← DupeSweepPrivacy Policy
Last updated 6 September 2026
DupeSweep (“the app”, operated by Prince Sinha) helps Shopify merchants find and safely remove duplicate products. This page explains exactly what the app stores, why it needs it, and how long it keeps it.
The short version. The app reads your product catalog and nothing else. It never accesses customer records, orders, or payment data, and it does not request the permissions that would allow it to. It stores no personal information about your shoppers.
What the app accesses
The app requests exactly two Shopify permissions: read_products and write_products. Read access is what lets it find duplicates; write access is what lets it archive one, and undo that archive. It requests no other scopes, so it is technically incapable of reading customers, orders, inventory locations, finances, or anything else in your store.
What the app stores
- Your shop domain and an access token, so the app can talk to your store on your behalf.
- A mirror of your product catalog — product titles, handles, status, vendor, and product type; variant SKUs, barcodes, and inventory counts; and product image URLs with their dimensions. This mirror is what duplicate detection runs against, so scans are fast and do not hammer the Shopify API.
- Image fingerprints, not images. To detect the same photo uploaded at two resolutions, the app downloads each product image, computes three short hashes from it, and discards the image. It stores the hashes and the file size. It never stores your image files.
- Scan results — which products were grouped as possible duplicates, the confidence score, and the reason.
- A snapshot before every change. This is the app’s core safety promise: before archiving anything, it saves a full copy of that product (its fields, variants with prices, image URLs, metafields, collections, and SEO settings) so the change can be undone exactly. If your product metafields contain data you consider sensitive, it will be inside these snapshots.
- An audit log of every change the app made, and any groups you asked it to stop showing you.
What the app never stores
No customer names, emails, addresses, or phone numbers. No orders, carts, or checkouts. No payment or card data. No shopper browsing behaviour, and no tracking scripts added to your storefront. The app has no access to any of it.
Who else sees your data
The app runs on Google Cloud Run (United States) and stores its data in a Neon PostgreSQL database (United States). Those two providers, and Shopify itself, are the only third parties involved. Your data is never sold, rented, shared for advertising, or used to train machine-learning models.
How long it is kept
- On uninstall: your access token is deleted immediately, and the app can no longer reach your store.
- 48 hours after uninstall: Shopify sends a shop-redaction request and the app deletes everything else it holds for your store — catalog mirror, scan results, snapshots, and audit log.
- Customer-data requests: Shopify’s mandatory customer data and redaction webhooks are implemented and verified. Because the app holds no customer data, there is nothing to return or erase in response to them.
Your rights
You can uninstall at any time from your Shopify admin, which starts the deletion above. If you want your data deleted sooner, or want a copy of what the app holds for your store, email princesinha7072@gmail.com and it will be handled within 30 days.
Changes to this policy
If what the app stores changes, this page changes with it and the date above is updated. Material changes will be announced in the app before they take effect.
Contact
Questions about privacy: princesinha7072@gmail.com.