Last updated: 18 August 2026. Applies to SellerGrab StoreSpy (Shopify Product Export) version 0.1.0 and to the sellergrab.com website.
Sign-in is required, including on the free tier
StoreSpy asks you to sign in with Google before you can use the workbench. This applies to the free tier as well as to Pro — your plan is attached to your account rather than to one browser, so it follows you to another computer.
SellerGrab receives your Google account identifier, email address and basic profile name for authentication and plan administration. We do not receive your Google password.
What stays on your device
| Data | Where | Why |
|---|---|---|
| Last run configuration (source, columns, options, interval) | chrome.storage.local | Restore your settings the next time you open a page |
| Anonymous device identifier | chrome.storage.local | Request integrity, entitlement lookup and abuse prevention |
| Session and cached plan entitlement | chrome.storage.local | Keep you signed in and avoid a network request on every paid-feature click |
| Pending diagnostic events | chrome.storage.local | Retry bounded error events after a temporary network failure |
Exported rows are held in the tab while a run is in progress and written to the file you download. Chrome removes local extension storage when you uninstall the extension. You can also clear it from Chrome’s extension settings.
What is not collected
- No exported catalog data is uploaded. Product titles, descriptions, variants, prices, SKUs, image URLs, collection structures and the CSV, XLSX and JSON files you export stay out of SellerGrab’s servers.
- No browsing history is collected. StoreSpy has no always-on content script; it reads a tab only when you click its icon on that tab. It does not send the pages you visit to SellerGrab.
- No cookies are read or sent. StoreSpy does not request the
cookiespermission, and its catalog requests are made with credentials omitted — they carry no session of yours and no session of the store’s. - No seller admin access. StoreSpy reads public storefront endpoints only. It never signs into, reads from or writes to any Shopify admin, and it does not proxy requests through a server of ours.
- No advertising profiles. We do not sell user data or use it for personalized advertising, credit scoring or lending.
Where exported data comes from
Catalog data is fetched by your browser directly from the storefront you are looking at, using the
public JSON endpoints a Shopify storefront serves to anyone: /products.json,
/products/<handle>.json, /collections.json, /collections/<handle>/products.json and
/search/suggest.json. CSV, XLSX and JSON files are assembled locally inside the extension.
SellerGrab does not receive a copy.
Subscription and entitlement
Pro is a subscription — $9.99 per month or $49.99 per year — opened from inside the extension. The payment provider processes the payment details required to complete the purchase. SellerGrab receives the checkout status and entitlement information needed to unlock unlimited exports, but does not receive or store your full card number or card security code.
You can cancel at any time from inside the extension; Pro stays active until the end of the period you have already paid for. Transaction records may be kept where necessary for payment operations, accounting, fraud prevention and legal compliance.
Limited diagnostics and product events
The bundled payment SDK can send limited events to https://shopify.sellergrab.com, including
unhandled extension errors and pricing, sign-in or payment-flow outcomes. These records can contain
an event ID and time, event name, extension ID/version, browser language, anonymous device
identifier and a bounded error message or stack trace.
They do not contain storefront page content, product titles, product IDs, prices, image URLs, exported files, general browsing history or personal communications.
Website analytics
The sellergrab.com website uses Google Analytics 4 to measure aggregate traffic, such as which pages are viewed, referring sources, approximate location derived from IP address, and general device and browser information. This measurement covers the website only: the StoreSpy extension does not send your browsing activity or any storefront content to Google Analytics.
Google Analytics sets cookies in your browser for this purpose. You can block them through your browser settings or Google’s opt-out browser add-on. Blocking analytics does not affect any website or extension feature.
Permissions, one by one
| Permission | What it is used for |
|---|---|
storage | Store the run configuration, anonymous identifier, session, cached entitlement and retry queue described above |
activeTab | Read the address of the tab you clicked the icon on, so the export targets that store |
tabs | Open the workbench, pricing and account pages in their own tab |
scripting | Confirm the current tab is a Shopify storefront when you click the icon |
| Host access to the five storefront JSON endpoints listed above | Fetch the catalog data you asked for, with credentials omitted |
Host access to shopify.sellergrab.com | Sign in, check subscription entitlement and send the limited diagnostics described above |
One thing worth stating plainly: the extension declares host access by URL path — for example
*://*/products.json* — but Chrome evaluates host permissions by domain and ignores the path. Chrome
therefore shows the broad “read and change your data on all websites” wording at install time, and
that wording is accurate about what Chrome has granted. What the extension actually does with it is
narrower, and is described above: no always-on content script, no cookies, no credentialed requests,
and requests only to the five public catalog endpoints of the store you pointed it at.
Removing your data
Uninstalling removes data stored by the extension in Chrome. It does not erase transaction records that SellerGrab or its payment provider must retain. To request access to or deletion of eligible service-side data, including the account created by Google sign-in, email [email protected].
Chrome Web Store Limited Use
SellerGrab’s use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide and improve the extension’s user-facing functionality, and we do not sell it.