Privacy Policy
Effective Date: June 09, 2026
Last Updated: June 09, 2026
Developed by Vinsinfo | www.storshift.com
Introduction
StorShift is an eCommerce data migration solution developed and operated by Vinsinfo ("we," "our," or "us"). We are committed to protecting the privacy and security of your personal information and the personal data of your customers.
This Privacy Policy explains what information we collect, how we use and protect it, and your rights regarding that information when you use our website at www.storshift.com or our migration application at app.storshift.com (together, the "Service").
By accessing or using StorShift, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.
1. Data Controller and Data Processor
1. Data Controller and Data Processor
Understanding the roles of Data Controller and Data Processor is important for compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1.1 Vinsinfo as Data Controller
1.1 Vinsinfo as Data Controller
Vinsinfo acts as the Data Controller in relation to personal data collected directly from you — the StorShift account holder. This includes your account registration data (name, email address, phone number), support communications, and usage data generated when you interact with the StorShift platform.
As Data Controller, Vinsinfo determines the purposes and means of processing this data and is responsible for ensuring its lawful processing in accordance with applicable privacy legislation.
1.2 Vinsinfo as Data Processor
1.2 Vinsinfo as Data Processor
When you use StorShift to migrate your eCommerce store data — including your customers' personal data (names, email addresses, addresses, phone numbers) — Vinsinfo acts as a Data Processor on your behalf. In this capacity:
- We process your customers' personal data solely on your documented instructions, i.e., to perform the migration to your Zoho Commerce destination store.
- We do not process your customers' personal data for any purpose beyond completing the migration.
- We implement appropriate technical and organisational security measures to protect the data we process on your behalf.
- We do not engage any sub-processor without appropriate safeguards being in place (see Section 6 — Sub-Processors).
- Upon completion of the migration and your confirmation, we delete or return the migrated data in accordance with our retention policy.
1.3 You as Data Controller
1.3 You as Data Controller
As the store owner initiating the migration, you are the Data Controller for your customers' personal data. You are responsible for:
- Ensuring you have a valid legal basis (e.g., consent, legitimate interest, contractual necessity) to transfer your customers' personal data to a new platform.
- Informing your customers of the migration and any change in the platform processing their personal data, where required by applicable law.
- Ensuring your instructions to StorShift are lawful and compliant with applicable data protection regulations.
If you are subject to GDPR, you may wish to enter into a Data Processing Agreement (DPA) with Vinsinfo. Please refer to Section 15 of this Privacy Policy for details.
2. Information We Collect
2. Information We Collect
2.1 Information You Provide Directly
2.1 Information You Provide Directly
Account Registration Data
Account Registration Data
When you create a StorShift account, we collect your first name, last name, email address, password, and optionally your phone number.
Store Configuration Data
Store Configuration Data
To connect your source eCommerce platform, you will provide store credentials such as API Consumer Keys, Consumer Secrets, and your store domain name. These are used solely to establish a secure connection for the purpose of migration.
Regarding disconnection: once a store is connected, the user cannot disconnect or break the flow on their own. If any changes or disconnection are required, the user needs to contact our support team.
Contact and Support Data
Contact and Support Data
When you reach out through our contact form or support channels, we collect your company or store name, email address, subject, and the content of your query or feedback.
Assisted Migration Request Data
Assisted Migration Request Data
For BigCommerce and Shopify migrations handled by our support team, we initially collect only your contact information through the request form. Our team will then reach out to understand your migration requirements, gather the necessary store details, and coordinate the migration from your desired source platform to the destination platform on your behalf.
2.2 Store Data Processed During Migration
2.2 Store Data Processed During Migration
As part of delivering the migration service, StorShift processes store data from your source platform on your behalf. This includes:
Product Data
Product Data
Product names, SKUs (product and variant), descriptions, prices, stock quantities, dimensions, product variants and attributes, product images, and category images.
Customer Data
Customer Data
Customer first and last names, email addresses, billing addresses, shipping addresses, phone numbers, city, state, country, and postal codes.
Order Data
Order Data
Order totals, discount totals, tax totals, shipping totals, currency, payment status, shipment status, billing and shipping details, and associated line item information.
