This Privacy Policy explains how TidySync ("we", "us") collects, uses, and shares information when you install or use our Shopify app and related websites (including documentation and legal pages).
1. Scope
This policy covers merchant stores that install TidySync, users who access the embedded dashboard, and visitors to public pages such as this policy.
2. Information we collect
From Shopify (after you install):
- Shop domain and basic shop profile information
- OAuth offline access tokens required to call Shopify Admin APIs on your behalf
- Catalog and related resources you choose to import, export, scan, or edit (e.g. products, collections, customers, metafields as permitted by granted scopes)
- Billing-related identifiers for subscriptions and one-time charges via Shopify Billing
Generated by the App:
- Job history, previews, diffs, snapshots for undo, audit logs
- Mapping templates, schedules, notification preferences
- Plan, credit usage, and feature settings for your store
From visitors to public pages: standard web logs (IP, user agent, pages viewed) may be processed by our hosting provider for security and reliability.
3. How we use information
- Provide, operate, and improve import, export, and bulk-edit features you request
- Authenticate embedded sessions and protect against abuse
- Process Shopify Billing charges you approve
- Provide support and troubleshoot failed jobs
- Comply with legal obligations and enforce our Terms
We do not sell your store data. Processing only covers data needed for operations you initiate (for example, a bulk-edit request and relevant product fields).
4. Third-party processors
When you use assisted editing or content suggestions, relevant prompts and catalog snippets may be sent to subprocessors solely to generate plans or content for your request. Do not include sensitive personal data in prompts that is not needed for the task.
5. Sharing
We share data only with:
- Shopify, as required to operate an embedded app and billing
- Infrastructure providers (hosting, database, queue/redis) under contract
- Subprocessors as described above when you use assisted editing features
- Authorities when required by law
6. Retention
We retain tenant, job, and audit data while the App is installed and for a reasonable period afterward for backups, disputes, and legal compliance. After uninstall, we delete or anonymize personal and store data within a commercially reasonable timeframe, except where retention is required by law or for security logs.
7. Security
We use HTTPS, access controls, and least-privilege practices. No method of transmission or storage is 100% secure; please protect Shopify staff accounts with strong authentication.
8. Your choices
- Uninstall the App from Shopify Admin to revoke access tokens
- Contact us to request deletion of retained tenant data where applicable
- Adjust notification emails inside the App settings
9. Children
The App is for business use and is not directed to children under 16.
10. International transfers
Data may be processed in the regions where our hosting and subprocessors operate. By using the App, you understand that processing may occur outside your country subject to appropriate safeguards.
11. Changes
We may update this policy and will revise the "Last updated" date. Material changes may also be communicated in-app or via Shopify where appropriate.
12. Contact
Privacy requests: contact us via the channel listed on sync.tidyflowapp.com or your TidySync support email.