Home Security

Security and data handling

You are about to upload a file with your cost prices in it. Here is exactly where it goes, how long it stays, who else can see any part of it, and the things we do not claim.

Last reviewed 8 September 2026

1. Your file is not stored

The Pre-Flight Report is written from your upload, and the upload is deleted in the same request that created it. There is no copy on our servers to leak, to hand over, or to forget about.

You can check this from the outside rather than taking our word for it: the file is uploaded again for each step instead of being held between screens. That is not an oversight in the design. It is what not keeping it looks like.

2. What we keep

Three things, and this is the complete list: your email address (there is no password); your Supplier Profiles, which record column names and the field each was mapped to but not one cell of your data; and one row per free check holding a random cookie identifier, a SHA-256 fingerprint of the bytes and three counts.

A fingerprint is a hash and does not reverse into a file — it exists so that one person re-running one spreadsheet counts once rather than fifty times. Privacy and data retention states each of these in full, along with how to have any of it removed.

3. Who else touches it

Four, and each one receives something narrower than “our data”. What each actually gets is stated rather than summarised.

Google (Gemini API)

Enrichment, on Paid Services terms

Only the specific cells that deterministic processing could not resolve — measured at 22.9% of products. Never a whole file. Google does not train on it; Google does log it for a period Google has not published.

Google (Sign-in)

Continue with Google, if you use it

Nothing from us. We ask Google who you are once and receive exactly two things back: your email address and a permanent account identifier. We keep no Google token.

Cloudflare

DNS, and encrypted offsite backups in R2

Encrypted database archives. Cloudflare holds the ciphertext and not the key, so the bucket on its own does not open.

Resend

Transactional email

Your email address and the sign-in link. No catalogue data is ever emailed.

The database itself runs on our own server, not on a managed cloud database. Nobody holds a copy of it except us and, in encrypted form, Cloudflare.

4. Backups, and how we know they work

A backup nobody has restored is a hope, not a backup. Ours has been restored, and this is the whole test rather than a summary of it: the archive was downloaded back out of Cloudflare R2, compared byte for byte with the local copy, decrypted, and restored into a scratch database, where the row counts matched the live system exactly. The bucket was then listed rather than assumed.

It also runs on a timer as a service account rather than from somebody’s shell, because “it works when I run it” is not the same claim as “the timer works”.

5. No third-party scripts, and no tracking

This site loads no analytics, no advertising and no tracking scripts. Not a reduced set — none. The only cookie we set is the one that keeps you signed in and the random identifier that counts free checks, which is why you have not been asked to dismiss a consent banner.

That is a deliberate refusal and not an omission we intend to correct quietly. The page where you upload a file containing supplier cost prices is the last page on the internet that should be running somebody else’s JavaScript. If this ever changes, it changes here first, with the name of whatever was added.

6. Things we do not do

  • We do not train models on your catalogue. Neither do we permit our model provider to — that is a term of the paid tier we buy, quoted and linked on the privacy page.
  • We do not sell, share or rent any of it. There is no data business here and there will not be one.
  • We do not run advertising. Considered and rejected: it would put third-party ad scripts on the upload page, which contradicts section 5.
  • We do not email your catalogue. Nothing leaves in an attachment.

7. What we do not claim

We hold no SOC 2 report, no ISO 27001 certificate, and no third-party penetration test. Saying so is cheaper than letting you assume otherwise and find out during procurement.

ImportReady is a small, named business — Haryz Adil, operating under the law of Morocco — and the honest version of our security posture is that it rests on collecting very little, deleting the file immediately, running no third-party code, and being able to say precisely who else touches what. Those are claims you can check. A certificate we do not hold is not.

8. Telling us about a problem

Write to contact@getimportready.com. A person reads that inbox. If you have found something that affects other people’s data, say so in the subject line and we will reply before anything else in the queue.

We do not run a paid bounty programme and are not going to pretend otherwise, but we will tell you what we did about it and when.