestamps, error messages, and shop identifiers for diagnostics.

We do not collect or store customer personal data, order data, or payment information.

How we use it

  • To run enrichment jobs you initiate from the app interface.
  • To match generated copy to your existing catalog style and to produce a Shopify product-import CSV you apply to your store.
  • To diagnose errors and improve the service.

We do not sell, share, or use your data for advertising or any purpose unrelated to operating #ProductCreator.

Where it lives

Data is stored on managed cloud infrastructure (PostgreSQL on Railway, hosted in the EU). Connections to Shopify and to our database use TLS. Access tokens are stored in our database and are used only to call the Shopify Admin API on your store's behalf. Product text you choose to enrich is sent to Anthropic (Claude) to generate copy; Anthropic is not permitted to use that content to train its models under our API terms.

How long we keep it

  • Import jobs, mapping profiles, style samples, and settings are retained while the app is installed.
  • When you uninstall the app, Shopify sends an app/uninstalled webhook. We delete your access token, stop processing, and schedule deletion of your remaining data after a 30-day grace period (so a quick reinstall can keep credits and profiles).
  • After Shopify's standard 48-hour grace period, we receive shop/redact and we delete all stored data associated with your shop immediately, even if the 30-day window has not elapsed.
  • You can request earlier deletion at any time by emailing us (below).

GDPR / compliance

#ProductCreator honours Shopify's mandatory compliance webhooks:

  • customers/data_request — we don't store customer data, so any request returns no data.
  • customers/redact — same: nothing to redact.
  • shop/redact — we delete all data associated with the shop.

If you're in the EU/EEA or UK, the GDPR/UK GDPR applies to any personal data of yours (the merchant) that we process. The lawful basis is the contract you accept when installing the app from the Shopify App Store. You may request access, correction, or deletion of that data at any time.

Sub-processors

  • Shopify — source of all store data we access.
  • Railway — hosting and PostgreSQL.
  • Anthropic — AI enrichment of product text you submit (titles, descriptions, and related fields).
  • Sentry — error tracking (no customer data, only stack traces and shop identifiers).

Changes

We may update this policy. Material changes will be communicated via email to your Partner contact and noted by changing the "Last updated" date above.

Contact

Questions, deletion requests, or concerns:
dtails ApS — support@dtails.dk