Transfer Store ("the App", "we", "us") is a Shopify application that helps merchants export data from one Shopify store and import it into another. This policy explains what information the App accesses, how it is used, and how it is protected.
Information we access
When you install the App on a Shopify store, you grant it permission to read and/or write the following data through Shopify's APIs:
Store content and pages: blog posts, articles, online store pages, and navigation menus.
Products: product listings, variants, images, collections, and related metadata.
Metaobjects and metafields: custom data structures and their definitions.
Files: images and other media stored in your Shopify Files section.
Orders and draft orders: order records, line items, and draft order details.
Discounts: discount codes and automatic discount configurations.
Locations and locales: store location and language settings.
The App accesses this data only to perform transfers that you explicitly initiate.
How we use information
To read data from a source store and write it to a destination store at your direction.
To temporarily stage files and export archives so that large transfers can be completed reliably.
To display transfer progress, results, and error reports to you within the App.
We do not sell your data, use it for advertising, or share it with third parties except as described below.
Data storage and retention
Session data (Shopify access tokens and shop identifiers) is stored in our application database for as long as the App is installed.
Transfer files are staged temporarily in cloud object storage (Amazon S3) during an active transfer and are deleted automatically after the transfer completes or expires.
Transfer logs (records of what was transferred, timestamps, and errors) are retained only as long as needed to support the operation and troubleshoot issues.
We do not retain copies of your products, customers, or orders beyond what is required to complete an in-progress transfer.
Subprocessors
Shopify: source of all store data and the platform the App runs on.
Amazon Web Services (S3): temporary storage of transfer archives and media.
Vercel: application hosting.
Data security
Data is transmitted over encrypted connections (HTTPS/TLS). Access tokens and staged files are protected with access controls, and staged files use time-limited, signed URLs. We restrict internal access to production systems to authorized personnel only.
Your rights and Shopify compliance
The App supports Shopify's mandatory data protection webhooks:
customers/data_request: if a customer requests their data, we will provide any customer data the App holds.
customers/redact: customer data is deleted upon request.
shop/redact: all data associated with a store is deleted 48 hours after the App is uninstalled.
If you uninstall the App, session data is removed and any staged transfer files are purged.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.