This data is processed exclusively to perform your requested migration to Zoho Commerce. We do not use your store's customer or order data for advertising, profiling, or analytics.
2.3 Automatically Collected Information
2.3 Automatically Collected Information
- Usage Data: Pages visited, features accessed, migration steps completed, and interaction logs
- Technical Data: IP address, browser type and version, operating system, and device identifiers
- Log Data: Server access logs, error reports, referring URLs, and session durations
2.4 Third-Party Authentication Data
2.4 Third-Party Authentication Data
When you connect your Zoho Commerce store through OAuth as part of the destination store configuration, Zoho requests your authorization and, upon your approval, returns an authorization code to StorShift. We use this authorization code to obtain access and refresh tokens from Zoho, which enable our system to transfer migrated data to your selected Zoho Commerce store. At no point does StorShift collect, store, or have access to your Zoho account password or login credentials.
3. How We Use Your Information
3. How We Use Your Information
Service Delivery
Service Delivery
To execute and manage the data migration process from your source eCommerce platform to your Zoho Commerce destination store.
Account Management
Account Management
To create and maintain your StorShift account, verify your identity, and manage your session.
Communication and Notifications
Communication and Notifications
To send migration status updates, real-time progress notifications, and post-migration completion reports by email.
Customer Support
Customer Support
To respond to support tickets, contact form submissions, demo requests, and assisted migration inquiries.
Service Improvement
Service Improvement
To monitor platform performance, identify and resolve technical issues, and improve the reliability and accuracy of the migration tool.
Security and Fraud Prevention
Security and Fraud Prevention
To detect, investigate, and prevent unauthorized access, technical abuse, or fraudulent activity on the platform.
Legal Compliance
Legal Compliance
To fulfill our obligations under applicable laws and regulations, including data protection laws in India and internationally.
We do not sell, rent, trade, or share your personal information or your store's data with any third party for marketing, advertising, or commercial purposes.
4. Legal Basis for Processing (GDPR)
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, our legal basis for collecting and using your personal information is as follows:
- Contractual Necessity: Processing is necessary to perform the migration service you have requested.
- Legitimate Interests: Processing is in our legitimate interest to operate and improve the Service, ensure security, and provide customer support.
- Legal Obligation: Processing is necessary to comply with applicable laws and regulations.
- Consent: Where you have given consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Data Security
5. Data Security
StorShift implements multiple layers of protection to help safeguard your information and your customers' data throughout the migration process.
Encrypted Data Transmission
Encrypted Data Transmission
All data transferred between your browser, our application, and your store platforms is protected using HTTPS and TLS encryption.
Secure API Credential Handling
Secure API Credential Handling
API keys and credentials you provide are used solely to access and read your store data during the migration session. We implement measures to ensure credentials are not retained beyond the operational need to complete your migration. We strongly recommend revoking or rotating API credentials from your source platform once your migration is complete.
Data Transfer Approach
Data Transfer Approach
Our migration process is designed to transfer store data directly from your source platform to your Zoho Commerce destination store with minimal intermediate storage. We aim to ensure that your store's data is not retained on our servers beyond what is operationally necessary to complete and verify the migration.
Access Controls
Access Controls
Access to customer data, migration records, and internal systems is restricted to authorized Vinsinfo personnel. Each team member operates under defined access permissions and is bound by confidentiality obligations.
Non-Disclosure Commitment
Non-Disclosure Commitment
We commit that your store data, API credentials, and configuration details will not be disclosed to any third party, will not be sold, and will not be used for any purpose other than completing your requested migration.
Post-Migration Recommended Steps
Post-Migration Recommended Steps
After your migration is confirmed complete, we strongly recommend revoking the API credentials provided to StorShift from your source platform and reviewing any access that was shared during the process.
Data Breach Response
Data Breach Response
In the event of a personal data breach affecting data we process, Vinsinfo will:
- Conduct an internal investigation to assess the nature, scope, and risk of the breach.
- Notify affected Data Controllers (i.e., you, the store owner) without undue delay and, where required by applicable law, within applicable statutory notification periods.
