Privacy Policy
Last updated: 2026-09-07
Order Sync Guardian (“the app”, “we”) is a Shopify app that syncs your store’s orders one-way into a Google Sheet that the app creates in your connected Google account. This policy explains what data we process, why, where it goes, and how long we keep it.
Data we process
- Order data from your Shopify store: order id and name, creation time, line items (SKU, product/variant title, quantity, unit price, line total), currency, financial and fulfillment status, and cancellation/refund events.
- Customer personal data attached to those orders: customer name, email address, and shipping address. These are written into your Google Sheet so you can fulfil and route orders.
- Google account data: when you connect Google, we store an OAuth refresh token and short-lived access token (encrypted at rest) and the email address of the connected account. We use the
drive.filescope only, which limits our access to the single spreadsheet the app creates — we cannot see any of your other Google Drive files. - App configuration: your alert email address and sync bookkeeping (queue state, heartbeat timestamps).
How we use it
- To append order rows to the Google Sheet the app created for you.
- To detect and recover missing orders (the “heartbeat”) and to email you alerts when a sync problem is found.
- To operate billing and the app’s core functionality.
We do not sell your data, use it for advertising, or write anything back into your Shopify store. Sync is strictly one-way (Shopify → Sheet).
Sub-processors
- Fly.io — application hosting and database (data stored in the Tokyo, Japan region).
- Google (Sheets & Drive API) — the destination for your synced data, in the Google account you connect.
- Resend — transactional email delivery for sync alerts.
Retention
We keep your data only while the app is installed. When you uninstall, we immediately revoke and delete your Google OAuth tokens, and we delete all of your data within 30 days. Shopify also sends us a shop redaction request roughly 48 hours after uninstall, on receipt of which we erase everything we hold for your store. We honour Shopify’s mandatory privacy webhooks: customer data request, customer redaction (we mask the personal-data columns of the affected rows in our records), and shop redaction.
The Google Sheet itself lives in your Google account and remains under your control; deleting rows there is your responsibility.
Security
Google OAuth tokens and Shopify credentials are encrypted at rest and scoped per store. Transport is over HTTPS.
Your rights & contact
To request access to, correction of, or deletion of your data, uninstall the app or contact us at support@ordersyncguardian.example. Depending on your jurisdiction (e.g. GDPR/CCPA) you may have additional rights; we will honour applicable requests.
Order Sync Guardian