Privacy Policy

Last updated October 5, 2026

Draft — pending legal review. This document describes how the service works today, but it has not yet been reviewed by a lawyer and may change.

DropLy (“the service”, “we”) turns a product listing into a store page and publishes it to your own Shopify store. It is operated from Israel and is currently an invite-only beta. This policy says what data the service holds, why, who else processes it, how long it is kept, and how you can download or delete it. It describes the service as it is built today.

1. What we collect

  • Your Google account. When you sign in with Google we receive your email address, name and profile picture, and the identifiers and tokens Google issues for the sign-in, which we store to keep your sign-in linked to your account. We ask Google for your basic profile and email only.
  • Your invite. Which invite code you redeemed, and when.
  • Products you import. The link you paste (or the listing text you paste) and the public listing data fetched for it: title, description, prices, variants, photographs, and the supplier’s shipping options and costs to your store’s country. Photographs are copied into our own storage. We use publicly available product catalogue data only, from listings you choose to import. We do not build or maintain an independent product catalogue: imported data belongs to your account and is deleted with it, or on request.
  • What you make. Brand kits — including the contact email and social profile links you choose to show on your store pages — pricing settings (including whether you charge VAT, your payment fee and your minimum margin, which only the margin shown uses), whether you chose “set up shipping” on the publish screen and which of your shop's delivery profiles you chose for it, and pricing decisions (markups, the shipping method, exchange rates, sell prices), the stores the service generates, their text, your edits (including a name you give a store) and the customer reviews you add, enhanced versions of the product photographs, and the extra gallery pictures made for a store — a supplier photograph with its text cropped or cleaned off, and new shots made from the product’s main photograph — each marked with where it came from, and what making them cost — and any picture you upload yourself for one of a product’s choices, stored with the product’s other pictures.
  • Your Shopify connection. Your shop’s domain, the access token Shopify grants us and, where Shopify issues one, the refresh token that renews it (both stored encrypted, and never sent to your browser), when they expire, the permissions granted, your shop’s name and currency, and the countries your shop ships to. Your shop’s name is shown as your store’s name on its pages unless you give the store one. We ask Shopify only for permission to write products, write pages, write files, make the products we publish available on your Online Store sales channel, keep those products' variants stocked at your shop's location, each with the supplier's label as its SKU, and read your shipping profiles, to tell you when a product we published is in one that does not ship to your store's country, and to put a product's variants back into the shipping profile they were in when updating it moved them (never into one you did not choose, and nothing else in your shipping settings) — and, for shops connected through our original app, one page template to your theme. We do not ask for, and do not read, your orders or your customers. When you remove the app from your shop, Shopify tells us and we delete the access token at once; 48 hours later Shopify asks us to erase what we hold about the shop, and we delete the connection and the Shopify identifiers recorded on your stores. Until then we keep a note of each such notice: which one, for which shop, and when.
  • Usage and cost records. For every paid call made on your behalf to an AI or import provider: which provider and model, how much text or how many images were processed, the estimated cost, and the time. These run the daily spending allowance and our accounting.
  • Progress records. For each store you create, and each publish or pictures run you start: which steps it went through, when each began and finished, and — if it stopped — a short reason code. These are what the progress you see on screen is read from, and the step durations are what our time estimates are worked out from.
  • Technical data. Our hosting providers keep standard request logs, which include IP addresses. Error reports sent to our error monitoring carry internal identifiers — such as your account id — never your email address, and are scrubbed of access tokens, cookies, request contents and pricing details before they leave our servers.

2. Why we use it

  • To sign you in and keep your account secure.
  • To do what you ask: import a product, write its store page, prepare its pictures, and publish to your Shopify store — including the product’s supplier cost, converted at your store’s rate, into Shopify’s own “Cost per item” field, so Shopify can show you your margin.
  • To apply the daily spending allowance and prevent abuse.
  • To find and fix errors.
  • To answer you when you write to support.

We do not sell your data, we do not show advertising, and we do not use analytics or advertising trackers.

3. Who processes it for us

The service is built on these providers. Each receives only what its job needs.

ProviderWhat forWhere
Vercel Inc.Hosting the app; storing product picturesUnited States, global edge network
NeonThe databaseEuropean Union (Germany)
Railway Corp.The background worker that runs imports and generationUnited States
Google LLCSigning inUnited States
Shopify Inc.Publishing to your store, once you connect itCanada, United States
Anthropic PBCReading listings, writing store text, checking pictures — receives product data and photographsUnited States
OpenAI, L.L.C.Writing store text, when it is the model chosen for that instead of Anthropic — receives product data, and is asked not to keep itUnited States
Features & Labels Inc. (fal.ai)Enhancing pictures and making extra gallery pictures — receives product photographsUnited States
Apify Technologies s.r.o.Fetching the product listings you import — receives the linkCzech Republic (EU)
Functional Software Inc. (Sentry)Error monitoring — ids only, scrubbedEuropean Union (Germany)

Exchange rates come from the European Central Bank’s published reference rates; no personal data is sent to fetch them. When you import a product, the listing is read from the marketplace it is on (today, AliExpress).

4. Transfers outside Israel

Your data is stored and processed outside Israel, in the European Union and the United States. Where the law requires it, these transfers rely on the safeguards the providers offer, such as the European Commission’s Standard Contractual Clauses.

5. How long we keep it

  • Everything is kept for as long as your account exists.
  • When you delete your account, your data is deleted from our database at once and your product pictures from our storage. The usage and cost records remain, with nothing that identifies you, for our accounting.
  • Copies can remain for a limited time in our database provider’s restore history and in hosting and error-monitoring logs, until they are overwritten under those providers’ retention periods.
  • What you published to your Shopify store is yours, and deleting your account does not remove it. Since 24 September 2026 a published page’s pictures and fonts are copied into your shop’s own Files library and load from Shopify, so the page keeps working after your account is deleted. A page last published before then still loads its pictures from our storage and stops showing them once your account is deleted — publish it again first to move them into your shop.

6. Your rights and choices

  • Download your data at any time from the account menu (“Download my data”): a JSON file of everything your account holds, without access tokens.
  • Delete your account at any time from the account menu (“Delete my account”).
  • Ask us to access, correct or delete your data, or anything else about it, at roeinissim@gmail.com. If you cannot sign in, write from your account’s address and we will delete it on request.
  • You can also complain to a data protection authority — in Israel, the Privacy Protection Authority.

7. Cookies

Only cookies the service needs to work:

  • your sign-in session, and during sign-in a security token and the address to return to;
  • your choice of language;
  • while you connect Shopify, a short-lived security cookie (ten minutes) that checks the answer belongs to the request you started, and one of the same life holding the address of the screen to return to.

No analytics, advertising or third-party tracking cookies. Store pages published to your Shopify store are served by Shopify under its own cookies.

8. Your shoppers

We do not collect data about the people who visit your published store pages. Shopify serves those pages, and the pictures and fonts on them, from your own shop’s files. A page last published before 24 September 2026 loads its pictures from our storage provider, which sees each request as any web server does, until it is published again.

9. Children

The service is for businesses and is not meant for anyone under 18.

10. Security

Traffic is encrypted in transit. Shopify access tokens are encrypted at rest. Every account sees only its own data, and that is tested automatically before changes ship.

11. Changes

When this policy changes, the date at the top changes with it. If a change matters to how your data is used, we will tell you in the app or by email before it applies.

12. Contact

Questions or requests: roeinissim@gmail.com.