Contents
1. Who we are
Store Shift is a data migration application for Shopify that moves store data from WooCommerce into Shopify. It is a product of Webnday Pvt. Ltd ("we", "us"), which is the data controller for the purposes of this policy. This page explains what we do with data when you install and use the app.
Contact for any privacy matter: support@webnday.com.
When we migrate your store data, you are the controller of that data and we act as a processor on your instructions — we only move what you select, when you tell us to.
2. Data we read from your stores
To perform a migration we read the following in transit:
From your WooCommerce store (via the REST API, using credentials you provide)
- Products — titles, descriptions, SKUs, prices, stock, weights, images, attributes, variations, tags, categories, brands and custom
meta_data. - Product categories — names, descriptions and images.
- Customers — first and last name, email address, phone number and billing/shipping addresses.
- Orders — line items, totals, currency, order status, dates, shipping lines and the billing/shipping addresses attached to each order.
From your Shopify store (via the Admin API, using the token granted at install)
- Your shop domain, shop name and contact email.
- The primary location ID, needed to set inventory quantities.
- The IDs of records we create, so we can update them instead of duplicating them later.
We do not read Shopify data beyond what the granted scopes allow, and we do not browse your store for any purpose other than completing the migration you requested.
3. Data we actually store
Only the following is written to our database:
| What | Why |
|---|---|
| Shopify shop domain, shop name, email | To identify your account and contact you about your migrations |
| Shopify access token (encrypted) | To write the migrated records into your store |
| WooCommerce store URL, consumer key and secret (encrypted) | To read your source data |
| Migration records — which entities you selected, options, timestamps, status | To run and report on the migration |
| ID mapping table — WooCommerce record ID → Shopify record ID | So re-running never duplicates anything |
| Progress counters and logs, including error messages returned by Shopify | So you can see what failed and why, and retry it |
| Support tickets you send us, and the email address you give for them | To answer you |
| Your subscription plan and Shopify charge ID | To apply the right plan limits |
4. What we deliberately do not store
- We do not keep a copy of your product catalogue.
- We do not keep a copy of your customer list, their addresses or their order history.
- We do not store customer passwords — WooCommerce password hashes cannot be migrated to Shopify and we never request them.
- We do not store payment card details. Billing is handled entirely by Shopify; we never see your card.
- We do not use tracking cookies, advertising pixels or third-party analytics on the app.
Your records pass through our servers in memory during a migration and are written to your Shopify store, not ours. What remains afterwards is the ID mapping described above.
5. Why we process it
- To perform the contract with you — running the migrations you request.
- Legitimate interests — keeping the service secure and working, diagnosing failures, preventing abuse.
- Legal obligation — retaining billing records where required.
6. Sharing and sub-processors
We do not sell, rent, licence, publish or trade your data. We do not share it with advertisers, data brokers, AI training providers or any other third party. No one buys access to it, and we do not use your store data to build products for anyone else.
The only parties that touch your data are the ones needed to run the service:
| Provider | Role |
|---|---|
| Shopify Inc. | The destination of your migration, and our billing processor |
| Your WooCommerce host | The source of your data — your own infrastructure |
| Our hosting provider | Runs the application servers and database |
| Our email provider (SMTP) | Delivers migration notifications and support replies |
We will disclose data if legally compelled to do so by a valid order from a competent authority. If that ever happens we will tell you, unless we are legally prohibited from doing so.
7. How long we keep it
- While the app is installed — credentials, mappings, migration history and logs are kept so you can re-run and audit migrations.
- When you uninstall — Shopify notifies us and we mark the shop as uninstalled and stop all processing immediately.
- Shop redaction — when Shopify sends the
shop/redactrequest (normally 48 hours after uninstall), we delete the shop's data, including the encrypted credentials, mappings and logs. - Customer redaction — we act on Shopify's
customers/redactandcustomers/data_requestrequests as required. - Billing records — retained only as long as required for accounting and tax purposes.
You do not need to wait for a webhook: you can ask us to delete everything at any time (section 9).
8. Security
- All WooCommerce keys and Shopify tokens are encrypted at rest and are never returned to the browser in full — they are shown masked.
- All traffic is over HTTPS.
- Every Shopify webhook and OAuth callback is HMAC-verified before it is accepted.
- Every database query is scoped to a single shop, so one merchant's data cannot be reached from another's session.
- Shopify offline access tokens are short-lived and refreshed automatically.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority as required by law.
9. Your rights and deletion requests
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Have it corrected or deleted
- Restrict or object to processing
- Receive it in a portable format
- Complain to your local data protection authority
To exercise any of these, email support@webnday.com from the address associated with your store, or open a ticket from the Support page inside the app. We respond within 30 days, and usually much sooner.
The fastest way to delete everything is to uninstall the app from your Shopify admin — that starts the deletion process automatically.
10. If you are a customer of a merchant
If you shopped at a store that used Store Shift, we processed your details only to copy them from that merchant's WooCommerce store into their Shopify store, on their instruction. We are a processor; the merchant is the controller. Please direct access or deletion requests to the merchant. If you contact us directly we will pass your request to them and assist.
11. Children
Store Shift is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.
12. Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes will be announced inside the app before they take effect.
13. Contact
Questions about privacy, or a deletion request:
support@webnday.com
Or use the contact form.