Chrome Extension
The ItemFits Chrome extension lets you check whether a product on a retailer's page (such as Amazon, IKEA, or Wayfair) will fit through doors, up stairs, into vehicles, or in a room. To provide this feature, the extension collects and transmits the following data to our backend at itemfits.com:
• Account and authentication data. If you choose to sign in, we collect your email address. When you sign in with email and password, your password is sent over HTTPS to our authentication provider (Supabase) and is never stored inside the extension. When you sign in with Google, we use Chrome's identity API (chrome.identity.launchWebAuthFlow) to open Google's OAuth consent window and receive your email address and a session token via our authentication provider. Your Supabase session token is stored locally in the extension's chrome.storage.local so you stay signed in across popup opens.
• Product page content. When you click "Scan this page" in the extension popup, we run a one-shot content script in the active tab to extract publicly visible product attributes — title, dimensions, price, images, hyperlinks, and structured data (JSON-LD) — and send them to itemfits.com/api/extension/parse-product so our AI can identify the item and its dimensions. The extension never scans pages in the background or without your explicit click.
• Chat messages. Messages you type into the extension's chat interface are sent to itemfits.com/api/extension/chat, where they are processed by our AI provider (Anthropic, the maker of Claude) and stored so you can reference past conversations from the extension's History view.
• Scan and chat history. We store a per-user history of the products you've scanned and the chat threads you've started so you can revisit them. You can delete individual entries from the History view or request full deletion by emailing support@itemfits.com.
• Diagnostic data and device identifier. When a request to itemfits.com fails (for example, a network error or a 500 from our parser), the extension transmits a small, technical error report to itemfits.com/api/extension/telemetry containing: a randomly generated error ID, an error code, the HTTP status code, the request path, and the retailer hostname where the error occurred. The extension also generates a random per-install identifier (UUID) the first time you use it and stores it in the browser's extension storage; it is sent alongside chat requests so our abuse-protection systems can rate-limit the extension separately from the website. Neither the diagnostic reports nor the identifier contain your email address, page contents, or any text you have typed. You can disable diagnostic reports at any time from the extension's Options page (right-click the extension icon → "Options" → Privacy → "Don't send error telemetry to ItemFits"). The identifier is regenerated if you uninstall and reinstall the extension.
Subprocessors used by the extension. We share the data above with a limited number of service providers strictly to deliver the extension's single purpose:
• Supabase — database and authentication. Stores your account, sessions, scan history, and chat transcripts.
• Anthropic (maker of Claude) — AI model provider. Processes chat messages and scanned product data to generate fit assessments. Per Anthropic's commercial terms, data sent via its API is not used to train Anthropic's models.
• Stripe — payment processing for premium tier purchases made on itemfits.com. The extension itself does not handle payment information; if you purchase a paid plan, you do so on the web app and Stripe processes the transaction on our behalf. The extension never sees card numbers or banking details.
These providers are contractually bound to use the data only to deliver services to ItemFits.
What the extension does NOT collect. The extension does not track your browsing history outside of pages you explicitly scan. It does not monitor your clicks, keystrokes, mouse movements, or scroll position. It does not read form fields. It does not access your location, camera, microphone, or files. It does not inject scripts into pages you haven't asked it to scan. It does not sell, rent, or share your data with advertisers or data brokers, and it does not use your data for purposes unrelated to checking whether an item fits in a space.
Shopify App — Data Handling
Scope and responsibility. ItemFits LLC (“ItemFits,” “we,” “us,” or “our”) operates the ItemFits Shopify app, including merchant-branded and white-label experiences. This section applies to merchants using the ItemFits Shopify app and to their customers, prospective customers, and store visitors. It takes precedence over general descriptions elsewhere on this page for Shopify shopper data. The merchant determines why its shoppers' data is processed; ItemFits processes that data to provide the merchant's requested fit-check and reporting services. ItemFits also processes merchant account, billing, support, and security information to operate its own service. Our Shopify Merchant Data Processing Terms explain the parties' responsibilities.
Data and purposes. ItemFits processes the following information:
• Merchant and catalog information: shop domain, installation and access credentials, merchant contact information, billing/plan state, product and variant identifiers, titles, images, categories, SKUs, dimensions, publication eligibility, and synchronization status. We use it to connect the store, maintain its eligible product catalog, configure the widget, manage the app subscription, and support the merchant.
• Fit-check and conversation information: product and variant references, measurements entered, fit results, explanations, language, timestamps, and messages submitted to the widget. We use it to answer shoppers' fit questions, support conversation history, and let the merchant understand questions and product fit problems. Free-form messages can contain personal information entered by a shopper; please do not enter contact details or other unnecessary personal information.
• Activity and identifiers: browser/visitor, session, conversation, operation, and fit-check identifiers; recorded widget opens, check attempts and outcomes, and ItemFits cart actions. These support service operation, troubleshooting, and merchant analytics. For signed-in shoppers, a Shopify-authenticated customer identifier may be recorded with a fit check for supported history and order linking. Where the shopper has allowed analytics and marketing, Shopify's cart identifier may be recorded with a fit check, stored only as a keyed hash. These identifiers can relate to an individual and are personal data, even when no name or email is present. This processing is not anonymous merely because an identifier replaces a name.
• Storefront commerce activity, where the merchant enables it: with the merchant's permission ItemFits registers a Shopify web pixel that records product views, cart additions and removals, checkouts started, and completed checkouts across the whole storefront, not only on ItemFits surfaces. For each event we record the product and variant identifiers, quantity, the time, and for completed checkouts the order identifier, currency and order total. Shopify's visitor identifier and checkout token are stored only as keyed hashes. We do not record names, email addresses, phone numbers, postal addresses, payment details, discount codes, or line-item titles. Shopify withholds these events entirely where the shopper has not allowed analytics, and that permission is the basis for this collection. We use them to show the merchant how fit checks relate to storefront browsing and purchasing, such as how many shoppers viewed a product without checking fit. These identifiers can relate to an individual and are personal data, even when no name or email is present.
