Privacy Policy
Effective · June 15, 2026
Who we are
CSVwise is a Shopify app operated by Answer 42 Labs LLC, a US-based company ("we," "us"). The app cleans messy product CSVs before merchants import them via Shopify's native importer. For privacy questions, contact us at privacy@csvwise.com. CSVwise is a business tool and is not directed to children; you must be at least 18 to use it, consistent with our Terms of Service.
What data we collect
We collect only what we need to deliver the app:
- Shopify session data. When you install CSVwise, Shopify provides us with an OAuth session token and basic shop identifiers (shop domain, the staff user's name and email if they grant it). We store these to authenticate API calls back to your store.
- Usage records. Each cleanup is logged with row count, column count, the per-issue fix counts that produced the cleaned file, and the staff user who initiated it. These records support debugging and let us enforce tier limits.
- Sample CSV content sent to AI for column mapping. When you opt into the AI-assisted column mapping step, we send your CSV's column headers and the first 5 data rows to an AI provider, via Vercel AI Gateway, for analysis. The full file content is never transmitted; AI processing is limited to that deterministic sample. See "AI-assisted column mapping" below for the providers involved.
- What we do not collect. CSVwise does not store your store's customer data, order data, or product catalog. CSV files you upload are processed in your browser; only the specific samples described above are transmitted to our servers. For the Pro and Studio handle-collision check, CSVwise reads existing product handle information from your store to run the check, but does not store your product catalog on our servers.
AI-assisted column mapping
CSVwise offers an optional AI-assisted column mapping step. When you use this feature:
- We send your CSV's column headers and the first 5 rows of data to Anthropic's Claude model for analysis, routed through Vercel AI Gateway. For reliability, the Gateway may serve this request through any of the zero-data-retention providers that host Anthropic's Claude model — Anthropic, Amazon Bedrock, or Google Vertex AI — but the model and the data sent are identical in every case. We do not route this data to any other model or AI provider.
- This request is processed under Zero Data Retention (ZDR): we have configured Vercel AI Gateway to route only to providers that have agreed not to retain or train on the data. The 5-row sample is not used to train any model and is not stored beyond the lifetime of the single request — neither by the AI provider nor by Vercel AI Gateway itself.
- The mapping result the AI provider returns is shown back to you so you can review and override it before any data transformation runs. The AI's suggested mapping is advisory; you review and can override it, so no decision about you is made solely by automated means.
- If you do not run AI-assisted column mapping, no CSV content is transmitted to any AI provider.
We never send full-file content, customer data, order data, or anything outside the 5-row sample to any AI provider.
How we use your data
- To deliver the cleanup, mapping, and import-readiness checks the app provides.
- To authenticate API calls between CSVwise and your Shopify store.
- To bill paid tiers (via Shopify's billing system — we do not see your payment details).
- To diagnose errors and improve the app, via aggregated usage records.
- To respond to support requests sent to support@csvwise.com.
Our lawful bases (GDPR). Where the GDPR applies and CSVwise acts as a controller, we rely on the following lawful bases under Article 6:
- Performance of a contract — to deliver the cleanup, mapping, and import-readiness checks; to authenticate API calls to your store; and to administer paid subscriptions.
- Consent — for the optional AI-assisted column mapping step, which transmits a 5-row sample to an AI provider only when you choose to run it. You can decline; not running it transmits nothing, and you may withdraw at any time by not using the feature.
- Legitimate interests — to secure, debug, and improve the Service through aggregated usage records and crash diagnostics. Our interest is operating a reliable, secure product; we weigh it against your rights and use the minimum data needed.
- Legal obligation — to retain certain billing and transaction records where tax or accounting law requires.
Where CSVwise acts as a processor on a merchant's behalf, the merchant, as controller, is responsible for establishing the lawful basis for the underlying processing.
Sub-processors
To operate CSVwise we rely on a small, fixed set of third-party service providers that process personal data on our behalf ("sub-processors"). We have a data processing agreement (DPA) in place with each of our direct providers — Shopify, Vercel, Neon, Upstash, and Sentry — that binds them to data-protection terms consistent with this policy and applicable law (including, for transfers, the safeguards listed under "International data transfers"). The AI providers that serve the optional column-mapping step (Anthropic, and the zero-data-retention infrastructure providers that host its model) are engaged through Vercel AI Gateway and are covered by Vercel's own data-processing and zero-data-retention agreements.
- Shopify Inc. — to authenticate your shop and call the Admin API on your behalf (e.g., the "handle already in use" check on Pro and Studio tiers).
- Vercel Inc. — to host the app, serve requests, and (when you opt into AI mapping) route the 5-row CSV sample through Vercel AI Gateway to the Anthropic Claude model. AI Gateway is a routing and observability layer; it does not retain prompt content beyond the lifetime of the request.
- Anthropic PBC — provides the Claude model used for the optional column-mapping step. Processes the 5-row CSV sample only when you opt into AI mapping, under a zero-data-retention agreement.
- Amazon Web Services, Inc. (Amazon Bedrock) and Google LLC (Google Vertex AI) — infrastructure providers through which Vercel AI Gateway may serve the same Anthropic Claude model for reliability. Each processes the 5-row CSV sample only when you opt into AI mapping and only if it serves your specific request, under a zero-data-retention agreement.
- Neon — managed Postgres database (provisioned via the Vercel Marketplace) where we store session and usage records.
