Privacy Policy
1. Who we are
REXOH LLC operates REXOH Cloud and is the controller of the personal data described here. Contact: support@test.rexoh.io.
2. What we store, and why
Account: your e-mail address, the store or business name you enter, and a hashed password — to run your account and to e-mail you about it. Shopify connection: your store domain, the app's Client ID, and the Client secret encrypted with a key that lives only on our server — to create products in your store. After a successful test we also keep the shop name and currency Shopify reports. API token: only a hash of it, the last four characters, and the time it was created — to recognise your extension or desktop app. Usage: the number of imports per month, and for each import the product title, the supplier's product id, the Shopify product id, the result (created, draft, skipped, failed) and the failure reason — shown in your console, kept for the last 200 imports. Activity: the time and kind of client (extension, desktop) of your last API call. Technical: web-server logs with IP address and browser type, kept for up to 30 days for security and debugging; a short-lived attempt counter per IP on the sign-in and sign-up forms to prevent abuse.
3. What we do not do
We do not sell or rent personal data. We do not use your data for advertising. We do not read your Shopify orders or customers (the app only has product permissions). We do not store card numbers — payment, when available, is handled by a payment provider, and we only see whether an invoice was paid. We do not store the AI provider's key on your side, and the supplier's product text sent to the AI provider contains no personal data of yours.
4. Processors
Hosting: Hostinger (server located in Europe). E-mail delivery: Hostinger Mail. Product creation: Shopify (your own store). Product data: AliExpress Open Platform API. AI text: the model provider configured on our server (currently DeepSeek and/or Anthropic); they receive the supplier's product data, never your account data. Each processor acts under its own agreement and only for the purpose above.
5. Data from the browser extension and desktop app
The extension reads the product page you are looking at only when you press its button, sends that product's data together with your API token to our server, and stores the token in your browser. It does not track browsing, does not read other tabs, and sends nothing without your click. The desktop app behaves the same way.
6. How long
Account data: for as long as your account exists, then deleted within 30 days of your request. Import log: the last 200 entries. Server logs: up to 30 days. Backups: up to 30 days, then overwritten.
7. Your rights
You can see and change your account data in your console. You can ask us, from the e-mail address on your account, to export all data we hold about you, to correct it, or to delete your account — we answer within 30 days, usually the same day. Under the GDPR, the Swiss FADP and similar laws you may also object to processing and complain to your data-protection authority. Removing your store credentials or revoking your token takes effect immediately.
8. Security
Traffic is encrypted (HTTPS). Passwords are hashed; store secrets are encrypted at rest with a server-only key; tokens are stored only as hashes. Access to the server is limited to REXOH LLC. If a breach ever affects your data we will tell you without undue delay.
9. Changes
We will update this page when the Service changes, and announce material changes by e-mail. The date at the top tells you the current version.