Order Import from CSV

Privacy policy

Order Import from CSV is a Shopify app that creates orders or draft orders from a CSV file. This policy explains what data the app accesses in your store, what it keeps, and how to get it removed.

App
Order Import from CSV for Shopify
Publisher
NutSoft Consultants Limited, United Kingdom
Effective
6 October 2026

Who this policy covers

It covers merchants who install the app and the information about their customers that passes through it. The merchant decides what goes in the CSV and remains the controller of that customer data; NutSoft Consultants Limited processes it only to carry out the import the merchant asks for.

What the app stores

The app keeps one record per installed store, so that it can call the Shopify Admin API on your behalf:

  • your store's myshopify.com domain
  • the API access token Shopify issues to the app, its expiry and refresh token
  • the list of permissions you granted

That is the only database table the app has. It does not keep import history, uploaded files, customer records, order records or product data. There is no account to create and no password to store.

What happens to your CSV

The file is read and parsed in your browser. It is never uploaded as a file and never written to our servers, storage or database. From the parsed rows, two kinds of request go to our server and on to Shopify:

  • a lookup request containing the customer emails, SKUs, barcodes and country codes from the file, so that rows can be matched against your customers, products and shipping methods before anything is created
  • create requests, in batches, containing the order rows you confirmed: customer email, billing and shipping names, addresses and phone numbers, line items and quantities, shipping method, and any tags, notes or discount you chose

Our server processes each request in memory, forwards the data to your store through the Shopify Admin API, and returns the result to your browser. Nothing from these requests is retained once the response is sent.

Store data the app reads and writes

The app asks for these Shopify permissions, and uses each one only as described:

  • read_customers, write_customers: to match the Customer Email column to existing customers, and to let Shopify create a customer when there is no match
  • read_products: to match SKUs and barcodes to active product variants and to show titles and prices while you review
  • read_shipping: to validate the Shipping Method column against the delivery methods and countries configured in your store
  • write_draft_orders: to create each imported row as a draft order
  • read_orders, write_orders: to complete draft orders into orders when you import in Orders mode

Orders, draft orders and customers created by an import belong to your store and live in Shopify. The app has no copy of them, and uninstalling the app does not remove them.

Where data is processed

The app runs on Vercel and its database is hosted by Neon. Both act as our processors and store data in their data centres under their own security programmes. Error logs produced while an import runs are kept by Vercel for a short period (currently up to one day) and then deleted automatically. These logs record which step failed and why; they are not meant to contain customer details, although a failed Shopify request may include the row that caused it.

We use no analytics, advertising, tracking cookies, email marketing or AI services in the app. The embedded app relies on Shopify's session token to identify your store; it sets no cookies of its own.

Retention and deletion

  • CSV data: not retained. It exists only in your browser and in memory while a request is processed.
  • Store record: kept while the app is installed and deleted automatically when you uninstall it.
  • Error logs: deleted automatically by Vercel after its retention window.

The app implements Shopify's mandatory privacy webhooks. When Shopify sends a customer data request or customer redaction request, there is nothing to export or erase because the app holds no customer data. When a store is redacted after uninstall, any remaining store record is removed.

Your rights

Merchants can request a copy or deletion of anything we hold about their store at any time. Customers of a merchant should direct requests to that merchant, who controls the data; we will help the merchant respond. UK and EU data protection law also gives you the right to complain to your supervisory authority, which in the UK is the Information Commissioner's Office.

Changes to this policy

If the app starts storing new kinds of data or using new providers, we will update this page and its effective date and note the change in the app listing.

Contact

NutSoft Consultants Limited
giles@nutsoft.co
Order Import from CSV support