Not legal advice. This draft was written by the Sync Pulze team as a plain-language starting point. Have a qualified lawyer review it against your jurisdiction and business specifics before publishing.

Privacy Policy

Last updated: February 5, 2026 (draft)

1. What we collect

Sync Pulze is a Shopify app for merchants. To provide the sync features you install us for, we collect and process the following categories of data from the shops you connect:

• Shopify shop identity — the shop domain (e.g. your-store.myshopify.com), shop name, the OAuth access token issued to Sync Pulze, and the scopes you grant.

• Product & inventory data — product titles, SKUs, variants, images, stock levels, listing prices, and cost prices for the products Sync Pulze manages on your behalf.

• Supplier connection data — supplier provider (AliExpress, AutoDS, CJ Dropshipping, TeemDrop), connection status, sync history, and cost/stock feeds returned by those suppliers.

• Account data — the email address, name, and password hash you use to sign in to Sync Pulze (bcrypt-hashed, we never store or see the plaintext password).

• Billing metadata — subscription tier, status, and transaction identifiers from Shopify Billing API or Stripe (depending on the distribution channel you installed through). We do not receive or store your payment card details.

Sync Pulze does not access the personal data of your shop's end-customers (names, addresses, order history) unless a future feature explicitly requires it — and that would only happen after we prompt you to grant an additional scope.

2. How we use it

• Inventory sync — detecting supplier out-of-stock events and hiding/unpublishing the corresponding Shopify products; auto-publishing when stock returns.

• Price sync — recomputing your Shopify listing prices when a supplier cost changes, according to the markup rule you configure.

• Margin dashboard — showing your live cost, price, margin, and at-risk products.

• Activity log — retaining a history of the automated actions we took on your store so you can audit them.

• Support — troubleshooting sync issues when you contact us.

We do not use your data to train machine learning models, advertise to your customers, or benchmark you against other merchants.

3. Who we share it with

Sync Pulze does not sell your data. We share it only with the following categories of processors, and only to the minimum extent required to run the service:

• Shopify Inc. — we call the Shopify Admin API on your behalf, using the access token you granted us.

• Your chosen suppliers (e.g. CJ Dropshipping) — we call their APIs to fetch cost/stock feeds for the products you asked us to sync.

• Payment processors — Shopify Billing (for App Store-installed merchants) or Stripe (for direct/non-Shopify distribution) handle subscription billing. We never see or store your card number.

• Cloud infrastructure — the servers and MongoDB database that host Sync Pulze.

We do not disclose your data to advertisers, data brokers, or affiliated products.

4. Data retention & deletion

For as long as your Shopify store is connected to Sync Pulze we retain the categories of data listed in section 1.

If you uninstall the app from your Shopify admin, Shopify sends us a shop/redact webhook 48 hours after uninstall. Upon receiving it, Sync Pulze permanently deletes: your store record, all sources, all products, the activity log, all payment/subscription records, all pending billing tokens, and all OAuth state — for that shop. This deletion is automatic and non-recoverable.

If a customer of your shop requests their data or deletion, and Shopify forwards us that request (customers/data_request, customers/redact), we log the event and acknowledge it. Sync Pulze does not currently store per-customer PII, so there is normally nothing to return or delete beyond the acknowledgement.

You can also request deletion at any time by emailing support (see section 8) — we will delete your account and associated data within 30 days.

5. Security

Passwords are stored as bcrypt hashes. Session cookies are HTTP-only, Secure, and SameSite=None. Access tokens for Shopify are stored server-side and never returned to the browser. Payment processing runs on Shopify Billing or Stripe — both PCI-DSS Level 1 certified.

Despite these controls, no service can guarantee absolute security. In the unlikely event of a breach affecting your data, we will notify you and any applicable authorities as required by law.

6. International transfers

Sync Pulze operates on cloud infrastructure that may transfer and process data across borders. By using the service you consent to those transfers subject to the safeguards required by applicable law (SCCs, adequacy decisions, etc.).

7. Your rights

Depending on your jurisdiction (GDPR, CCPA, PIPEDA, etc.) you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. Contact us at the email in section 8 to exercise them.

8. Contact

Questions about this policy or your data? Email us at bagels0001@gmail.com.

This is a placeholder address until a production support inbox is established — please replace before public release.

9. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app and by email at least 14 days before they take effect.