Overview
Who we are
Cyberify Catalog Export ("the App", "we", "our", "us") is a Shopify embedded application developed and operated by Cyberify. The app is available at cyberify.net and is distributed through the Shopify App Store.
We built Cyberify Catalog Export to help Shopify merchants browse their product catalog inside the app and export the products they choose as a CSV or JSON file — without ever modifying the product listing in Shopify.
This Privacy Policy explains what data we collect, why we collect it, how we store and protect it, and how you can request deletion. We aim to keep this policy clear, transparent, and free from unnecessary legal jargon.
Legal basis for processing (GDPR).
We process your data under the following legal bases:
- Contractual necessity — to provide the app's core functionality, including product syncing and letting you export your catalog.
- Legitimate interests — to improve reliability, monitor errors, and maintain platform security.
Roles & responsibilities.
For data protection purposes:
- You (the merchant) are the Data Controller of your store data.
- Cyberify acts as the Data Processor, processing your data only to provide the app's services on your behalf.
What we collect and why.
01 Shopify store information
We collect: shop domain (e.g. yourstore.myshopify.com), Shopify access token, installation date.
Why: to identify your store, connect securely to the Shopify Admin API, and read product data for display inside the app.
02 Product & catalog data
We collect:
- Product titles, descriptions, prices, and images
- Variants and inventory levels
- Collections
Why: to display your catalog inside the app's Products page, and to build the CSV or JSON file when you export the products you select.
We store a local, read-only copy of your product catalog to make the app fast to use. We never write changes back to your Shopify products.
Important. We do not sell or share your product data with any third party. Product data is never sent to an advertising network, marketplace, or data broker of any kind.
03 Settings
We collect: your product-sync preference (all variants vs. first variant only).
Why: to apply your preference when syncing products from Shopify.
04 Activity data
We collect: a log of product imports, including timestamps.
Why: to populate your dashboard's recent activity feed.
05 Exported files
When you export products as CSV or JSON, the file is generated and downloaded directly in your browser. We do not store a copy of exported files on our servers — once the download completes, the file exists only on your device.
06 Data we do not collect
- Customer names, order history, or payment/banking information
- Any Shopify customer records — we never request customer-related permissions
- Sensitive personal information
We do not use advertising cookies or tracking pixels. We may use minimal technical tools such as error monitoring services strictly for performance, diagnostics, and service reliability.
How we store and protect your data.
| Data type | Storage | Protection | Retention |
|---|---|---|---|
| Shopify access token | PostgreSQL (Neon · US East) | AES-256 at rest | Until uninstall |
| Product catalog | PostgreSQL (Neon · US East) | TLS in transit | Until uninstall + 48 hrs |
| Settings | PostgreSQL (Neon · US East) | TLS in transit | Until uninstall |
Security measures
- HTTPS (TLS 1.2+) for all communication
- AES-256 encryption for your Shopify access token
- Secure server infrastructure hosted on Amazon Web Services
- Firewall-restricted access — only required ports are public
- No logging of tokens, passwords, or sensitive credentials
- Restricted database and infrastructure access for authorised Cyberify personnel only
Key handling. Encryption keys are never stored inside the database.
International data transfers
Your data may be processed in countries outside your own, including the United States, where our infrastructure providers operate. We ensure appropriate safeguards are in place, including encryption, secure infrastructure, and standard contractual protections where required by law.
Third-party services.
| Service | Purpose | Data shared |
|---|---|---|
| Shopify Admin API | Read products and collections | Product and collection data |
| Neon PostgreSQL | Database hosting | Stored app data |
| AWS EC2 | Application hosting | Application traffic |
| Sentry | Error monitoring | Anonymised error stack traces |
We do not sell, rent, or trade your data for advertising or marketing purposes.
Service dependency disclaimer
Cyberify Catalog Export depends on third-party services including Shopify. We are not responsible for service interruptions, API limitations, or delays caused by these third-party platforms.
GDPR & Shopify compliance.
We fully comply with Shopify's required GDPR webhooks.
Customer data request
If a customer submits a data request, we identify and return any matching records. Since Cyberify Catalog Export does not collect Shopify customer records, our response will normally confirm that no customer data is stored.
Customer data erasure
If a customer requests deletion, we permanently delete any matching records within 30 days.
Shop data erasure
When a Shopify store is deleted or permanently closes, we permanently delete all associated store data within 48 hours. This includes products, tokens, settings, and activity logs.
Your rights as a merchant.
You have the right to:
- Access — request a copy of all data we hold about your store.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — request permanent deletion of your store data.
- Portability — request your data in a machine-readable format such as JSON or CSV.
To exercise any of these rights, contact info@cyberify.net. We respond within 5 business days.
Data retention & deletion.
- Uninstalling the app triggers automatic deletion within 48 hours.
- Database backups are retained for 7 days before permanent deletion.
Children's privacy.
This app is intended for business use by merchants and store operators. It is not intended for individuals under the age of 18, and we do not knowingly collect personal data from children.
Changes to this policy.
If we make material changes to this Privacy Policy, we will update the "Last Updated" date at the top of this page. For significant changes, we may also notify you by:
- Email to your Shopify store contact address
- In-app notification inside Cyberify Catalog Export
Continued use of the app after updates are posted constitutes acceptance of the updated policy.
Questions about your data?
If you have any questions about this Privacy Policy or wish to exercise your data rights, get in touch — we respond within five business days.