Privacy Policy
eSourcely (“we”, “us”) helps Shopify merchants import products from their own 1688 supplier accounts, publish them to their Shopify store, and manage the resulting orders. This policy explains what data we process and why. We designed eSourcely to hold as little personal data as possible.
Who this policy is for
Our customer is the merchant who signs up for eSourcely and connects their store. We are a data processor acting on that merchant’s behalf for any data belonging to their Shopify store.
What we collect
- Account data — the name, email address and business name you provide when you create an eSourcely account, plus a securely hashed password. We never store your password in plain text.
- Shopify connection — when you connect a store we store its domain and an access token (encrypted in transit, held server-side) so we can create products, read orders and write fulfilment tracking on your behalf. The token is limited to the scopes you approve.
- Product & order operations — the products you import and, for each Shopify order we process, the order’s identifier and line items so we can build the matching supplier purchase order and write tracking back. We do not store your customers’ names, email addresses, shipping addresses or payment details.
- Supplier data — product information you import from 1688 (titles, variants, images, prices).
What we do not do
- We never take custody of your funds. You pay your 1688 suppliers directly from your own account.
- We do not sell your data or share it for advertising.
- We do not store your end customers’ personal information.
How we use data
Solely to provide the service: importing and syncing products, computing your pricing, building purchase orders, and writing fulfilment tracking back to Shopify. We use aggregate, non-personal diagnostics to keep the service reliable.
Third parties
- Shopify — the platform your store runs on; we exchange product, order and fulfilment data with it under the permissions you grant.
- 1688 / Alibaba — the source of the products you import, accessed through your own supplier session or account.
- Infrastructure providers — hosting and database services that run eSourcely, bound by their own security and privacy obligations.
Data retention & deletion
We keep your data only while your account is active. When you uninstall the app, we disconnect the store and revoke stored tokens. We honour Shopify’s mandatory data-protection webhooks (customers/data_request, customers/redact, shop/redact): on a shop-redact request we erase the data we hold about that shop. You can request deletion of your eSourcely account at any time by contacting us.
Security
Passwords are hashed with scrypt; sessions are server-side. Access tokens are stored server-side and used only to fulfil your requests. All traffic is served over HTTPS.
Your rights
Depending on your jurisdiction you may have rights to access, correct or delete your personal data. To exercise them, email us at support@esourcely.com.
Contact
Questions about this policy? Email support@esourcely.com.