Privacy Policy
PixMatch (“the App”) is a Shopify embedded application that helps merchants match bulk product photos to catalog variants and publish them to Shopify. This policy explains what we store, why, and how merchants can request deletion.
1. Data we process
- Shopify shop identity — shop domain and offline access token required to call the Admin API on your behalf.
- Import job data — filenames, extracted SKUs / barcodes / handles, match status, product/variant IDs, upload results, and optional CSV contents you upload.
- Temporary media — ZIP archives and image files stored ephemerally on our servers during an import, then removable after processing.
- Connection credentials you authorize — for example Dropbox or Google Drive OAuth tokens when you connect a cloud account (used only to list folders and download selected product images at publish time).
- App preferences — naming patterns, match options, and last-used import source for your shop.
- Feature requests — free-text ideas you submit inside the App.
2. Google user data (Drive API)
When you connect Google Drive, PixMatch accesses Google user data only as needed for the Drive import feature:
- Data accessed — Google account email and basic profile name (to show which account is connected); and metadata plus bytes for Drive image files you explicitly select in Google Picker (names, IDs, MIME types, sizes).
- How we use it — to match SKU-named images you selected to Shopify variants, show a mandatory review screen, and — only after you confirm — download those images and upload them to Shopify via staged uploads. We do not browse your entire Drive. We do not use Google data for advertising, analytics resale, credit decisions, or unrelated product development.
- Sharing / transfer — we do not sell Google user data. Image bytes you confirm are transferred to Shopify as product media for your shop. Hosting is on our EU infrastructure provider (Fly.io, Frankfurt). We do not transfer Google user data to data brokers, advertisers, or unrelated third parties.
- Protection — OAuth tokens and related credentials are stored server-side and transmitted over HTTPS. Access is limited to operating the App for your shop.
- Retention & deletion — Drive OAuth tokens and connected-account display fields are cleared when you disconnect Google Drive or uninstall the App. Temporary image files used during an import are removed after processing / shop erasure. Import job history (filenames, match results) is erased on Shopify
shop/redactafter uninstall, or earlier on request to privacy@pixmatch.it.
Google Limited Use compliance. PixMatch's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace / Drive user data to develop, improve, or train generalized AI/ML models, and we do not transfer that data to third-party AI/ML services for model training.
3. Data we do not collect
PixMatch does not intentionally store Shopify customer personal data (names, emails, addresses, order history). Product catalog fields (SKU, barcode, handle, title) are read from Shopify only to match images and are retained as part of import job history until deleted.
4. How we use data
- Authenticate the App inside Shopify Admin
- Match photos to products and publish media you confirm
- Show import history, progress, and CSV reports
- Improve the product using aggregated, non-identifying feedback
5. Sharing
We do not sell merchant data. We process data on infrastructure providers that host the App (currently Fly.io in the EU region Frankfurt) and, when you connect them, third-party sources such as Dropbox or Google Drive under your authorization. Shopify remains the system of record for your catalog.
6. Retention & deletion
- On uninstall we clear Dropbox and Google Drive tokens and delete Shopify sessions immediately.
- About 48 hours after uninstall, Shopify sends a
shop/redactrequest; we then erase remaining shop data (import jobs, settings, feature requests). - Customer data request / redact webhooks are acknowledged; PixMatch does not retain customer personal profiles to export or delete.
7. Security
Access tokens and cloud credentials (Dropbox / Google Drive) are stored server-side and transmitted over HTTPS. Merchants should disconnect cloud accounts when no longer needed and uninstall the App to trigger full erasure.
8. International transfers
Primary application hosting is in the European Union (Fly.io, Frankfurt). Third-party services you connect may process data in other regions under their own terms.
9. Your rights
Store owners can request access or deletion by emailing privacy@pixmatch.it or by uninstalling the App (which triggers Shopify’s compliance webhooks). EU/UK merchants may also have rights under GDPR / UK GDPR.
10. Children
The App is intended for business use by Shopify merchants and is not directed at children.
11. Changes
We may update this policy as the App evolves. Material changes will be reflected by updating the effective date on this page.
12. Contact
XBRAIN srl · privacy@pixmatch.it · Marketing site: pixmatch.it