Privacy Policy
Operator: Hive Data Security
Contact: info@discogsimporter.app
Last updated: 28 September 2026
Discogs Importer (the “App”) helps merchants create Shopify products using metadata fetched from Discogs, and can optionally help connect Shopify products with the merchant’s Discogs Marketplace inventory. On Premium, a merchant may also choose to create a Shopify order from an eligible Discogs Marketplace order. This policy explains what data we access, what we store, and how it’s used.
Data we access
- Shopify: product read access for duplicate detection; product/metafield write access to create or update products at merchant request; inventory and location access for Stocktake, merchant-reviewed quantity corrections, and enabled Sync workflows that queue linked Discogs inventory updates after Shopify stock changes. If the merchant separately approves and enables complete order import, the App uses optional order access to create and verify the corresponding Shopify order, including its delivery address.
- Discogs: search queries and release metadata returned by Discogs for the selected release. If the merchant enables Sync, the App may also use the merchant’s Discogs API token to access their Discogs Marketplace inventory and orders. Complete-order import reads the buyer username, delivery name and address, item prices, shipping charge, order status and timestamps needed to create the selected Shopify order.
Data we store
- Shop domain and installation/session identifiers.
- Shopify access tokens required to operate the App (stored securely).
- Optional Discogs API tokens for Sync features, stored encrypted and removable by the merchant.
- Usage counters for product improvement, billing, and abuse prevention. On public website pages, Google Analytics measures page views, limited campaign identifiers, and clicks to our Shopify App Store listing. It does not measure activity inside the embedded app or private admin and scanner pages. Analytics events do not include customer personal data, Discogs tokens, product titles, search text, or Shopify embedded app query strings. Referrer query strings and URL fragments are removed. Google signals and advertising personalization are disabled.
- Basic operational logs (timestamps, success/error codes) for reliability and support.
- For enabled complete-order import, an account-scoped Discogs order ID, the resulting Shopify order ID and state, and a one-way integrity digest used to detect later order changes. The App does not retain the buyer’s raw name, delivery address, instructions, email address or phone number in this claim or its operational logs.
- Stocktake inventory snapshots and scans, staff names and assigned sections, physical-record notes, optional private record photos, and review history. Stocktake photos remain private in DI; selected photos are copied to Shopify products only with merchant approval.
Webhooks
The App registers Shopify webhooks for lifecycle events (e.g., app/uninstalled, scopes update), product/inventory updates, and paid orders to manage installation state, revoke access tokens where applicable, and support merchant-enabled Sync workflows.
How we use data
- Authenticate the merchant and operate the embedded app.
- Perform searches and display results.
- Create draft or live products at the merchant’s request.
- Sync linked Discogs Marketplace inventory when the merchant enables it.
- Create and verify a Shopify order from an eligible Discogs Marketplace order when a Premium merchant separately enables complete-order import. The delivery details are sent directly to Shopify for that purpose and are not used for marketing.
- Detect duplicates and enforce plan limits.
- Troubleshoot errors and improve reliability.
Sharing
We do not sell personal information. We share data only with service providers required to operate the App (e.g., hosting/database), and only to the extent necessary.
Retention
We retain minimal operational data only as long as needed to provide the service, support billing periods, and handle support/legal needs. Uninstalling the App revokes access via Shopify. Stocktake records and photos do not expire automatically. Deleting a saved count removes its associated evidence and review history; uninstall and Shopify shop-redaction webhooks remove the shop’s stocktake data and imported order claims. Orders already created in Shopify are then managed and retained by the merchant in Shopify. Images already copied to Shopify products are also managed in Shopify.
Deletion requests
You can uninstall the App at any time in Shopify. If you want deletion of retained operational data, email info@discogsimporter.app and include your shop domain.