Privacy Policy
PixMatch (“the App”) is a Shopify embedded application that helps merchants match bulk product photos to catalog variants and publish them to Shopify. This policy explains what we store, why, and how merchants can request deletion.
1. Data we process
- Shopify shop identity — shop domain and offline access token required to call the Admin API on your behalf.
- Import job data — filenames, extracted SKUs / barcodes / handles, match status, product/variant IDs, upload results, and optional CSV contents you upload.
- Temporary media — ZIP archives and image files stored ephemerally on our servers during an import, then removable after processing.
- Connection credentials you authorize — for example Dropbox OAuth tokens when you connect a Dropbox account (used only to list folders and obtain temporary image links).
- App preferences — naming patterns, match options, and last-used import source for your shop.
- Feature requests — free-text ideas you submit inside the App.
2. Data we do not collect
PixMatch does not intentionally store Shopify customer personal data (names, emails, addresses, order history). Product catalog fields (SKU, barcode, handle, title) are read from Shopify only to match images and are retained as part of import job history until deleted.
3. How we use data
- Authenticate the App inside Shopify Admin
- Match photos to products and publish media you confirm
- Show import history, progress, and CSV reports
- Improve the product using aggregated, non-identifying feedback
4. Sharing
We do not sell merchant data. We process data on infrastructure providers that host the App (currently Fly.io in the EU region Frankfurt) and, when you connect them, third-party sources such as Dropbox under your authorization. Shopify remains the system of record for your catalog.
5. Retention & deletion
- On uninstall we revoke Dropbox tokens and delete Shopify sessions immediately.
- About 48 hours after uninstall, Shopify sends a
shop/redactrequest; we then erase remaining shop data (import jobs, settings, feature requests). - Customer data request / redact webhooks are acknowledged; PixMatch does not retain customer personal profiles to export or delete.
6. Security
Access tokens and Dropbox credentials are stored server-side and transmitted over HTTPS. Merchants should disconnect Dropbox when no longer needed and uninstall the App to trigger full erasure.
7. International transfers
Primary application hosting is in the European Union (Fly.io, Frankfurt). Third-party services you connect may process data in other regions under their own terms.
8. Your rights
Store owners can request access or deletion by emailing privacy@pixmatch.it or by uninstalling the App (which triggers Shopify’s compliance webhooks). EU/UK merchants may also have rights under GDPR / UK GDPR.
9. Children
The App is intended for business use by Shopify merchants and is not directed at children.
10. Changes
We may update this policy as the App evolves. Material changes will be reflected by updating the effective date on this page.
11. Contact
XBRAIN srl · privacy@pixmatch.it · Marketing site: pixmatch.it