01
Scope and controller
This Privacy Policy applies to the CaptainSync Shopify app and the public CaptainSync website. The data controller for the processing described here is the CaptainSync app developer identified in the Shopify App Store listing.
Privacy questions and data-rights requests can be sent to y.sentuerk@reply.de.
02
Information we process
CaptainSync processes only the information required to connect stores, compare Metafield Definition schemas, apply changes a merchant explicitly approves, and preserve an operational history.
Shopify installation and identity
Store domain and Shopify shop identifiers; granted app scopes; OAuth session and refresh credentials; and the signed-in Shopify user's identifier, name, email, locale, collaborator status, and account-owner status when Shopify supplies them.
CaptainSync configuration
Organization and membership records, Source or Destination roles, connected-store labels, hashed invitation tokens, Sync Profile names, selected stores, and selected owner types.
Definition and operation data
Metafield Definition schema information such as owner type, namespace, key, name, description, type, validations, and access settings; Compare snapshots; selected resource keys; job state; timestamps; item-level results; and Shopify API error messages.
Sync confirmation records
The signed-in merchant user's email and stable Shopify user ID (when available), confirmation time, confirmation statement, selected changes, and Source and Destination stores are stored with each started Sync for accountability. Execution events also record attempt number, outcome, app version, deployed commit, and a SHA-256 evidence digest.
Subscription information
Shopify shop and app identifiers, plan and item handles, billing interval, price, subscription status, test status, renewal or period-end date, and the last reconciliation time. Payment card details are handled by Shopify and are not received by CaptainSync.
Technical information
Hosting and security systems may process IP address, user agent, request time, requested URL, response status, and diagnostic errors to deliver and protect the service. CaptainSync does not use advertising trackers.
03
Information we do not process
CaptainSync V1 does not request, query, copy, or store Shopify customer records, order contents, draft orders, shipping addresses, customer contact details, payment details, product content, or Metafield values. It operates on Metafield Definition schemas only.
CaptainSync also does not place tracking technology on a merchant's storefront and does not monitor the merchant's customers. Shopify's mandatory customer privacy webhooks are acknowledged, but there is no customer data in CaptainSync to return or erase.
04
Purposes and legal bases
- Provide the service: authenticate Shopify users, connect stores, run Compare and Sync, show results, provide support, and administer subscriptions. This processing is necessary to perform the service requested by the merchant.
- Protect the service: authorize organization access, prevent misuse, diagnose failures, maintain reliable background jobs, and secure accounts. This supports our legitimate interest in operating a safe and reliable service.
- Maintain accountability: retain explicit Sync confirmations, operation results, and subscription state. This supports contract administration, security, and the establishment or defense of legal claims.
- Meet legal obligations: respond to valid privacy requests, Shopify compliance webhooks, and lawful requests from authorities where required.
CaptainSync does not use merchant information for advertising, profiling, or unrelated marketing, and does not make decisions with legal or similarly significant effects using automated profiling.
06
Retention and deletion
- CaptainSync configuration, Compare snapshots, Sync history, and subscription records are retained while needed to provide the installed app and its audit history.
- Expired online sessions and offline sessions whose access and refresh credentials can no longer be used are removed by a daily cleanup process.
- Pairing invitations are single-use and expire after 24 hours. Only a SHA-256 hash of an invitation token is stored; the raw token is not persisted.
- Deleting a Sync Profile in CaptainSync deletes its stored Compare and operational Sync history, including item-level results. Compact confirmation and execution audit evidence is retained separately for accountability.
- When the app is uninstalled, CaptainSync deletes Shopify sessions and cancels the local subscription entitlement. Shopify generally sends the mandatory
shop/redactrequest approximately 48 hours after uninstall. On receipt, CaptainSync deletes the store connection and all profiles, Compare data, Sync runs, item results, jobs, and subscription records that depend on that store, including the separately retained audit evidence.
Limited residual copies may remain temporarily in infrastructure backups or security logs according to the service provider's standard lifecycle. They are isolated from ordinary use and expire through that lifecycle unless longer retention is legally required.
07
Security
CaptainSync uses HTTPS/TLS in transit, Shopify OAuth, expiring access credentials, organization-scoped authorization, managed PostgreSQL infrastructure, and restricted production secrets. Shopify OAuth access and refresh credentials are stored in the server-side session database used by the Shopify app framework. CaptainSync does not display these credentials or write them to application logs. Legacy manually supplied access tokens, if any remain, are protected with CaptainSync's AES-256-GCM encryption layer.
No online service can guarantee absolute security. Merchants should protect their Shopify accounts, limit staff access, and contact us promptly if they suspect unauthorized CaptainSync activity.
08
Your privacy rights
Depending on applicable law, an individual may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, and to withdraw consent where consent is the legal basis. An individual may also have the right to complain to a competent data-protection authority.
Send a request to y.sentuerk@reply.de. We may need to verify the requester's identity and relationship to a Shopify store before acting. Because merchants control their own store and customer relationships, a merchant's customer should ordinarily direct store-related privacy requests to that merchant. CaptainSync will respond to valid Shopify compliance webhooks as required.
09
Changes to this policy
We may update this policy when CaptainSync's functionality, service providers, or legal obligations change. The date at the top identifies the current version. Material changes will be communicated through an appropriate channel where required.
10
Contact
Questions, privacy requests, and security reports:
y.sentuerk@reply.dePlease include the relevant .myshopify.com store domain when contacting us about an installed app.