Privacy policy
Last updated: 25 September 2026
PIDReady is a Shopify app that helps merchants prepare the product identifiers EU customs ask for. This policy explains what information it collects when a store uses it, why, how long it is kept and the choices you have.
Who we are
PIDReady is provided by Alejandro Oberogo, Beechwood Grove, Manchester, M9 4ND, United Kingdom (“we”, “us”), the controller of the personal data described here. You can contact us at support@pidready.com.
What we collect
PIDReady only asks Shopify for permission to read and edit products and inventory. It cannot see your customers or your orders. We store:
- Store details: your store's myshopify.com address and name, the language of your Shopify admin, your PIDReady plan and settings, and when you installed and last opened the app.
- Access credentials: the tokens Shopify issues so PIDReady can work with your store. They are stored encrypted.
- Product data: for each product variant, what is needed to check and export customs identifiers: product and variant titles, status, vendor, product type, collections, SKU, manufacturer reference, barcodes, HS code, country of origin, whether it needs shipping, your exclusions and the status PIDReady works out.
- Work records: catalogue scans, the changes you make through PIDReady (so they can be undone), the files you import (Excel or CSV) and background tasks.
- Technical records: our server logs each request (time, page address without its parameters, result, duration and store address) and any errors. We don't log IP addresses, access tokens or what you send. To protect the service from abuse, requests to public pages are counted per IP address in memory for one minute; that count is not stored. Our hosting provider also keeps its own request logs, which can include IP addresses and browser details.
- Support messages: if you email support@pidready.com, we receive your email address and what you write.
Product data is information about products, but it can identify a person when a store is run by one (for example, a store named after its owner), so we treat all of it with the same care.
Cookies
PIDReady sets one cookie, pidready_locale, which remembers the language of your Shopify admin for up to a year so the app opens in that language. It is not used for tracking, and PIDReady has no advertising or analytics trackers. The app runs inside your Shopify admin and uses Shopify's own scripts (App Bridge and Polaris), which Shopify's privacy policy covers.
Why we use it
- To provide PIDReady to your store: scanning your catalogue, showing what is missing, saving your changes to Shopify, undoing them, exporting files and keeping the report up to date. Legal basis: performing our contract with you.
- To keep PIDReady secure and working: logs, error reports and abuse protection. Legal basis: our legitimate interest in running a secure, reliable service.
- To answer your support requests. Legal basis: our contract with you, or our legitimate interest in helping you.
- To keep business and tax records. Legal basis: legal obligation.
We don't sell personal data, use it for advertising or make automated decisions about you with it.
Payments
If you subscribe to a paid plan, Shopify bills you and processes the payment. We never see your payment details. We receive your store's name and the amounts in Shopify's payout records and keep them for as long as UK tax law requires.
Who we share it with
We use these providers, who process data only on our behalf and under data processing terms:
- Railway Corporation: hosting and database. Our servers and database are in Railway's EU West region (Amsterdam, the Netherlands).
- Sentry (Functional Software, Inc.): error monitoring. Error reports contain your store address and technical details of the error, not IP addresses, what you send or access tokens.
Railway and Sentry are based in the United States; where they transfer personal data there, their data processing terms include the safeguards data protection law requires, such as standard contractual clauses.
Support emails: our domain registrar, Namecheap, forwards the emails you send to support@pidready.com to Gmail (Google), where we read and answer them. Namecheap and Google handle these emails under their own terms and privacy policies.
PIDReady works through Shopify, which handles your store's data under its own terms and privacy policy. We may also disclose information when the law requires it.
How long we keep it
- Store details, product data and access credentials: while PIDReady is installed.
- History of changes: 30 days. Imported files: 7 days.
- Catalogue scans: 90 days (the latest one is kept while PIDReady is installed). Records of background tasks: 3 to 30 days.
- When you uninstall PIDReady, its access tokens are deleted at once. Shopify asks us to erase your store's data 48 hours later and we delete everything we hold about your store then (if that request never arrives, we delete it after 30 days). The values you saved in Shopify stay in your store.
- Database backups: deleted automatically after at most 90 days.
- Server logs: up to 30 days. Error reports: up to 90 days.
- Support emails: up to two years after the conversation ends.
- Billing records: as long as UK tax law requires.
Your customers
PIDReady does not process personal data about your customers. Shopify's privacy requests about customer data (data requests and erasure) are answered automatically: there is nothing to return or delete.
Security
All connections use HTTPS. Access tokens are encrypted in the database (AES-256-GCM), and each store's data is kept separate and deleted as a whole. Access to the systems that hold your data is limited to us.
Your rights
Under UK and EU data protection law you can ask us for a copy of your personal data, and ask us to correct or delete it, to limit or stop using it, or to send it to you or someone else in a common format. Email support@pidready.com and we will reply within one month. Uninstalling PIDReady deletes your store's data as described above.
If you are unhappy with how we handle your data, please tell us first. You can also complain to the Information Commissioner's Office (ico.org.uk) or, in the EU, to the data protection authority where you live or work.
Changes to this policy
We will post any changes on this page and update the date at the top.