TariffOS Manifesttariffos.com

Legal

Privacy policy

Effective August 15, 2026.

Data TariffOS accesses

TariffOS requests read-only product and inventory access. It processes store and catalog identifiers, product and variant labels, SKU, vendor, product type, tags, price and currency, product cost, HS codes, country and province of origin, and Shopify update timestamps. It does not request Shopify customer, order, payment, checkout, or shipping-address data.

How data is used

Catalog data is used only to synchronize the store, identify missing, invalid, or conflicting customs inputs, display the audit, record merchant review choices, and provide a requested CSV export. TariffOS does not sell catalog data and does not use it for advertising.

Landed-cost and rate-comparison values are calculated in the merchant’s browser. They are not submitted to TariffOS, written to the Shopify catalog, or retained by the app.

The app does not install storefront scripts or advertising cookies. Its hosting providers may process technical request information such as IP address, user agent, request path, status, and timestamp for delivery, security, and reliability. Application logs exclude access tokens, secrets, catalog payloads, and email addresses.

Service providers and international processing

Vercel hosts the application and Neon hosts its PostgreSQL database. The current application compute and database are located in United States East regions, so information submitted from outside the United States is transferred to and processed in the United States. Shopify API traffic is encrypted in transit, and Shopify credentials stored by TariffOS are encrypted at rest.

Storage, security, and retention

Successful webhook bodies are cleared after processing; failed webhook bodies are retained for at most seven days; webhook metadata and completed job payloads are retained for 30 days; product analytics events are retained for 13 months. Catalog and review records remain while the app is installed. Uninstall disables the integration and removes active sessions. A verified deletion request or Shopify shop-redaction request deletes the shop record and dependent connector data.

Your choices

For access, correction, export, or deletion requests, email privacy@tariffos.com. TariffOS also implements Shopify’s mandatory privacy webhooks.