Privacy Policy - Easy Product Image Translate

Last Updated: September 25, 2026

Data Controller and Our Role

Grupo IO Ecommerce S.L., with Tax ID B21822408 and registered address at Calle Eduardo Morales, 32, 2ºA – 28025, Madrid (Spain), operates the Product Image Translate Shopify application. We are the data controller for personal data processed to manage our relationship with merchants, provide support, and maintain the security of our service.

When we process personal data contained in merchant-provided images or alternative text solely on the merchant’s behalf, the merchant remains the data controller and we act as a data processor. Merchants are responsible for ensuring that they have the necessary rights and lawful basis to upload and publish that content.

You can contact us at info@migraciones.io.


1. Purpose of Data Processing

We process data for the following purposes:

  • Authenticate merchants and maintain the connection between the application and their Shopify store.
  • Display the store’s products, product images, and configured languages.
  • Allow merchants to upload a finished translated image for each product image and store language, and optionally provide localized alternative text.
  • Validate and process uploaded images, store them in Shopify Files, and associate them with the relevant product, image, and language.
  • Display the appropriate image through the theme app extension according to the storefront language, keeping the original image when no translation is available.
  • Show translation status, filter images that still need a translation, and allow interrupted uploads to be completed.
  • Respond to support requests, diagnose technical issues, protect the service, and comply with legal obligations and privacy requests.

Product Image Translate does not automatically translate text inside images. Merchants supply the finished translated images. The app does not send images or alternative text to an AI translation or image-generation provider.


2. Legal Basis

For processing for which we act as data controller, the applicable legal bases are:

  • Performance of a contract: To provide the application and support requested by merchants who are parties to the service agreement.
  • Legitimate interests: To administer business relationships, assist authorized store staff, troubleshoot the application, prevent misuse, and maintain service security, subject to the rights and interests of the individuals concerned.
  • Legal obligations: To comply with applicable law and respond to valid requests from authorities.

Where we act as a processor for merchant-provided content, we process that content on the merchant’s instructions. The merchant is responsible for determining the applicable legal basis.


3. Data We Process

3.1 Store, Authentication, and Product Information

  • Shop domain, installation information, granted permissions, and configured store languages.
  • Shopify access tokens, refresh tokens where applicable, and session information needed to authenticate and operate the app.
  • Where supplied by Shopify during authentication, authorized staff account information such as user ID, name, email address, account role, and interface language.
  • Product IDs, titles, handles, publication status, media IDs, image URLs, dimensions, and existing alternative text.
  • Uploaded image content, Shopify file IDs and URLs, target languages, merchant-entered alternative text, translation mappings, and pending-upload records.

3.2 Image Storage and Publication

Uploaded images pass through our server for validation and image processing before being uploaded to Shopify Files. This processing includes removing embedded metadata and converting the image to a supported delivery format. Uploaded image files are stored by Shopify and delivered through its content delivery network. Our application database stores authentication information and pending-upload references, rather than a permanent copy of the uploaded image files.

Published translation mappings are stored in Shopify product metafields. Images, alternative text, and mapping information used by the storefront are intended for public display or access. They should not contain confidential information that is unsuitable for publication.

3.3 Storefront Visitors

The app uses the current storefront language and product identifiers to determine which uploaded image to display. It does not use IP-based geolocation for this purpose, and it does not request access to Shopify customer, order, or payment records.

Shopify may include customer identifiers in signed app-proxy requests or privacy webhook notifications. The app does not use those identifiers to personalize images, profile shoppers, or build customer records. Personal data may also be present in images or alternative text if a merchant includes it in their content.

3.4 Technical and Support Information

Our infrastructure may process request metadata and technical logs, such as IP addresses, request URLs, timestamps, response codes, browser information, and error details, for service operation and security. Support communications may include your contact details, store information, and content you voluntarily provide.


4. Data Recipients

Data is disclosed where necessary to provide the service or meet legal obligations:

  • Shopify: For authentication, product and language access, image uploads, Shopify Files storage, product metafields, storefront delivery, app-proxy requests, and privacy notifications.
  • Hosting and infrastructure providers: To operate the application server, database, network, and recovery infrastructure.
  • Support and communications providers: Where necessary to receive and respond to merchant enquiries.
  • Competent authorities and professional advisers: Where required by law or necessary to establish, exercise, or defend legal claims.

