Syntonic/Multi Sync

Privacy Policy

Multi Sync · Effective 12 August 2026

Multi Sync (“the app”, “we”) is a Shopify app that keeps products and inventory in step between two or more Shopify stores that you control, or that you have been given a connection code for.

This policy describes exactly what the app stores, what it does not, and how long it keeps it. It is written against what the software actually does rather than the widest permissions it could theoretically use.

The short version

The app stores shop identifiers, product and variant record IDs, stock quantities, and a log of sync activity.

It stores no customer personal data at all — no names, email addresses, postal addresses, phone numbers, payment details or order contents. There is no customers table in the app’s database.

What we collect and why

Store credentials

Your .myshopify.com domainIdentifies which store a record belongs to
Shopify access token and refresh tokenLets the app read and write on your behalf via Shopify’s API
Granted scopes and token expiryRequired to keep the connection valid

These are issued by Shopify when you install the app and are revoked when you uninstall it.

Store configuration

Your chosen role (source or destination), your connection code, and your sync settings — which fields sync, tag and status filters, matching rule, removal behaviour, and inventory direction.

Product and inventory records

For each product the app syncs, it stores the Shopify ID of the product and each variant on both stores, the SKU or handle used to match them, the product title, and the timestamp of the last sync. It also briefly stores stock quantities it is about to write, so it can recognise its own writes coming back and avoid an endless sync loop; those expire after 90 seconds.

Product titles are stored because they appear in your activity log so you can see what happened. Descriptions, images and pricing are not stored.

Activity log

Every sync action is recorded: which store it came from, which store it went to, which product, what happened, and whether it succeeded. This is what powers the Activity screen and lets failed work be retried.

Webhook delivery IDs

Shopify may deliver the same webhook more than once. The app records delivery IDs so it can recognise and ignore duplicates.

What we do not collect

One thing we read but never store

To support the “unpublish if sold, delete if never sold” removal option, the app asks Shopify whether any order exists that references a given product. It receives only a yes or no. No order details, and nothing about the customer, is read or retained. This is the only use of order access in the app, and it runs only when you have chosen that specific removal setting.

Where your data is held

The app runs on Railway in the United States, with a PostgreSQL database in the same region. Railway is our only hosting provider and only sub-processor.

If you are in a region with data-residency requirements, note that data is processed in the United States.

How long we keep it

You uninstall the appYour access tokens are deleted immediately
48 hours after uninstallShopify sends a shop/redact request and the app deletes everything it holds for your store — connections, product mappings, settings, activity log and webhook records
A customer redaction requestAcknowledged; the app holds no customer data to delete
A customer data requestAcknowledged; the app holds no customer data to disclose

Uninstalling and redaction are deliberately separate so that reinstalling within that window restores your configuration rather than making you set it up again.

While the app is installed, the activity log is retained so you can review sync history.

Sharing

We do not sell, rent or share your data. It is not disclosed to any third party except our hosting provider (Railway), which processes it solely to run the app.

Data does move between the stores you have connected — that is the app’s purpose. A store only receives data from another store once someone with access to it has entered that store’s connection code. You can end this at any time by disconnecting, and the destination store controls what it imports.

Your choices

Security

Access tokens are stored in an access-controlled database and are never written to logs. All communication with Shopify uses HTTPS. Every incoming webhook is verified against Shopify’s HMAC signature and rejected if it does not match.

Changes

If this policy changes materially we will update the effective date above and, where the change affects how your data is handled, notify you through the app.

Contact

Hammad Zaib, trading as Syntonic
hammadzaib@hotmail.com

For privacy questions or a deletion request, contact us at the address above.

This policy is governed by the laws of Pakistan.