Privacy Policy

Last updated: September 19, 2026

SyncNest ("the App", "we", "our", "us"), published by AppNest Studios, is a Shopify app that syncs a merchant's Shopify data (orders, products, inventory, customers, refunds) to and from the merchant's own Google Sheets in real time. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.

Contact / Data Protection: [email protected]

1. Who the data belongs to

The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's Shopify store data solely to provide the sync service the merchant configured.

2. What we access and why

Shopify data (via the Shopify Admin API)

We request the minimum scopes needed for the syncs the merchant enables:

ScopeWhy
read_orders, write_ordersSync orders to a sheet; optional write-back of order tags & notes
read/write_merchant_managed_fulfillment_ordersOptional write-back of tracking numbers / fulfilling orders from the sheet
read_products, write_productsSync products; optional write-back of product edits
read_inventory, write_inventorySync inventory; optional write-back of quantities
read_locationsResolve inventory location names
read_customersSync customers (only if the merchant enables a customer sync)

Order and customer records may contain personal data (names, email addresses, shipping/billing addresses) when the merchant chooses to map those columns. That data flows from Shopify to the merchant's own Google Sheet. We do not retain the field values — see §4.

Google account data (via Google OAuth)

We request only:

SyncNest's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. What we store

DataStored?Notes
Shopify session / access tokenYesRequired to call the Admin API
Google refresh tokenYesEncrypted at rest (AES-256-GCM)
Google account emailYesShown so you know which account is connected
Sync configuration (resource, direction, column mapping, sheet id/tab)YesYour settings
Alert email / Slack webhook URLYesWhere to notify you on failure
Row index (record ID + row number + value hash)YesKeeps syncs idempotent
Job/run history, usage counts, audit actionsYesOperational metadata
Order / product / customer field valuesNoWritten to your Google Sheet; not persisted by us

The row-index hash is a one-way fingerprint used to detect changes and keep syncs idempotent — it does not store or reveal the underlying values.

4. Data retention & deletion

5. Subprocessors / third parties

ProviderPurposeData shared
Google (Sheets & Drive API)The sync targetThe data you configure to sync
Hosting (Railway) + Postgres/RedisRun the AppStored data listed in §3
ResendFailure-alert emails (if configured)Your alert email + error summary
SlackFailure-alert messages (if configured)Your webhook + error summary
SentryError tracking (if configured)Diagnostic error data

We do not sell personal data or use it for advertising.

6. Security

7. Your rights

Merchants can export or delete their data by uninstalling the App (triggers full deletion) or by contacting us at the address above. Data subjects should contact the merchant (controller) for GDPR/CCPA requests; we assist the merchant in fulfilling them.

8. Changes

We will update this policy as the App evolves and revise the "Last updated" date above.

SyncNest by AppNest Studios · [email protected]