- Upstash Inc. — managed Redis for short-lived rate-limit counters and one-time-use cleanup tokens.
- Functional Software, Inc. (Sentry) — application error reporting (e.g., a crash on the cleanup pipeline). Sentry receives crash diagnostics including stack traces; we do not send CSV content to Sentry.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA). We do not do this with any data, for anyone.
Our role. For the personal data we process to deliver the Service on your instructions — your Shopify session data, the usage records tied to your shop, and the optional 5-row AI sample — CSVwise acts as a processor and you, the merchant, are the controller. For the limited data we process for our own purposes — our business-contact relationship with the staff who install or operate the app, the aggregated usage statistics we use to debug and improve the Service, and the crash diagnostics sent to our error-reporting provider — CSVwise acts as a controller. If you are subject to the GDPR or a comparable law and need a DPA covering our role as your processor, email privacy@csvwise.com and we will provide one.
Changes to our sub-processors. The list above is our current sub-processor list. We will update it (and the effective date) when we add or replace a sub-processor that processes personal data. Where required by applicable law or by a data processing agreement with you, we will provide reasonable advance notice and an opportunity to object on reasonable data-protection grounds; if we cannot address your objection, you may terminate by uninstalling.
Data retention
- Session and usage records are kept while CSVwise is installed and for 48 hours after uninstall, after which Shopify delivers a shop-redaction webhook and we hard-delete all shop-scoped rows (session tokens, usage records, billing state). We honor Shopify's 48-hour reinstall window because credits and history should survive a brief uninstall/reinstall mistake.
- Staff identifiers (the name and email of the staff user who installed the app or ran a cleanup) are stored as part of session and usage records and follow the same lifecycle: retained while CSVwise is installed and deleted within the 48-hour post-uninstall window described above. We keep them only to authenticate and attribute activity within your installation, and we do not retain a separate copy beyond that lifecycle. Aggregated usage statistics that no longer identify any individual may be retained for product analytics.
- The 5-row AI sample is transmitted only when you run AI mapping, under Zero Data Retention. It is not stored on our servers, by the AI provider, or by Vercel AI Gateway beyond the lifetime of the single API request.
- CSV files you upload are processed in your browser. We do not store them on our servers.
Security
We protect the data described above with industry-standard safeguards: OAuth session tokens and usage records are encrypted at rest by our managed database provider, all data in transit moves over TLS, and access to production systems is limited to the personnel who need it to operate or support the app. No system is perfectly secure; if a breach affects your data, we will notify affected merchants without undue delay and notify any applicable authorities as required by law.
GDPR + your rights
Shopify forwards data-access and data-deletion requests from your store's customers to all installed apps via standard compliance webhooks (customers/data_request, customers/redact, shop/redact). CSVwise implements all three. Because we do not store your store's customer data, the customer-scoped webhooks acknowledge with no data to return; the shop-scoped webhook — which Shopify fires about 48 hours after uninstall — triggers a hard delete of all CSVwise records for your shop, well within the 30-day GDPR deadline.
The staff identifiers we hold — the name and email of the staff user who installed the app or ran a cleanup — describe your own staff, who are our direct business contacts. They are not your store's end-customers, so they fall outside the scope of the customers/redact webhook; requests concerning that data should be sent to us directly at privacy@csvwise.com.
International data transfers. CSVwise is operated from the United States, and our sub-processors are located in the United States. Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland, that data is transferred to the United States under appropriate safeguards as required by Chapter V of the GDPR. Our baseline safeguard is the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where the data originates in the United Kingdom. Several of our sub-processors are additionally self-certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions); for those processors, transfers may also rely on the Framework. The safeguard each sub-processor relies on is:
| Sub-processor | Transfer safeguard |
|---|---|
| Shopify Inc. | Standard Contractual Clauses (per Shopify's DPA) |
| Vercel Inc. | Standard Contractual Clauses + UK Addendum (per Vercel's DPA) |
| Anthropic PBC | Standard Contractual Clauses (per Anthropic's Commercial Terms / DPA) |
| Amazon Web Services, Inc. (Amazon Bedrock) | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Google LLC (Google Vertex AI) | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Neon | EU-U.S. Data Privacy Framework and Standard Contractual Clauses (per Neon's DPA) |
| Upstash Inc. | EU-U.S. Data Privacy Framework (incl. UK and Swiss extensions) and Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | EU-U.S. Data Privacy Framework (incl. UK and Swiss extensions) and Standard Contractual Clauses |
Neon's Data Privacy Framework coverage is held under its parent company, Databricks, Inc. (which acquired Neon in 2025), with Neon, LLC as a covered entity.
To request a copy of the relevant transfer documentation, email privacy@csvwise.com.
If you are in a jurisdiction with additional rights (right of access, rectification, portability, erasure, restriction of processing, objection to processing, withdrawal of consent), email privacy@csvwise.com with your shop domain and request. We will respond within 30 days.
Changes to this policy
If we make material changes we will post the updated policy at this URL and update the "effective" date above. For Pro and Studio merchants, we will also notify you by email at the shop owner's registered Shopify email.
Contact
Privacy questions: privacy@csvwise.com. We aim to respond within two business days. For service of legal process, Answer 42 Labs LLC maintains a registered agent on file with the Oregon Secretary of State Business Registry (sos.oregon.gov).