Back to ImportFix AI

ImportFix AI

Privacy Policy

This policy explains what information ImportFix AI processes, why it is processed, where it is stored and what choices you have.

Last updated: 13 September 2026

1. Who operates ImportFix AI

ImportFix AI is an independent software project operated from Poland. For privacy questions, requests or complaints, contact us at importfix.app@gmail.com.

2. What the service does

ImportFix AI checks and prepares supplier CSV and XLSX files before they are imported into WooCommerce. Core file parsing and analysis take place in your browser. ImportFix does not automatically import products into your WooCommerce store.

3. Information we process

  • Google account information: when you sign in with Google, we receive the identifiers needed for authentication, including your Google account ID, email address and basic profile information such as your name or profile image. We request only the OpenID, email and profile scopes. We do not request access to Google Drive, Gmail, contacts or calendars.
  • Supplier files: CSV and XLSX file contents are parsed in your browser. The complete uploaded file is not automatically uploaded to our servers, OpenAI or your account database.
  • Account data: if you are signed in, supplier mapping profiles and confirmed supplier-to-WooCommerce SKU matches are stored in your account.
  • Supplier-history baselines: when you intentionally save a baseline while signed in, we store the supplier profile reference, save time, tracked fields and the product SKU, name, regular price and stock values available for comparison. Fields that are not mapped for tracking are not included as tracked values.
  • Optional AI mapping data: only when you select “Suggest with AI” do we send the selected column name, a small set of sample values and the available WooCommerce target fields to OpenAI. We do not send the complete supplier file through this feature.
  • Technical data: our hosting and authentication providers may process IP address, browser, device, request, diagnostic and security information needed to deliver and protect the service.
  • Support messages: we process the information you choose to include when contacting us.

4. How and why we use information

  • to authenticate users and maintain secure sessions;
  • to store and synchronise supplier settings, saved matches and baselines requested by the user;
  • to provide optional AI-assisted mapping;
  • to maintain security, prevent abuse, diagnose errors and enforce usage limits;
  • to respond to support and privacy requests; and
  • to comply with legal obligations.

Depending on the context and applicable law, processing is based on providing the service you request, our legitimate interests in operating and securing the service, your consent or deliberate request for optional features, and compliance with legal obligations.

5. Local browser storage and cookies

ImportFix uses strictly necessary authentication cookies to keep signed-in sessions working. When you use the service without signing in, mapping profiles, supplier-history baselines and confirmed SKU matches may be stored in your browser's local storage. You can remove local data through your browser settings. Blocking necessary cookies may prevent sign-in from working.

6. Service providers

We use the following providers to operate ImportFix. They process information under their own terms and privacy commitments and, where applicable, on our behalf:

  • Vercel — application hosting, delivery and technical logs;
  • Supabase — authentication and account database;
  • Google — optional Google sign-in; and
  • OpenAI — optional AI-assisted column mapping.

OpenAI API requests are made with response storage disabled. OpenAI states that API data is not used to train its models by default unless the customer explicitly opts in. Standard abuse-monitoring logs may nevertheless retain submitted API content for up to 30 days, unless a longer period is required for legal or safety reasons.

7. International processing

Some service providers may process information outside your country, including outside the European Economic Area. Where required, transfers are handled using recognised legal safeguards provided by the relevant service provider.

8. Retention and deletion

  • Account mapping profiles, saved matches and supplier-history baselines are retained until you delete the relevant supplier profile, delete your account or request deletion, subject to limited backup, security and legal retention.
  • Local browser data remains until it is removed by you, by ImportFix functionality, or by your browser.
  • Authentication and infrastructure logs are retained according to operational, security and provider requirements.
  • OpenAI's standard API abuse-monitoring retention may be up to 30 days as described above.

Until self-service account deletion is available, email us from the address associated with your account to request account access or deletion. We may need to verify your identity.

9. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of your data, withdraw consent, or appeal a decision. You may also complain to your local data-protection authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO).

You can also manage or revoke ImportFix's Google access from your Google Account connections page.

10. Security

We use reasonable technical and organisational safeguards, including encrypted transport, authenticated access and database row-level access controls. No internet service can guarantee absolute security, so you should avoid uploading unnecessary personal or confidential information.

11. Children

ImportFix is a business-oriented tool and is not intended for people under 18. We do not knowingly seek personal information from children.

12. Changes to this policy

We may update this policy as the service changes. We will publish the revised version here and update the date above. Material changes may also be communicated through the service where appropriate.

13. Contact

Privacy requests: importfix.app@gmail.com