Last updated September 27, 2026
Cloud Image Uploader Privacy Policy
This policy covers the Cloud Image Uploader app only, listed on Shopify as MZ: Cloud Image Uploader. The rules common to every app we publish are on the Privacy Policy page.
What the app does
It scans the images in the folder you choose in your connected Google Drive account, matches file names to the SKU, barcode or title of your Shopify products, and uploads the matching images to the product and variant in your Shopify store. It does this when you start it, or on its own at the interval you set.
Data we access from your Google account
When you connect Google Drive, the app asks for three permissions:
- See your Drive files (
drive.readonly). Used to list the files in the folder you choose, read each file’s name, type, size and modified date, and download a matching image in order to upload it to Shopify. The app never creates, changes, deletes or shares anything in your Drive; the permission itself is read-only. - Your email address and basic profile (
userinfo.email,userinfo.profile). Used to show you which Google account is connected on the app’s Accounts screen.
How we use Google data
Data received from Google is used only to do the job above, that is, to upload the images you choose to your own Shopify store. It is not used for advertising, it is not sold, it is not used to train artificial intelligence or machine learning models, and it is not read by people. The only exceptions are investigating a problem at your request or a legal obligation.
How we store Google data
| Data | How it is kept |
|---|---|
| Your Google account’s name, email address and the address of its profile picture | In the connected account record, until you disconnect |
| Google access and refresh tokens | Encrypted in the database. Never shown on any screen or written to any log. |
| The ID and path of the folder you chose | In the connected account record |
| For each file in the folder: its Drive ID, name, extension, size, type, modified date and Drive link | To know which file was uploaded to which product, and never to upload the same file twice |
| The image itself | Held on our server as a temporary file only while it is uploaded to Shopify, and deleted as soon as the upload finishes. It is never stored permanently. |
Who we share Google data with
The images you choose are uploaded only to your own Shopify store; once uploaded they are part of your product and stay in Shopify. Your Google account details and the files in your Drive are not transferred to any other third party.
Google API Services User Data Policy
Cloud Image Uploader’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data we collect from your Shopify store
| Data | Why |
|---|---|
| Your store domain, store name, contact email and the Shopify scopes you grant | Installing the app and recognising your store |
| Product data: product and variant IDs, title, handle, SKU, barcode and the images already on your products | Matching an image to the right product, and not uploading an image a product already has |
| Sync records: when a sync ran, how many images were matched and uploaded, which failed and why | Showing the history and errors in the app’s admin |
The app does not collect or store customer data. It requests no scope that would expose orders or a customer’s name, email, phone number or address.
Install notification
The moment the app is installed, your store name, your store domain and the store’s Shopify admin email are sent to Meze Apps’ own install counter, so that we know how many stores run which version. When the app is uninstalled, only your domain and the fact that it was uninstalled are sent. No Google data and no product data is part of these calls.
Error reports
When an error occurs in the app, a technical error report is sent to Sentry. No personal data and no Google data is attached to these reports.
How long it is kept
| Record | Deleted |
|---|---|
| Sync run records and product activity logs | after 90 days, automatically every day |
| Background jobs that failed | after 30 days |
| Server log files | after 14 days |
Beyond that, deletion happens in these ways:
- When you disconnect Google Drive. The app first revokes the access you granted on Google’s side, then deletes the connected account record, the encrypted Google tokens and every file record read from that account. You can also remove the access yourself at any time on your Google account permissions page.
- When you uninstall. On the shop redaction request Shopify sends within 48 hours of uninstalling, the Google access is revoked and every record belonging to your store, including the Google connection and its tokens, is deleted.
- When you ask us. As the store owner you can request deletion at any time.
Customer data requests
All three of Shopify’s privacy requests are honoured: customer data request, customer redaction and shop redaction. Because the app holds no customer data, there is no record to hand over or delete for the first two.
For any privacy question or deletion request, write from the store owner’s address to [email protected]. We reply within one business day and complete deletion requests within 30 days.