- Provide information on the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.
- Assist you in fulfilling your own notification obligations to supervisory authorities and affected individuals, where applicable.
- Maintain records of all data breaches, their effects, and the remedial actions taken, in accordance with applicable law.
If you become aware of any security vulnerability or incident involving data processed through StorShift, please notify us immediately at support@storshift.com.
6. Sub-Processors
6. Sub-Processors
To deliver the StorShift service, Vinsinfo engages the following third-party sub-processors who may have access to or process data on our behalf. We take steps to ensure each sub-processor provides sufficient safeguards to protect the data they handle.
| Sub-Processor Category | Details / Purpose |
| Cloud Hosting Provider | StorShift is hosted on a cloud infrastructure platform (such as AWS, Google Cloud, or Microsoft Azure). The hosting provider stores application data, migration logs, and account information in secure, access-controlled environments. Specific provider details will be updated in this section as infrastructure decisions are finalised. |
| Email / Notification Provider | We use a transactional email service (such as SendGrid, Mailgun, or similar) to deliver account notifications, migration status emails, and support communications. These providers process your email address solely for message delivery. |
| Application Monitoring | We may use an application performance monitoring tool (such as Sentry, Datadog, or similar) to capture error logs and performance metrics. These tools may process technical identifiers and usage data but are configured to minimise personal data exposure. |
| Payment Processor | If your use of StorShift involves a paid plan, payment data is processed by a PCI-DSS compliant payment gateway. StorShift does not store payment card details. |
| Customer Support Platform | Support communications may be managed through a helpdesk or CRM tool. Data shared includes your name, email address, and the content of your support query. |
We will update this sub-processor list whenever we add, change, or remove sub-processors. Where required by applicable law (e.g., GDPR), we will provide prior notice of any new sub-processor that may affect your data processing rights.
Enterprise customers who require a current and binding list of sub-processors as part of contractual obligations are encouraged to contact us at support@storshift.com to request a formal Sub-Processor Addendum.
7. Data Sharing and Third-Party Services
7. Data Sharing and Third-Party Services
We do not sell or rent your data. We may share your information only in the following limited circumstances:
With Zoho Commerce
With Zoho Commerce
As the destination platform of your migration, data is transferred to your selected Zoho Commerce store using OAuth authorization you explicitly grant. Zoho's data practices are governed by Zoho's Privacy Policy at zoho.com/privacy.
With Source Platforms
With Source Platforms
StorShift reads data from your source platform (WooCommerce, Shopify, BigCommerce) using API credentials you provide. Your use of these platforms remains subject to their respective terms and privacy policies.
With Our Support Team (Assisted Migrations)
With Our Support Team (Assisted Migrations)
For BigCommerce and Shopify migrations, your store configuration details are shared with authorized Vinsinfo support engineers to facilitate the assisted migration.
For Legal Requirements
For Legal Requirements
We may disclose your information where required by law, court order, or governmental authority, or where necessary to protect the rights, safety, or property of StorShift, Vinsinfo, or others.
Business Transfers
Business Transfers
In the event of a merger, acquisition, reorganization, asset sale, or similar corporate transaction involving Vinsinfo, personal data may be transferred as part of that transaction subject to applicable data protection laws and confidentiality obligations.
Third-Party Analytics and Advertising
Third-Party Analytics and Advertising
As of the effective date of this Privacy Policy, StorShift currently uses only essential cookies required for platform functionality. We do not currently deploy tools such as Google Analytics, Meta Pixel, or similar tracking technologies on our platform.
In the event we introduce any third-party analytics or advertising tools in the future (including but not limited to Google Analytics 4, Meta Pixel, or similar services), this Privacy Policy will be updated prior to such deployment to describe the data collected, the purpose of processing, your opt-out rights, and any cross-border transfer implications. Where required by applicable law, we will seek your consent before enabling such tracking.
Users who wish to be notified when such changes occur are encouraged to periodically review this page or contact us at support@storshift.com to register their interest in advance notification.
8. Cookies and Tracking Technologies
8. Cookies and Tracking Technologies
StorShift uses cookies and similar tracking technologies to maintain your session, remember your preferences, and analyze website usage to improve the Service.
