Privacy Policy
Effective August 19, 2026
SyncifyPro ("the App", "we", "us") is a Shopify app operated by IntelliShop that lets merchants export, import, schedule and migrate their store data. This policy explains what data the App processes, why, how it is protected, and the choices merchants and their customers have. By installing the App you agree to this policy.
1. Who we are and how to reach us
IntelliShop — contact support@syncifypro.app. We act as a data processor on behalf of the merchant, who remains the data controller for their store's data.
2. Data we process
The App only processes data when a merchant runs (or schedules) an export, import or migration, and only for the entities and columns the merchant selects. Depending on that selection this can include:
- Store data: products, variants, collections, inventory, discounts, metafields, pages, blogs, redirects, files, markets and similar catalog/content records.
- Customer personal data (Shopify "protected customer data"): customer name, email address, phone number and addresses, and the same fields as they appear on orders, draft orders and gift cards.
- Order data: order line items, totals, payment and fulfillment status, shipping/billing details.
- Merchant account data: the shop domain, the Shopify access token required to call the Admin API, app settings, presets, schedules and job history.
- Credentials the merchant chooses to store for delivery destinations and migration sources (FTP/SFTP/S3 servers, Google Drive/Sheets connection, WooCommerce/BigCommerce/Magento/PrestaShop/Etsy API keys). These are encrypted (AES-256-GCM) before storage and never returned to the browser.
We do not collect data directly from the merchant's customers, and we do not use tracking pixels, advertising identifiers or analytics on customer data.
3. Purposes
Personal data is used solely for store management on the merchant's instruction:
- producing the export/import/migration files the merchant requested;
- matching and updating records during imports (for example by email or handle);
- delivering files to the destinations the merchant configured (download, their own FTP/SFTP/S3 server, Google Drive/Sheets, or email recipients they specify);
- showing job history and results inside the App.
We never sell personal data, use it for advertising, profiling or automated decision-making, or share it with anyone other than the sub-processors listed below.
4. Where data is stored and for how long
- Export/import files are stored on Cloudflare R2 (encrypted at rest) and shared via short-lived signed links. Files are deleted according to the retention period configured in the App's Settings, or when the merchant deletes a job.
- Job records, settings, presets, schedules and encrypted credentials are stored in the App's database hosted on Fly.io (Amsterdam, EU), encrypted at rest and backed up with encrypted snapshots.
- On uninstall, Shopify notifies the App and all data for that shop (session, jobs, files, credentials, schedules) is deleted.
Test/development data is kept in a separate environment from production data.
5. Sub-processors
We use these infrastructure providers, each bound by their own data-protection terms:
- Fly.io — application hosting and database (EU region).
- Cloudflare — R2 object storage for export/import files, DNS.
- Resend — email delivery, only when a merchant chooses email as a delivery destination.
- Google — Google Drive/Sheets, only when a merchant connects their Google account.
- Any FTP/SFTP/S3 server, marketplace or e-commerce platform the merchant connects is chosen and controlled by the merchant.
6. Security
- All traffic uses TLS (HTTPS, SFTP/FTPS, HTTPS APIs).
- Data is encrypted at rest; merchant-entered credentials are additionally encrypted with AES-256-GCM using a key held only on the production server.
- Access to production systems is limited to the operator, protected by strong passwords and two-factor authentication.
- Every export/import run is logged in the App's job history; infrastructure access is logged by our providers.
- In the event of a security incident affecting personal data, we will contain it, notify affected merchants and Shopify without undue delay, and rotate credentials.
7. Merchant and customer rights
Merchants can view and delete job history and files inside the App at any time, and can uninstall the App to delete all of their data. Merchants receiving access, correction or deletion requests from their customers can fulfil them from Shopify; where the App still holds a related file, email us and we will delete it within 30 days. The App honours Shopify's mandatory customers/data_request, customers/redact and shop/redact webhooks.
8. Changes
We may update this policy; the effective date at the top will change and material changes will be announced inside the App.