Privacy Policy
Multi Sync (“the app”, “we”) is a Shopify app that keeps products and inventory in step between two or more Shopify stores that you control, or that you have been given a connection code for.
This policy describes exactly what the app stores, what it does not, and how long it keeps it. It is written against what the software actually does rather than the widest permissions it could theoretically use.
The short version
The app stores shop identifiers, product and variant record IDs, stock quantities, and a log of sync activity.
It stores no customer personal data at all — no names, email addresses, postal addresses, phone numbers, payment details or order contents. There is no customers table in the app’s database.
What we collect and why
Store credentials
| Your .myshopify.com domain | Identifies which store a record belongs to |
| Shopify access token and refresh token | Lets the app read and write on your behalf via Shopify’s API |
| Granted scopes and token expiry | Required to keep the connection valid |
These are issued by Shopify when you install the app and are revoked when you uninstall it.
Store configuration
Your chosen role (source or destination), your connection code, and your sync settings — which fields sync, tag and status filters, matching rule, removal behaviour, and inventory direction.
Product and inventory records
For each product the app syncs, it stores the Shopify ID of the product and each variant on both stores, the SKU or handle used to match them, the product title, and the timestamp of the last sync. It also briefly stores stock quantities it is about to write, so it can recognise its own writes coming back and avoid an endless sync loop; those expire after 90 seconds.
Product titles are stored because they appear in your activity log so you can see what happened. Descriptions, images and pricing are not stored.
Activity log
Every sync action is recorded: which store it came from, which store it went to, which product, what happened, and whether it succeeded. This is what powers the Activity screen and lets failed work be retried.
Webhook delivery IDs
Shopify may deliver the same webhook more than once. The app records delivery IDs so it can recognise and ignore duplicates.
What we do not collect
- Customer personal data of any kind. No names, emails, addresses, phone numbers, IP addresses or payment information. The app has no customers table.
- Order contents. The app does not store what was bought, by whom, or for how much.
- Analytics or tracking. The app sets no tracking cookies and uses no third-party analytics or advertising services.
One thing we read but never store
To support the “unpublish if sold, delete if never sold” removal option, the app asks Shopify whether any order exists that references a given product. It receives only a yes or no. No order details, and nothing about the customer, is read or retained. This is the only use of order access in the app, and it runs only when you have chosen that specific removal setting.
Where your data is held
The app runs on Railway in the United States, with a PostgreSQL database in the same region. Railway is our only hosting provider and only sub-processor.
If you are in a region with data-residency requirements, note that data is processed in the United States.
How long we keep it
| You uninstall the app | Your access tokens are deleted immediately |
| 48 hours after uninstall | Shopify sends a shop/redact request and the app deletes everything it holds for your store — connections, product mappings, settings, activity log and webhook records |
| A customer redaction request | Acknowledged; the app holds no customer data to delete |
| A customer data request | Acknowledged; the app holds no customer data to disclose |
Uninstalling and redaction are deliberately separate so that reinstalling within that window restores your configuration rather than making you set it up again.
While the app is installed, the activity log is retained so you can review sync history.
Sharing
We do not sell, rent or share your data. It is not disclosed to any third party except our hosting provider (Railway), which processes it solely to run the app.
Data does move between the stores you have connected — that is the app’s purpose. A store only receives data from another store once someone with access to it has entered that store’s connection code. You can end this at any time by disconnecting, and the destination store controls what it imports.
Your choices
- See what is stored: the Activity and Settings screens in the app show your configuration and sync history.
- Stop the sync: disconnect a connection at any time from the Stores screen.
- Delete everything: uninstall the app. Deletion completes automatically within 48 hours, or contact us to have it done sooner.
Security
Access tokens are stored in an access-controlled database and are never written to logs. All communication with Shopify uses HTTPS. Every incoming webhook is verified against Shopify’s HMAC signature and rejected if it does not match.
Changes
If this policy changes materially we will update the effective date above and, where the change affects how your data is handled, notify you through the app.
Contact
Hammad Zaib, trading as Syntonic
hammadzaib@hotmail.com
For privacy questions or a deletion request, contact us at the address above.
This policy is governed by the laws of Pakistan.