Your file is not stored
The Pre-Flight Report is written from your upload, and the upload is deleted in the same request that created it. There is no copy on our servers to leak, to hand over, or to forget about.
You can check this from the outside rather than taking our word for it: the file is uploaded again for each step instead of being held between screens. That is not an oversight in the design. It is what not keeping it looks like.
What we keep
Three things, and this is the complete list: your email address (there is no password); your Supplier Profiles, which record column names and the field each was mapped to but not one cell of your data; and one row per free check holding a random cookie identifier, a SHA-256 fingerprint of the bytes and three counts.
A fingerprint is a hash and does not reverse into a file — it exists so that one person re-running one spreadsheet counts once rather than fifty times. Privacy and data retention states each of these in full, along with how to have any of it removed.
Who else touches it
Five, and each one receives something narrower than “our data”. What each actually gets is stated rather than summarised, along with where it happens.
Google (Gemini API)
Enrichment, on Paid Services terms
Only the specific cells that deterministic processing could not resolve — measured at 22.9% of products. Never a whole file. Google does not train on it; Google does log it for a period Google has not published.
Any country in which Google or its agents maintain facilities. Their terms offer no regional confinement and we do not imply one.
Google (Sign-in)
Continue with Google, if you use it
Nothing from us. We ask Google who you are once and receive exactly two things back: your email address and a permanent account identifier. We keep no Google token.
United States, and wherever Google operates.
Cloudflare
DNS, and encrypted offsite backups in R2
Encrypted database archives. Cloudflare holds the ciphertext and not the key, so the bucket on its own does not open.
United States. The archives are encrypted before they leave this server.
Resend
Transactional email
Your email address and the sign-in link, and — if you asked for launch updates (N2) — the confirmation and unsubscribe links sent to that address. No catalogue data is ever emailed, and nothing about a file you checked is ever attached to either.
United States.
Hetzner Online GmbH
The server this runs on
Nothing sent deliberately, and everything by consequence: the database, the application and any upload for the seconds it is being read live on a machine Hetzner owns and we rent. They are our host, not a service we call.
Germany (Falkenstein, Saxony). Inside the EU.
The database itself runs on our own server, not on a managed cloud database. Nobody holds a copy of it except us and, in encrypted form, Cloudflare.
Backups, and how we know they work
A backup nobody has restored is a hope, not a backup. Ours has been restored, and this is the whole test rather than a summary of it: the archive was downloaded back out of Cloudflare R2, compared byte for byte with the local copy, decrypted, and restored into a scratch database, where the row counts matched the live system exactly. The bucket was then listed rather than assumed.
It also runs on a timer as a service account rather than from somebody’s shell, because “it works when I run it” is not the same claim as “the timer works”.
No third-party scripts, and no tracking
This site loads no analytics, no advertising and no tracking scripts. Not a reduced set — none. We set three cookies, all of them first-party and all of them strictly necessary — ir_session, ir_visitor, ir_oauth — which is why you have not been asked to dismiss a consent banner. Each one is listed here, with what it does and how long it lasts.
That is a deliberate refusal and not an omission we intend to correct quietly. The page where you upload a file containing supplier cost prices is the last page on the internet that should be running somebody else’s JavaScript. If this ever changes, it changes here first, with the name of whatever was added.
One thing has been added since that sentence was written, and this is it being named. There is now an optional email opt-in below the Pre-Flight Report, so we store a list of addresses that asked to hear about the launch. It sets no cookie, loads no script, and adds one step to the daily tally above — confirmed opt-ins, counted the same way as the rest, as a number on a date. The address is not joined to the file you checked or to the free-check count, and there is no column that could join them. The privacy page describes it in full.
What we do count, so that the paragraph above stays honest: on our own server, with no script in your browser and no cookie, we add one to a daily tally when the tool page is loaded, when a file is uploaded, when a report is produced, when an upload is refused, when the pricing page is loaded, and when an email address confirms that it wants launch updates. The table holds a date, the name of the step and a number. It has no identifier in it — not a cookie id, not an IP address, not a user agent, not a page path — so the counts are rates across everyone and can never be one person’s path through the site. The privacy page describes the same table, and it is the last row in the list of things we keep.
Things we do not do
- We do not train models on your catalogue. Neither do we permit our model provider to — that is a term of the paid tier we buy, quoted and linked on the privacy page.
- We do not sell, share or rent any of it. There is no data business here and there will not be one.
- We do not run advertising. Considered and rejected: it would put third-party ad scripts on the upload page, which contradicts section 5.
- We do not email your catalogue. Nothing leaves in an attachment.
What we do not claim
We hold no SOC 2 report, no ISO 27001 certificate, and no third-party penetration test. Saying so is cheaper than letting you assume otherwise and find out during procurement.
ImportReady is a small, named business — Haryz Adil, operating under the law of Morocco — and the honest version of our security posture is that it rests on collecting very little, deleting the file immediately, running no third-party code, and being able to say precisely who else touches what. Those are claims you can check. A certificate we do not hold is not.
Telling us about a problem
Write to [email protected]. A person reads that inbox. If you have found something that affects other people’s data, say so in the subject line and we will reply before anything else in the queue.
We do not run a paid bounty programme and are not going to pretend otherwise, but we will tell you what we did about it and when.
Last updated 8 September 2026 · last reviewed 9 September 2026 against the running product. Reviewing this page means re-reading it against the running system, not re-reading the page. If something here stops being true, it changes here first.