Last updated: July 1, 2026
Who is responsible
Preflights is responsible for the personal data processed through this service. Privacy and data-rights requests can be sent to hello@preflights.app.
Catalog inspections
- Uploaded supplier and Shopify files: the raw upload is validated and used only to run that inspection. The web server may buffer it temporarily while handling the request, but Preflights does not copy it into the product database or object storage and does not retain it after processing.
- Derived report: Preflights stores the parsed findings, score, and report metadata in its database so the private report link works and paid details can be revealed.
- Optional report email: if you ask us to email the link, the address is stored with that report and sent to our email provider.
- Retention: report data and the stored report email are automatically deleted 90 days after the inspection is created. The report link then stops working.
Report links are unguessable capability links, but anyone you share one with may be able to view the same free or paid report state. Treat the link as confidential.
Shopify app
- What we access: when you install the Preflights Shopify app, you grant read-only
read_productsaccess. The app reads your product titles, SKUs, prices, and inventory quantities via Shopify's Admin API to cross-check the file you're about to import (price changes, removed SKUs). It requests no write access and never modifies your store. - Access token: Shopify issues an access token so the app can make those read calls. We store it server-side as a credential (never exposed to the browser) and use it only for the product reads and billing checks above.
- No customer data: the app does not access, request, or store any of your customers' personal information — only your products and the token.
- Uninstall & deletion: on uninstall, Shopify sends an
app/uninstalledwebhook and we delete the stored access token. Because we hold no customer data, Shopify's mandatory data-request/redaction webhooks (customers and shop) have nothing to return or erase; we acknowledge them and retain nothing. - Billing: the app's subscription is handled entirely by Shopify's Billing API. We never see or store your payment details — Shopify bills you and tells us only whether a subscription is active.
Payments and retained transaction records
If you purchase a report, PayPal processes the payment. Preflights stores the PayPal order identifier, payment state, and payment timestamp. The automatic 90-day report purge keeps this limited transaction metadata so one payment cannot be replayed against another report and so charges can be reconciled or disputed. Transaction records may also be retained where reasonably required for accounting, fraud prevention, or legal obligations.
Website and contact data
- A language preference is stored in local storage and a first-party cookie for up to one year.
- IP-derived request data is used for short abuse-prevention windows. Hosting and security providers may also create operational logs.
- If you use the contact/request form, Formspree processes the details you submit, such as email, store URL, role, and notes. We retain correspondence only as long as needed to answer the request, operate the relationship, or meet legal obligations.
Preflights currently does not run advertising trackers or behavioral analytics on these pages.
Why we process data
We process inspection and payment data to provide the service you request, take steps before entering a contract, secure the service, prevent fraud and abuse, and meet applicable legal obligations. Optional contact and report-link email data is used to respond to or deliver what you requested.
Service providers and locations
Preflights uses Cloudflare for the website, DNS, and edge security; Render for application hosting; Neon for the production database (configured in its EU-Central region); Resend for report-link email; PayPal for payments; and Formspree for the contact/request form. These providers process data under their own infrastructure and terms, and some processing may occur outside the EEA with the transfer mechanisms offered by those providers.
Your choices and deletion requests
You may ask to access, correct, or delete personal data associated with you, or object to/restrict certain processing where applicable. Email hello@preflights.app and include the report link or inspection ID when requesting early report deletion. We may ask for enough information to verify that the request is legitimate. You may also complain to your local data-protection authority.
Security and changes
We use HTTPS, access controls, server-side report gating, upload validation, and limited retention to reduce risk. No online service can promise absolute security. Material changes to this policy will be published here with a new date.