• Order attribution, where Shopify access is permitted and the feature is enabled: order and customer identifiers, order timestamps and paid/test status, currency, order totals, and purchased product/variant identifiers, quantities, and prices, and, where enabled, refund, cancellation and return status, amounts and Shopify-provided return reason categories for those orders. We link an eligible paid order to the most recent qualifying fit check during the preceding attribution window (currently seven days), using the signed-in customer identifier or, where the shopper allowed analytics and marketing, a keyed hash of Shopify's cart identifier. Withdrawn permission ends linking. The stored assisted-order record contains the order, fit-check reference, timestamps, currency, gross amount, and product lines. It does not need customer names, email addresses, phone numbers, or postal addresses. Reports show partial coverage and association, not proof that ItemFits caused a purchase. The seven-day attribution window is not a seven-day deletion period.
Shopify access. The app requests write_products for catalog/metafield operations, read_themes to check theme-extension setup, read_orders for eligible order reporting, and, where storefront commerce measurement is enabled, write_pixels to register the ItemFits web pixel and read_customer_events to receive the storefront events that pixel subscribes to. Requested permissions do not by themselves enable access to protected customer data. Order notifications depend on Shopify's required access approval or development-access configuration and feature activation. We do not request the optional protected name, email, phone, or address fields for order analytics. Merchant contact details and personal information voluntarily entered in support or chat are separate from those optional Shopify customer fields.
Limits on use. Shopify shopper data is used for the services and purposes described here, including merchant reporting and service support/security. We do not sell it, share it for targeted advertising, use identifiable Shopify shopper data to train models, or use it to market to shoppers. We do not combine it across merchants to build advertising profiles. Sending a question to an AI provider to answer it is distinct from using it to train a model. Fit guidance and assisted-order reports do not determine credit, insurance, employment, eligibility for essential services, or other decisions with legal or similarly significant effects. Merchants remain responsible for their own decisions and must not use these reports as a substitute for required human review.
Aggregated statistics. We may create aggregated statistics from the information described here, such as counts and rates of widget views, fit checks and results, orders linked to a fit check, refunds, returns and service costs. Aggregated statistics do not identify a shopper. Figures shown to other merchants never identify a store: they combine at least five stores, and small groups are withheld. We use aggregated statistics to operate, secure and improve the service and to show merchants how their results compare with other stores. We do not sell them. A store's own aggregated statistics are kept until the store uninstalls ItemFits and its data is erased; cross-store figures that already include a store are not recalculated after that store's erasure.
Consent and choices. Installing the app or granting Shopify API permissions is not the same as obtaining a shopper's consent to analytics. Merchants must provide appropriate notices and establish a lawful basis for the processing they enable. Where a customer's consent is required, optional analytics must not be used unless the customer's choices can be honored. A storefront cookie banner alone does not establish that ItemFits applies that choice. Contact support before enabling processing that depends on consent to confirm the available controls. Shoppers may ask the merchant, or contact us with the store domain, to request access, correction, deletion, or an applicable restriction or objection. We verify and scope requests before acting. We do not require unnecessary identity documents or contact information.
Service providers. Shopify supplies the store platform and authenticated app interfaces. Supabase hosts the database and authentication services; Vercel hosts application/API delivery. Anthropic processes relevant product text, shopper questions, and fit context to provide AI-assisted extraction and answers. Resend delivers internal operational email to ItemFits (such as app install and uninstall notices and service alerts), which can include store name and contact details; we do not use it to email shoppers. Data may be processed outside the shopper's country, including in the United States. Providers are used to deliver the service, not to sell shopper data or provide advertising audiences. Contact support for information about processing locations, applicable provider terms, or transfer arrangements for your store; this page does not represent that a particular transfer mechanism has been executed for every merchant.
Security. Merchant report access uses authenticated Shopify sessions and store-scoped queries. Shopify webhook signatures are checked before their payloads are accepted. Service credentials are handled on the server. Public app/API connections use HTTPS. Database storage and infrastructure protection depend on our hosting providers and deployed configuration; we do not describe these safeguards as end-to-end encryption or claim that every field is separately encrypted. Access to identifiable data is limited to service delivery, authorized support, security, and fulfilling requests. Contact support to report a suspected disclosure or security issue.
Retention and deletion. Catalog and installation records support the ongoing store connection. Fit history, conversations, activity, and any enabled order-attribution records support the service and merchant reports. Some records may remain for the duration of an installation; there is not currently a uniform automatic age-based deletion period covering all Shopify datasets, including assisted-order records. A report's date filter does not delete underlying data. Merchants and shoppers can request earlier deletion or restriction by contacting support. Uninstall revokes the app's ongoing store access; Shopify also sends a shop-erasure notification separately. We process that notification and customer access/erasure requests, with support review where automated coverage is incomplete. Uninstall is not a guarantee that every record or backup is erased within 48 hours. Any necessary legal retention or limitation on fulfilling a request will be explained to the requester. This policy does not promise that removing an account identifier alone anonymizes free-text messages.
Contact and requests. ItemFits LLC, 401 East Jackson Street, Suite 2340, Tampa, FL 33602, United States. Email support@itemfits.com with the subject “Shopify privacy request” and the relevant store domain. Shoppers may also ask their merchant to initiate a request through Shopify. Include only the information needed to locate the relevant records. We will explain verification, available data, and the applicable response timeline; request rights depend on the law that applies to the request. For security reports, use the subject “Shopify security report”.
Shopify Merchant Data Processing Terms