Legal
Privacy Policy
Last updated 16 August 2026
Ottermerce is a tool for moving catalog data in and out of a BigCommerce store. This page describes what it stores, where, for how long, and how to have it removed. It is written to be read rather than to be defensible, so where something is a limitation it says so.
Who this is between
"We" is the operator of Ottermerce, contactable at support@ottermerce.com. "You" is the person or business holding an Ottermerce account.
For data about your customers that passes through the service, you are the data controller and we are a processor acting on your instructions — the instructions being the files you upload and the operations you run.
What we store
| Data | Why | Kept |
|---|---|---|
| Your name, email and password hash | To sign you in | Until you ask us to delete the account |
| Your BigCommerce store hash and API token | To read and write your store on your behalf | Until you disconnect the store or delete the account |
| Files you upload (CSV/XLSX) | To run the import, and as the record of what was run | Until you delete the import record |
| Per-row results of each run | So you can see what happened and download a report | Until you delete the import record |
| Files generated by an export | So you can download them | Until you delete the export record |
| Your plan and its limits at the time of each run | To enforce and explain limits | With the import record |
What we do not store
We do not keep a copy of your catalog. BigCommerce remains the source of truth. Products, categories, customers and the rest are read when an operation needs them and are not written to our database.
The exception is deliberate and worth stating plainly: an import file you upload, and an export file we generate, do contain catalog data, and they sit in storage until you delete the record. If you export your customer list, that file contains customer names, emails and addresses, and it stays until removed.
Your BigCommerce API token
The token is encrypted at rest with a key held outside the database. It is written once and never sent back to your browser — the Settings page can only show you which credential is stored, not what it is.
Disconnecting removes our copy of the token; it does not revoke it. A token issued by BigCommerce keeps working until you uninstall the app or delete the API account in your BigCommerce control panel. If you believe a token has been exposed, revoke it there.
Ottermerce sends no email. There is no marketing list, no newsletter, no verification mail and no password-reset mail, because the application has no mail path at all.
One thing can cause an email, and it is BigCommerce that sends it, not us: if a customer import
file contains a Force Password Reset column set to true, BigCommerce mails that
customer. It is read only from that column, never implied by anything else, and our exports
never write it — so a file that goes out through an export and back in through an import cannot
trigger it by accident. A dry run says out loud when a row would cause one.
Where the data lives
On servers we operate in Amazon Web Services' us-east-1 region (Northern Virginia, United States). If you are in the EEA or the UK, using the service involves a transfer of personal data to the United States.
Third parties
- BigCommerce — every operation you run talks to their API using your token. Their handling of your store data is governed by your agreement with them.
- Amazon Web Services — hosting.
- Google Fonts — this marketing site loads typefaces from Google's servers, which means Google receives your IP address when you view these pages. The application itself does the same.
We do not sell data, and we do not share it with anyone else.
Cookies
The application sets two cookies, both strictly necessary: a session cookie that keeps you signed in, and a CSRF token that stops other sites submitting forms as you. There is no advertising, no tracking pixel and no analytics on the application.
When the app is opened inside the BigCommerce control panel it runs in a cross-site frame, which
requires the session cookie to be marked SameSite=None; Secure. It is still only
ever sent to us.
Deleting your data
- An individual file or run — delete the import or export record in the app; the stored file goes with it.
- Your store credentials — Disconnect in Settings.
- Everything — email support@ottermerce.com from your account address and ask for account deletion. We will remove the account, its credentials, its files and its history within 30 days and confirm when it is done.
Uninstalling the app from BigCommerce removes the stored credentials immediately. It leaves your import history in place on purpose — that history is the record of what the app did to your store, and it is exactly what people ask for after an uninstall that went wrong. Ask us if you want it gone too.
Your rights
Depending on where you live you may have the right to access, correct, export or erase the personal data we hold about you, and to object to or restrict its processing. Email support@ottermerce.com and we will respond within 30 days. You are also entitled to complain to your local data protection authority.
Security, and its limits
Traffic is encrypted in transit. Store tokens are encrypted at rest. Passwords are stored as salted hashes and cannot be read back. Access to production is restricted to key-based authentication.
No service can promise it will not be breached. If a breach affects your data we will tell you what happened, what was exposed and what to do, without waiting to have a complete picture first.
Children
The service is for businesses and is not directed at anyone under 16.
Changes
If this policy changes in a way that affects what we do with your data, we will change the date at the top and note what changed. Continuing to use the service after that means you accept the revised policy.