Syncsafe privacy policy
Last updated 21 August 2026
Who this is about
Syncsafe is a Shopify app operated by Firuz Shirinov. This policy covers the data the app processes when a merchant installs it on a Shopify store. Contact: firuz.shirinov@gmail.com.
What Syncsafe stores
The complete list. Syncsafe requests the Shopify access scopes read_products, read_inventory, write_inventory and read_locations, and stores only what those return.
About your store
- Your
.myshopify.comdomain and store name. - The ID of the store location Syncsafe syncs stock against.
- Which two stores you have connected, and the settings for that connection.
- Your subscription status, its Shopify subscription ID, and the dates Shopify reports for it. Syncsafe never sees or stores payment card details — billing is handled entirely by Shopify.
About your products
- Product and variant titles, Shopify variant and inventory item IDs, SKUs, and whether inventory tracking is enabled.
- Stock quantities, before and after each change.
A record of what the app did
- Every inventory change Syncsafe handled: which item, what quantity, when Shopify recorded it, and what Syncsafe decided to do about it. This log is append-only and is the core of how the app works — it is what lets you see that a bad stock number was refused rather than silently written.
- The raw Shopify webhook that triggered each change. These contain inventory item IDs, location IDs, quantities and timestamps.
Access credentials
- The Shopify OAuth access token and refresh token for your store, which is how the app reads and writes inventory on your behalf. These are held only in the app’s session store and are never sent anywhere else.
What Syncsafe does not store
Syncsafe holds no customer data of any kind. It does not request the access scopes that would let it read customers or orders, and there is no field anywhere in its database for a customer name, email address, phone number, shipping address, order or payment method.
It also stores no personal data about you or your staff. Syncsafe uses Shopify offline sessions, which identify a store rather than a person, and carry no name, email address or user ID.
Consequently, when Shopify sends the mandatory customers/data_request or customers/redact requests, Syncsafe has nothing to disclose and nothing to delete. It records that the request arrived and was answered, without storing any detail about the customer it concerned.
How long it is kept
Data is kept for as long as the app is installed, because the record of past stock changes is the app’s main function.
When you uninstall Syncsafe, Shopify sends a shop/redact request 48 hours later, and Syncsafe erases everything belonging to that store: the store record, its connection, its SKU mappings, its sync state and its entire change history. This is permanent and cannot be undone. If you reinstall within those 48 hours, your data and your history are kept and the app resumes where it left off.
One thing worth knowing before you uninstall: a connection’s history is erased if either of its two stores is redacted, because each record refers to both. Removing the app from the destination store therefore erases the history held for the source store too.
After an erasure, Syncsafe retains one row recording that the erasure happened: the store domain and Shopify store ID, the ID of Shopify’s request, the date it was requested and the date it completed, whether it completed, and a count of how many records were deleted from each table. That is the minimum needed to demonstrate the request was honoured, and it contains no product, stock or personal data — the counts are numbers, not the records themselves.
Who else sees it
Syncsafe does not sell data, does not share it with advertisers, and does not use it to train anything. It is processed only by:
- Shopify — the source of the data and the destination of the writes.
- Railway — the hosting provider running the application and its PostgreSQL database.
Data is transmitted over TLS at every hop, including between Syncsafe’s own components.
Your rights
You can uninstall Syncsafe at any time from your Shopify admin, which starts the erasure described above. You can also ask for a copy of everything held about your store, or for it to be deleted sooner, by emailing firuz.shirinov@gmail.com. Requests are answered within 30 days.
Changes
If this policy changes materially, the date at the top changes with it and merchants with the app installed are notified by email at the address Shopify holds for the store owner.