Essential Cookies
Essential Cookies
Required for core functionality such as keeping you logged in and maintaining your migration progress.
Analytics Cookies
Analytics Cookies
StorShift currently uses only essential cookies required for platform functionality. Analytics cookies are not currently deployed. If analytics technologies are introduced in the future, this Privacy Policy will be updated accordingly.
You may configure your browser to refuse cookies. Disabling certain cookies may affect the functionality of the Service. We do not currently use cookies for targeted advertising or retargeting.
9. Data Retention
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, and resolve disputes. The following retention periods apply:
| Data Category | Retention Period |
| Account Registration Data (name, email, password) | Retained for the duration of your active account. Upon account deletion request, data is removed within 30 days, except where retention is required by law. |
Store Configuration Data (API keys, store URL) | Retained only for the duration of the active migration session. Deleted promptly upon migration completion or session expiry. We recommend you also revoke keys from your source platform. |
Migrated Store Data (products, customers, orders) | Processed in transit and retained for a maximum of 7 days post-migration completion to allow for verification and error-checking. Deleted thereafter unless you raise a support issue requiring further review. |
Migration Logs and Reports | Retained for 90 days from migration completion date to support troubleshooting and audit. Deleted thereafter. |
Support and Contact Communications | Retained for 2 years from the date of last communication to support ongoing service delivery and legal record-keeping. |
| Server and Application Logs | Retained for 90 days for security monitoring, debugging, and performance analysis. |
| Payment Records (if applicable) | Retained for 7 years in accordance with applicable financial and tax regulations in India (as required under the Income Tax Act and GST compliance requirements). |
To request deletion of your account and associated data before the end of the stated retention period, please contact us at support@storshift.com. We will action verified deletion requests within 30 days.
10. Your Rights
10. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal and operational obligations.
- Right to Restriction: Request that we limit the processing of your data in certain circumstances.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to certain types of processing, including processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please email support@storshift.com. We will respond within 30 days in accordance with applicable law.
11. Compliance Standards
11. Compliance Standards
StorShift and Vinsinfo are committed to responsible data handling in accordance with applicable laws and industry standards. The following frameworks and regulations inform our privacy and security practices:
11.1 India — Digital Personal Data Protection Act, 2023 (DPDP Act)
11.1 India — Digital Personal Data Protection Act, 2023 (DPDP Act)
As an India-based business, Vinsinfo operates in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act). Under this framework:
- We process personal data in accordance with the lawful grounds permitted under the DPDP Act, including consent and other legitimate uses recognized under applicable law.
- We implement reasonable security safeguards to prevent personal data breaches.
- We honor data principal rights including the right to access, correct, and erase personal data.
- We notify the Data Protection Board of India and affected individuals of significant data breaches as required under the Act.
11.2 European Union — General Data Protection Regulation (GDPR)
11.2 European Union — General Data Protection Regulation (GDPR)
For users and data subjects located in the European Economic Area (EEA) or the United Kingdom, StorShift processes personal data in accordance with the principles of the EU GDPR, including lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
11.3 International Data Transfers
11.3 International Data Transfers
StorShift is operated by Vinsinfo, based in India. Where personal data is transferred internationally (e.g., to cloud infrastructure providers or email delivery services), we implement appropriate safeguards such as standard contractual clauses (SCCs) or equivalent mechanisms to ensure an adequate level of data protection.
11.4 Information Technology Act, 2000 (India)
11.4 Information Technology Act, 2000 (India)
Vinsinfo complies with the provisions of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), which govern the collection, storage, and processing of sensitive personal data in India.
11.5 Payment Card Industry (PCI-DSS)
11.5 Payment Card Industry (PCI-DSS)
Where StorShift processes or facilitates payment transactions, we rely on PCI-DSS compliant payment processors. StorShift itself does not store, process, or transmit full payment card data.
11.6 Ongoing Review
11.6 Ongoing Review
We review our compliance posture regularly and update our practices in response to new or revised legislation, regulatory guidance, or changes in our data processing activities.
