Privacy policy
Sourcely+ AI Product Importer · Last updated 15 August 2026
The short version
Sourcely handles product listings, not people. It stores no customer names, email addresses, orders, or payment details, and it never requests access to them.
What is stored
- About your store: your myshopify domain, store name, currency, primary domain, your subscription plan, and the settings you choose in the app.
- About your imports: the links you submit, and the product details read from them — titles, descriptions, image addresses, prices, SKUs, options and variants — together with a trimmed excerpt of the page text so a listing can be re-processed without fetching the page again.
- If you supply your own Groq API key: it is encrypted with AES-256-GCM before being written to the database. It is used only for your imports.
What is never stored
No customer personal data of any kind. Sourcely does not request the customer, order, or payment scopes from Shopify, so it has no technical means of reading them.
Pages you ask it to read
When you submit a link, Sourcely fetches that page from its own servers. Where the page publishes structured product data, that data is read directly and no third party is involved.
Where it does not, the page's visible text is sent to Groq so a language model can identify the product details. The same applies to the Pro plan's rewriting feature, which sends the product title and description. No information about your store, your customers, or your orders is included in those requests.
Product images are normally passed to Shopify as web addresses for Shopify to fetch. When a source site blocks that, Sourcely downloads the image and forwards it to Shopify directly. Image files are not retained on Sourcely's servers in either case.
Who else processes this data
- Render — application hosting (United States).
- Neon — the PostgreSQL database (United States).
- Groq — AI processing of page text, as described above.
- Shopify — your store, and the billing for this app.
Data is not sold, rented, or shared with anyone else, and it is not used to train AI models by Sourcely.
How long it is kept
Your data is kept while the app is installed. When you uninstall, Shopify sends a shop redaction request — normally within 48 hours — and everything belonging to your store is deleted at that point: settings, import history, and staged listings. You can also delete any staged listing yourself at any time from the review queue.
Products already published to your Shopify store belong to you and are unaffected by uninstalling.
Your rights
Sourcely responds to Shopify's GDPR webhooks. Because it holds no customer data, customer data requests and customer redaction requests have nothing to return or erase; shop redaction deletes your store's records as described above. To request a copy or deletion of your store's data at any other time, email paintersproservice@gmail.com.
Content you import
Product photographs and descriptions belong to whoever created them. Sourcely only imports from sources you have recorded an authorisation for — your own stores and brands, suppliers you hold an agreement with, products you are licensed to sell, or a rights holder's written permission. That declaration, including the domain and how you described the arrangement, is stored with your store's records and removed when you uninstall. Sourcely also honours robots.txt and will not read pages a site asks automated tools to leave alone. See the crawler information page for how site owners can block it.
Changes
Material changes to this policy will be announced in the app before they take effect.
Common questions
What the app imports, what it doesn't, and how content rights work is covered in the questions and answers.