The short version. The live demo on this website processes your files entirely inside your own browser — those files are never uploaded to us. If you join the waitlist we store your email address. If you install the Shopify app, we store your store's product data so we can validate it and undo changes. We don't sell anything to anyone, and we don't collect data about your customers.
DatumFeed is operated by Sean Miller, a sole trader based in Australia. You can reach a human at info@datumfeed.app.
1. The website
Waitlist form. If you join the early-access list we collect your email address, and optionally your store name, approximate SKU count, and any notes you choose to write. We use this only to contact you about DatumFeed and to decide what to build. Form submissions are processed by Formspree, who deliver them to our inbox.
Analytics. We use Cloudflare Web Analytics, which is privacy-first: it sets no cookies, does not fingerprint visitors, and does not track people across sites. We see aggregate page views, not individuals.
Hosting. This site is served by Cloudflare. Their edge servers process standard request data (such as IP address) to deliver pages and block abuse.
2. The live demo
Files you drop into the demo never leave your computer. The demo runs the DatumFeed engine as JavaScript inside your browser. Your spreadsheets are read in local memory, processed on your own machine, and discarded when you close the tab. Nothing is uploaded, stored, or transmitted to us — there is no server involved in demo processing at all.
3. The Shopify app
When you install DatumFeed on a Shopify store, we store the following so the app can do its job:
- Store identity and access. Your store's domain and the access token Shopify issues so we can read and write product data on your behalf.
- Supplier files you upload. The rows we parse from them, including part numbers, descriptions, prices, quantities and supplier names.
- Product data from your store. SKUs, barcodes, prices, inventory quantities, and product/variant IDs — used to compare your file against your catalogue and work out what changed.
- Sync records and snapshots. Before we change anything, we record the previous value of every product we're about to touch. This is what makes one-click Undo possible.
- Your settings. Pricing rules, supplier profiles, and any scheduled feed URLs you configure.
We do not collect data about your customers. DatumFeed requests permission for products and inventory only. It cannot read your orders, your customers, or your storefront theme — Shopify enforces this, not just our good intentions.
4. What we never do
- We don't sell, rent, or share your data with anyone for marketing.
- We don't use your product data or supplier files to train AI models. DatumFeed contains no AI in its processing path at all.
- We don't send you marketing you didn't ask for.
If you email us a supplier file to test, we treat it as confidential: it is used only to make sure the engine handles your data, is never shared or published, and is deleted on request.
5. How long we keep things
- Sync snapshots: retained for the most recent syncs (currently the last 10 syncs or 30 days, whichever comes first), then deleted. They exist so you can undo.
- App data: deleted when you uninstall the app. Shopify notifies us of the uninstall and we remove your store's sessions, uploads, sync history and settings.
- Waitlist emails: kept until you ask us to remove you, or until the waitlist is closed.
6. Who else touches the data
We use a small number of service providers to run DatumFeed. Each processes data only to provide their service to us:
- Shopify — the platform the app runs on and the source of your product data.
- Cloudflare — website hosting, DNS, and email forwarding for
@datumfeed.appaddresses. - Formspree — waitlist form delivery.
- Application hosting and database providers — used to run the app server and store the data described in section 3.
7. Your rights
You can ask us to show you what we hold about you, correct it, or delete it. Email info@datumfeed.app and we'll action it — there's no ticketing system, you're emailing the person who built this.
If you're in the EU or UK, you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection. If you're in Australia, the Australian Privacy Principles apply. Merchants can also trigger deletion at any time simply by uninstalling the app.
8. Security
Data is transmitted over HTTPS, access tokens are stored server-side and never exposed to the browser, and the app requests the narrowest Shopify permissions it can do its job with. No system is perfectly secure, but we keep the amount of data we hold deliberately small — the less we store, the less there is to lose.
9. Changes
If this policy changes materially we'll update the date at the top and, for anything significant, tell active merchants by email.
This policy is written to be understood rather than to be impressive. It is not legal advice, and it may be updated as DatumFeed grows.