SKUPrep

Privacy policy

Last updated: 25 August 2026

SKUPrep is a Shopify app that audits a merchant's product catalog and applies merchant-approved corrections to it. This policy describes exactly what it processes and what it does not.

SKUPrep does not process customer personal data. It requests only the read_products and write_products access scopes. It has no access to customers, orders, checkouts, payments or storefront visitors, and it never asks for them.

Who is responsible

The data controller for merchant account data, and the data processor for catalog data, is the operator of SKUPrep. For any privacy question or request, write to [email protected]; requests are answered within 30 days.

What is processed

DataWhyRetention
Shop domain, shop name, install date, planIdentify the installation, apply plan limits, bill correctlyUntil 48 hours after uninstall
Shopify access tokenRead and write the catalog on the merchant's behalfEncrypted at rest (AES-256-GCM); revoked and deleted on uninstall
Product catalog: titles, descriptions, vendors, tags, categories, options, variants (SKU, barcode, weight), images and their alt text, metafieldsRun the audit, propose fixes, verify applied changesDeleted 48 hours after uninstall
Findings, scores, proposals, change logShow the score trend, let the merchant review and roll back changes12 months, then pruned; deleted with the catalog on uninstall
Aggregate AI token counts per shop and monthEnforce plan limits and monitor cost12 months
Technical logs (job ids, shop id, timestamps, errors)Operate and debug the service30 days

Product prices and inventory quantities are read only to display context alongside a finding. They are never written, and are not used for any other purpose.

Sub-processors

ProviderPurposeWhat it receives
ShopifyThe platform the catalog lives onThe API calls SKUPrep makes on the merchant's behalf
Anthropic (Claude API)Optional AI features: attribute extraction, category suggestion, description rewriting, image alt textOnly the product text and image URLs of products being processed. No shop identifiers, no account data. Anthropic does not train on API inputs.
Hosting and database providerRuns the application and stores the data aboveAll data listed above, within the EU
SentryError monitoringError traces with shop and job identifiers. Access tokens and personal data are redacted before sending.

AI features can be switched off entirely in the app's settings. With them off, no data leaves the application other than to Shopify itself.

Where data is stored

Data is stored within the European Union. Transfers to sub-processors outside the EU are covered by Standard Contractual Clauses.

Deletion

Security

Your rights

Under the GDPR a merchant may request access to, correction of, export of, or erasure of their data, and may object to or restrict its processing. Write to [email protected]. A complaint can also be lodged with a supervisory authority.

Changes

Material changes to this policy are announced in the app before they take effect. The date at the top always reflects the current version.