Privacy policy
Last updated: 2026
Keyline is a Shopify app that converts supplier invoices, order confirmations, and packing slips into Shopify purchase-order import files. It is installed on a merchant's Shopify store through Shopify's authorization flow.
Data we process
- Store data: the store's myshopify.com domain, an encrypted API access token, granted scopes, and plan/subscription status (to enforce free-tier and AI usage limits).
- Catalogue data: product variant identifiers (ID, SKU, barcode) read from Shopify to match supplier lines. No other product fields are stored.
- Supplier documents: the files the merchant uploads. We extract line items (supplier code, barcode, description, quantity, unit cost, source snippet). We do not store the original uploaded file; PDFs are processed in memory.
- Usage counters: documents processed and AI pages used per period.
We do not collect or store customer personal data from the merchant's store.
How we use it
To match supplier lines to the merchant's variants, produce a purchase-order import CSV, and remember supplier-code mappings the merchant confirms. We do not sell data and do not use it for advertising.
AI processing (opt-in)
When AI PDF extraction is enabled, the document's text or rendered page images are sent to Google's Gemini API to extract line items. This is off by default and can be disabled at any time. No document is sent to the AI provider unless the feature is enabled.
Subprocessors
- Shopify - app platform, authentication, billing.
- Google (Gemini API) - AI extraction, only when enabled by the merchant.
- Hosting provider - application and database hosting.
Retention and deletion
Extracted line items and supplier mappings are retained while the app is installed. Raw
uploaded files are not retained. On uninstall we revoke the stored token; on a Shopify
shop/redact request we delete all data for that store. Because we hold no
customer personal data, customers/redact and customers/data_request
requests are acknowledged with nothing to return. Merchants can request deletion via the
support contact.
Your rights
Merchants may request access to, correction of, or deletion of their data via the support contact. Customer requests are handled by the merchant through Shopify.
Security
Access tokens are encrypted at rest. We verify Shopify webhook signatures and use HTTPS for all traffic.
Contact
Email: keyline.app@proton.me
Legal entity and postal address to be added before publication.