Syncnity
  • Features
  • Widgets
  • Integrations
  • Pricing
  • FAQ
Get Started

Legal Document

Privacy Policy
for Merchants & Website Visitors

Last updated: March 1, 2025
Applies to: Merchants & Visitors
GDPR Compliant UK GDPR CPRA / California India DPDP Act 2023

Introduction

Welcome to Syncnity, a Shopify application that provides an online review collection and marketing solution, owned and operated by Syncnity (a trade name of Syncnity Team, Proprietor) ("we", "us", "our").

This Privacy Policy (for Merchants and Website Visitors) (the "Policy"), which is incorporated into our Terms of Service and our Website Terms of Use, describes what personal information we collect and the policies and procedures we use regarding your personal information ("You", "Merchant" and "Website Visitor") through our syncnity.com website and through our Shopify web application (together — the "Service").

We are committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), UK GDPR, the California Privacy Rights Act (CPRA), and India's Digital Personal Data Protection Act 2023 (DPDP Act).

The Service is not directed to Merchants or Website Visitors under the age of 18. We do not knowingly collect information from children under 18 or knowingly allow them to use the Service.

This Policy may be amended from time to time. We will post any change at a reasonable time in advance of the effective date and will make efforts to proactively notify you by email where we have your email address.

Contact Us

If you have any questions, comments or concerns regarding this Policy or our processing of your personal information, please contact us:

Get in Touch

Email: info@syncnity.com
Support: syncnity.com/contact

What We Collect and Why

The table below details the personal information we collect from Merchants and Website Visitors, why we collect it, and the legal basis under GDPR where applicable.

Category Data Collected Purpose Legal Basis (GDPR)
Store Identity Shopify store URL, store name, shop ID (received via Shopify OAuth) To authenticate and identify your store; to provide the Service Contract Performance
Contact Data Merchant email address, account name To communicate with you about the Service, billing, and support Contract Performance
Order & Customer Data Order IDs, fulfilment status, product names, customer names and emails (from your Shopify store via API) To trigger automated review request emails on your behalf to your customers Contract Performance
Billing Information Subscription plan, billing cycle, payment status (processed via Shopify Billing API — we do not store card details) To manage your subscription and process payments Contract Performance
App Configuration Widget settings, email templates, dashboard preferences, branding choices To personalise and deliver the Service to your specification Contract Performance
Usage & Analytics Data Feature interactions, session data, clicks within the Syncnity dashboard To improve the Service, fix bugs, and understand how features are used Legitimate Interests
Device & Technical Data Browser type, operating system, IP address, referring URL To ensure security, detect abuse, and maintain Service stability Legitimate Interests
Website Visitor Data Pages visited on syncnity.com, session duration, referral source (via cookies and analytics tools) To understand website traffic and improve our marketing site Legitimate Interests / Consent
Marketing Communications Email address (if you opt in to marketing) To send you product updates, feature announcements, and promotional emails Consent
Support Communications Content of support tickets, chat messages, email correspondence To respond to and resolve your support requests Legitimate Interests

Methods and Sources for Collecting Your Personal Information

We collect personal information from several sources:

  • Directly from Shopify when you install and use the Service through the Shopify App Store, or directly from you when you provide information through contact forms, support channels, and email communications.
  • From your Shopify store via the Shopify API — specifically, order data and customer contact details needed to send review requests on your behalf.
  • From your customers when they interact with the review collection page and submit review content (text, photos, videos).
  • From our service providers who help us operate the Service (see our Sub-processors page).
  • Through your device when you access the Service, including through third-party cookies and analytics tools, and our own internal event tracking.

You are not legally obligated to provide us with your personal information, but if you do not, we will not be able to handle your enquiry or fulfil your request to access or use the Service's features.

Sharing Your Personal Information

We will not sell your personal information. We will not share your information with third parties, except in the circumstances listed below or when you provide explicit and informed consent.

Recipient What We Share Why Safeguards
Sub-processors (infrastructure, email, analytics) Data necessary to provide the relevant service component To operate the Service (hosting, email delivery, analytics, error monitoring) Data Processing Agreements; listed at syncnity.com/legal/sub-processors
Shopify Inc. App installation data, billing status Required to operate within the Shopify platform ecosystem Governed by Shopify's Partner Agreement and Data Processing Addendum
Legal & Regulatory Authorities Information required by law or court order To comply with applicable legal obligations Disclosed only to the extent required; you will be notified where legally permissible
Business Successors Merchant account data and associated records In the event of a merger, acquisition, or sale of all or part of our business 30 days' advance notice provided; successor bound by equivalent data protection obligations

Data Retention and Security

We retain your information for as long as we need it to operate the Service and our business, and thereafter as needed for legal, record-keeping, and dispute resolution purposes. The overall retention period is approximately 7 years.

