Privacy policy
Last updated 2026-10-07.
This policy explains what data Vexlyst's Shopify apps use, why, how long it's kept and who processes it. Vexlyst apps are published by Randall Rist (“Vexlyst”, “we”), which is responsible for this data. Contact us at support@vexlyst.com.
Who this applies to
Merchants who install a Vexlyst app from the Shopify App Store, and visitors to this website. Our apps work with your store's data on your behalf; they don't collect data about your customers.
Data each app uses
Vexlyst PO Importer
What it reads from your Shopify store
- Read access to products (scope read_products): product variant IDs, titles, SKUs, barcodes and whether inventory is tracked, used only to match supplier lines to your products.
What it stores, and for how long
| Data | Kept |
|---|---|
| Uploaded supplier file contents (the rows of the file; the file itself is not kept) and the import lines built from them, including supplier SKUs, descriptions, quantities, costs and the matched product variants. | The raw rows are deleted when you download the purchase-order file; the remaining import contents are deleted automatically once they are 7 days old (a daily cleanup). Only counts (for example, the number of lines) remain as import history. |
| Your suppliers' names, each supplier's column mapping, the supplier SKUs you have matched to your products, and the last unit cost exported for each matched product. | While the app is installed, so repeat imports match automatically. |
| Your store's myshopify.com domain and the access token Shopify issues to the app. | While the app is installed. |
What it doesn't collect
- No customer or order data.
- No payment details (billing is handled entirely by Shopify).
- No cookies or tracking in your browser.
Uninstalling and deletion
When you uninstall an app, its access token for your store is deleted immediately. Shopify
then sends us a data-deletion request (shop/redact) 48 hours after the uninstall, and
we delete everything the app stored for your store when we receive it. You can also ask us to
delete your data at any time by emailing support@vexlyst.com from the email address on
your Shopify account.
Shopify may also send us requests about your customers' data (customers/data_request
and customers/redact). Our apps don't store customer data, so there is nothing to
return or delete; we acknowledge these requests.
Product analytics
We use PostHog to understand how the apps are used, so we can improve them. Events are sent from our servers, not your browser, and contain only: your store's myshopify.com domain, which app and version sent it, the name of the step (for example “file uploaded”), and counts, yes/no values and the file type (CSV or Excel). They never contain file contents, file names, product or supplier names, SKUs, barcodes, prices or costs, or customer data. IP addresses are discarded and events aren't geolocated. This website has no analytics.
Cookies
Neither the apps nor this website set tracking or advertising cookies. The apps run inside your Shopify admin and use Shopify's session tokens to authenticate you.
Service providers
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosts the apps and this website; keeps short-lived request logs. | United States |
| Supabase | Hosts the apps' database (on Amazon Web Services). | United States |
| PostHog | Product analytics (see “Product analytics” below). | United States |
| Cloudflare | DNS for vexlyst.com and routing of email sent to our addresses. | Global |
Shopify provides the platform the apps run on and handles all billing; Shopify's own privacy policy applies to that. We don't sell or rent data, and we don't share it for advertising.
Security
Data is sent over encrypted connections (TLS), including to our database. Each app has its own database credentials that can reach only that app's data, and credentials are kept in our hosting provider's encrypted secret storage.
Your rights
You can ask us what data we hold about your store, to correct it, or to delete it, by emailing support@vexlyst.com. We respond within 30 days.
Changes
We'll update this page when our data practices change and change the date at the top.