We do not sell personal data or use uploaded images for advertising or AI model training.

Where personal data is transferred outside the European Economic Area, applicable safeguards are required, such as an adequacy decision or Standard Contractual Clauses. You may contact us for information about the safeguards applicable to your data.


5. Data Retention and Deletion

  • While the app is installed: Authentication information is retained as needed to operate the app. Pending-upload records are retained until the upload is completed, discarded, replaced, or removed through the app’s deletion processes.
  • After uninstall or a shop deletion notification: When the app successfully processes a valid Shopify app/uninstalled or shop/redact notification, it deletes the store’s sessions and pending-upload records from the active application database.
  • Images in Shopify Files: Removing a translation, discarding an upload, or uninstalling the app does not automatically delete uploaded files from Shopify Files. Merchants can manage and delete those files through their Shopify admin.
  • Product metafields: Removing a translation through the app removes its published mapping. Uninstalling the app does not guarantee deletion of all product metafields stored in Shopify; merchant-owned mapping data may remain and can be managed through Shopify.
  • Technical logs, recovery copies, and support records: These are separate from the active application database and are not automatically erased by the uninstall handler. Retention is limited to what is necessary for recovery, security, resolving support matters or legal claims, and applicable legal obligations.

Deleting an application record does not itself delete content stored in the merchant’s Shopify account or copies independently held by Shopify. Contact us if you need assistance with a deletion request.


6. Your Rights

Subject to applicable law, you may request access to, correction or deletion of your personal data, restriction of processing, or data portability, and object to processing based on legitimate interests. Contact info@migraciones.io. We may request proportionate information to verify your identity and, where relevant, your authority to act for a store.

If your request concerns personal data in content controlled by a merchant, please contact that merchant. We will assist with applicable requests relating to data we process on their behalf.

You may also lodge a complaint with the Spanish Data Protection Agency at www.aepd.es, or with another competent supervisory authority.


7. Security Measures

The application uses measures appropriate to its operation, including:

  • HTTPS encryption for external communications with the app and Shopify.
  • Shopify authentication and validation of signed webhook and app-proxy requests.
  • Store-specific access checks for image translation records and product operations.
  • Validation of image formats, file sizes, and image content before upload.
  • Restricted access to application infrastructure, credentials, and database storage.

8. Cookies and Browser Storage

The app uses authentication tokens and server-side session storage to provide the service. The administrative interface may use browser session storage for essential interface behavior, such as restoring navigation or scroll position.

The storefront extension does not set advertising or analytics cookies and does not store visitor preferences in local storage. It reads the storefront language provided by Shopify. Cookies or storage used separately by Shopify, the merchant’s theme, or other apps are governed by their respective privacy and cookie notices.


9. Shopify Privacy Webhooks

The app implements handlers for Shopify’s mandatory privacy notifications:

  • customers/data_request: The app authenticates and acknowledges these requests. It does not maintain a customer or order database to export.
  • customers/redact: The app authenticates and acknowledges these requests. There are no customer or order records in the application database to delete.
  • shop/redact: The app deletes the affected store’s sessions and pending-upload records from its active database.

These automated handlers do not remove personal data that a merchant has included inside an uploaded image or alternative text stored in Shopify. Requests concerning that content should be directed to the merchant; we can assist where applicable.


10. Contact Information

  • Email: info@migraciones.io
  • Postal Address: Grupo IO Ecommerce S.L., Calle Eduardo Morales, 32, 2ºA – 28025, Madrid, Spain
  • Shopify App: Product Image Translate

Informacion adicional

Migraciones.io ofrece servicios especializados de migracion a Shopify y Shopify Plus, optimizacion tecnica SEO, mejora de conversion y soporte de crecimiento para ecommerce. En cada proyecto trabajamos con metodologia, control de calidad y enfoque en resultados medibles para aumentar rendimiento, estabilidad y ventas.

Indice de contenidos por idioma: Blog EN | Blog FR | Blog PT | Paginas EN | Pages FR | Paginas PT