Order Import from CSV
Privacy policy
Order Import from CSV is a Shopify app that creates orders or draft orders from a CSV file. This policy explains what data the app accesses in your store, what it keeps, and how to get it removed.
- App
- Order Import from CSV for Shopify
- Publisher
- NutSoft Consultants Limited, United Kingdom
- Effective
- 6 October 2026
Who this policy covers
It covers merchants who install the app and the information about their customers that passes through it. The merchant decides what goes in the CSV and remains the controller of that customer data; NutSoft Consultants Limited processes it only to carry out the import the merchant asks for.
What the app stores
The app keeps one record per installed store, so that it can call the Shopify Admin API on your behalf:
- your store's myshopify.com domain
- the API access token Shopify issues to the app, its expiry and refresh token
- the list of permissions you granted
That is the only database table the app has. It does not keep import history, uploaded files, customer records, order records or product data. There is no account to create and no password to store.
What happens to your CSV
The file is read and parsed in your browser. It is never uploaded as a file and never written to our servers, storage or database. From the parsed rows, two kinds of request go to our server and on to Shopify:
- a lookup request containing the customer emails, SKUs, barcodes and country codes from the file, so that rows can be matched against your customers, products and shipping methods before anything is created
- create requests, in batches, containing the order rows you confirmed: customer email, billing and shipping names, addresses and phone numbers, line items and quantities, shipping method, and any tags, notes or discount you chose
Our server processes each request in memory, forwards the data to your store through the Shopify Admin API, and returns the result to your browser. Nothing from these requests is retained once the response is sent.
Store data the app reads and writes
The app asks for these Shopify permissions, and uses each one only as described:
read_customers, write_customers: to match the Customer Email column to existing customers, and to let Shopify create a customer when there is no matchread_products: to match SKUs and barcodes to active product variants and to show titles and prices while you reviewread_shipping: to validate the Shipping Method column against the delivery methods and countries configured in your storewrite_draft_orders: to create each imported row as a draft orderread_orders, write_orders: to complete draft orders into orders when you import in Orders mode
Orders, draft orders and customers created by an import belong to your store and live in Shopify. The app has no copy of them, and uninstalling the app does not remove them.
Where data is processed
The app runs on Vercel and its database is hosted by Neon. Both act as our processors and store data in their data centres under their own security programmes. Error logs produced while an import runs are kept by Vercel for a short period (currently up to one day) and then deleted automatically. These logs record which step failed and why; they are not meant to contain customer details, although a failed Shopify request may include the row that caused it.
We use no analytics, advertising, tracking cookies, email marketing or AI services in the app. The embedded app relies on Shopify's session token to identify your store; it sets no cookies of its own.
Retention and deletion
- CSV data: not retained. It exists only in your browser and in memory while a request is processed.
- Store record: kept while the app is installed and deleted automatically when you uninstall it.
- Error logs: deleted automatically by Vercel after its retention window.
The app implements Shopify's mandatory privacy webhooks. When Shopify sends a customer data request or customer redaction request, there is nothing to export or erase because the app holds no customer data. When a store is redacted after uninstall, any remaining store record is removed.
Your rights
Merchants can request a copy or deletion of anything we hold about their store at any time. Customers of a merchant should direct requests to that merchant, who controls the data; we will help the merchant respond. UK and EU data protection law also gives you the right to complain to your supervisory authority, which in the UK is the Information Commissioner's Office.
Changes to this policy
If the app starts storing new kinds of data or using new providers, we will update this page and its effective date and note the change in the app listing.
Contact
NutSoft Consultants Limited
giles@nutsoft.co
Order Import from CSV support