12. Children's Privacy
12. Children's Privacy
StorShift is a business-to-business service intended for use by adults and businesses. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has provided us with their information, please contact us immediately and we will promptly delete it.
13. Links to Third-Party Websites
13. Links to Third-Party Websites
Our website and documentation may contain links to third-party websites and services, such as Zoho Commerce. These third-party websites operate independently and have their own privacy policies and practices. StorShift is not responsible for the content, security, or privacy practices of third-party websites. We encourage you to review their privacy policies before providing any personal or business information.
14. Changes to This Privacy Policy
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, sub-processors, or applicable laws. When we make material changes, we will update the "Last Updated" date at the top of this page. Where appropriate, we will notify you by email. Continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
15. Data Processing Agreement (DPA)
15. Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a Data Controller (you, the store owner) and a Data Processor (Vinsinfo/StorShift) that governs how personal data is processed on the controller's behalf.
15.1 When a DPA Is Required
15.1 When a DPA Is Required
A DPA is typically required when:
- You are subject to GDPR and are instructing StorShift to process personal data of individuals located in the EEA or UK.
- Your enterprise compliance policy or customer contracts require a DPA with all data processors.
- You are subject to other data protection frameworks (e.g., CCPA, DPDP Act) that impose similar contractual requirements.
15.2 What Our DPA Covers
15.2 What Our DPA Covers
Our standard DPA includes the following key provisions:
- Subject matter, nature, purpose, and duration of the data processing.
- Categories of personal data processed and categories of data subjects.
- Obligations and rights of the Data Controller.
- Obligations of the Data Processor, including confidentiality, security measures, and sub-processor management.
- Data subject rights assistance obligations.
- Data breach notification procedures and timelines.
- Return or deletion of personal data upon termination of the service.
- Audit rights and cooperation with supervisory authorities.
15.3 How to Request a DPA
15.3 How to Request a DPA
To request a Data Processing Agreement with Vinsinfo, please contact us at support@storshift.com with the subject line "DPA Request." Our team will respond within 5 business days with our standard DPA for your review.
Enterprise customers with bespoke DPA requirements or existing standard contractual clause templates are welcome to share their requirements and we will work collaboratively toward an agreed arrangement.
16. Jurisdiction and Legal Actions
16. Jurisdiction and Legal Actions
This Privacy Policy and any dispute arising out of or in connection with it, or the processing of personal data described herein, shall be governed by and construed in accordance with the laws of India.
16.1 Primary Jurisdiction — India
16.1 Primary Jurisdiction — India
Vinsinfo is a company registered and operating in India. Any legal action, claim, or proceeding arising out of or relating to this Privacy Policy shall, in the first instance, be subject to the exclusive jurisdiction of the competent courts located in Chennai, Tamil Nadu, India.
16.2 GDPR — EU/UK Supervisory Authorities
16.2 GDPR — EU/UK Supervisory Authorities
If you are located in the European Economic Area (EEA) or the United Kingdom and you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your country of residence or place of work. A list of EU supervisory authorities is available at: edpb.europa.eu/about-edpb/board/members_en.
16.3 India — Data Protection Board
16.3 India — Data Protection Board
For users in India, complaints regarding violations of the Digital Personal Data Protection Act, 2023 may be directed to the Data Protection Board of India, once established and operational under the DPDP Act framework.
16.4 Dispute Resolution
16.4 Dispute Resolution
Prior to initiating any formal legal proceedings, both parties agree to attempt to resolve any dispute in good faith through direct negotiation. Disputes not resolved through negotiation within 30 days may be escalated to the applicable courts or regulatory authority as described above.
17. Contact Us
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices — including requests to exercise your data rights or to obtain a Data Processing Agreement — please contact us through the following channels:
StorShift byVinsinfo
Registered Business Name: VINSINFO PVT LTD
Registered Office Address:
Ph: 044-24314499
Email: support@storshift.com
Phone: +91 99763 37000 (Mon-Fri, 9AM-6PM IST)
Website: www.storshift.com
DPA / Legal Enquiries: support@storshift.com (Subject: DPA Request / Legal Enquiry)
