Privacy policy
Last updated: 23 September 2026
Stison Connector ("the app") is provided by Session Apps ("we", "us"). This policy explains what information the app stores when you install it in your Shopify shop, why, and for how long.
Customer data
The app stores no data about your customers. It doesn't read or keep names, email addresses, postal addresses, orders or payment details.
If you turn on Markets, a check runs inside Shopify's checkout to stop an edition being sold to a country it has no rights in. It looks at the delivery country, or the country the customer is shopping from, at the moment of checkout. Nothing from that check is sent to us or stored.
Shop data we store
- Product feed files. The title data files your Stison account sends to the app. We keep each file for 7 days, then delete it.
- A file history. A record of each file received: its name, size, when it arrived and was processed, and a summary of the result (counts and any errors). This is what the app's dashboard shows you.
- Settings. Your choices in the app, such as whether it writes to your shop or is in dry run, whether Markets is on, and any fields you add.
- An SFTP login. The username and password Stison use to deliver files to the app.
- Shopify access. The access key Shopify gives the app when you install it, so it can update your products.
The app also writes to your Shopify shop itself (products, author entries, images and related details). That data is held by Shopify under your agreement with them, not by us.
Why we store it
Only to run the app: to receive files from Stison, update your shop from them, and show you what happened. We don't sell or share this data, and we don't use it for advertising.
Where it's stored
The app and its data are hosted on Railway in the EU (Amsterdam, the Netherlands).
How long we keep it
- Feed files: 7 days.
- Everything else: for as long as the app is installed.
When you uninstall, the SFTP login is switched off straight away. 48 hours after you uninstall, Shopify asks us to delete your shop's data (Shopify's "shop redact" request). When that request arrives we permanently delete the SFTP login, any feed files still held, the file history and your settings.
Your rights
You can ask us what data we hold about your shop, or ask us to correct or delete it, by emailing session-apps@proton.me. If you're in the UK or EU you also have the right to complain to your data protection authority (in the UK, the Information Commissioner's Office).
Changes to this policy
If we change this policy, we'll update the date at the top of this page.
Contact
Session Apps
session-apps@proton.me