Data Type Retention Period Reason
Merchant account & store data Duration of subscription + 90 days post-termination To provide the Service and allow data export before deletion
Customer data processed on your behalf While your account is active Processed per your instructions as data controller
Billing records 7 years Indian accounting and tax regulations
Support communications 3 years To resolve disputes and improve support quality
Usage analytics & logs Up to 12 months Service improvement and security monitoring
Website visitor data (cookies) 12–24 months (per cookie type) Analytics and session management

Security Measures

We implement measures to reduce the risks of damage, loss of information, and unauthorized access or use. These include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and multi-factor authentication on all internal systems
  • Regular vulnerability scanning and penetration testing
  • Data hosted in SOC 2 Type II certified data centres
  • Incident response procedures with mandatory breach notification protocols

These measures do not provide absolute information security. Although we make every effort to protect your personal information, we cannot guarantee that it will be immune from all information security risks.

Additional Information for Individuals in the EU or UK

Controller & Processor Status

Syncnity is the data Controller for personal information it collects directly from Merchants and Website Visitors as described in this Policy.

Syncnity is the data Processor for personal information it processes on behalf of Merchants (i.e. your customers' data), as described in our Data Processing Addendum and our Privacy Policy for End Users.

EU & UK Representatives (GDPR Article 27)

As a company based in India offering services to individuals in the EU and UK, we have appointed representatives in these regions:

EU Representative [YOUR EU REPRESENTATIVE NAME & URL]
Sign up at prighter.com or datarep.com — approx. €100/year
EU Contact info@syncnity.com
UK Representative [YOUR UK REPRESENTATIVE NAME & URL]
May be same provider as EU rep — confirm with Prighter/DataRep

International Data Transfers

If we transfer your information from within the EU or UK to India or other countries not recognised as having adequate data protection, we will do so under a data transfer agreement incorporating Standard Contractual Clauses (SCCs) as determined by the EU Commission (Decision 2021/914), or the UK International Data Transfer Agreement (IDTA) for UK transfers. All transfers include supplementary technical safeguards (encryption in transit and at rest).

Legal Basis for Processing Your Personal Data

The table below sets out the legal basis under GDPR Article 6 for each processing activity:

Processing Activity Legal Basis Detail
Providing the Service (app functionality) Art. 6(1)(b) Contract Necessary to perform the subscription contract with you
Sending review request emails to your customers Art. 6(1)(b) Contract Core service feature you contracted for
Billing and subscription management Art. 6(1)(b) Contract Necessary to manage your paid subscription
Security, fraud detection, abuse prevention Art. 6(1)(f) Legitimate Interests Our legitimate interest in securing the platform
Product analytics and Service improvement Art. 6(1)(f) Legitimate Interests Our legitimate interest in improving the product
Marketing emails (newsletters, product updates) Art. 6(1)(a) Consent Only sent with your explicit consent; withdraw anytime
Non-essential cookies on syncnity.com Art. 6(1)(a) Consent Via cookie banner on first visit
Record retention for legal obligations Art. 6(1)(c) Legal Obligation Tax, accounting, and regulatory requirements

Your Data Subject Rights

If you are in the EU or UK, you have the following rights under GDPR:

Right to Access

Receive a copy of the personal information we process about you.

Right to Rectification

Correct inaccurate data and have incomplete data completed.

Right to Erasure

Request deletion where there is no overriding legitimate ground or legal obligation to retain.

Right to Restriction

Restrict processing in specific circumstances (e.g. while accuracy is contested).

Right to Data Portability

Receive your data in a structured, machine-readable format and transfer it to another controller.

Right to Object

Object to processing based on legitimate interests. We may override if we have compelling grounds.

Withdraw Consent

Withdraw consent for marketing or non-essential cookies at any time, without affecting prior lawful processing.

Right to Lodge a Complaint

Complain to your local supervisory authority. In the UK: ico.org.uk.

To exercise any of these rights, contact us at info@syncnity.com. We will ask you to verify your identity using a 2–3 point verification process before disclosing or acting on any personal data. We aim to respond within 30 days.

Additional Information for California Residents

If you are an individual residing in California, we provide the following information pursuant to the California Privacy Rights Act (CPRA). We do not sell or share your personal information for cross-context behavioural advertising and have not done so in the past 12 months.

Categories of Personal Information Collected (Past 12 Months)

CPRA Category Examples Collected Source Business Purpose
Identifiers Name, email address, Shopify store URL, IP address Directly from you; Shopify Service provision, authentication, communication
Commercial Information Subscription plan, billing history, product features used Shopify Billing API; internal records Billing, account management
Internet / Network Activity App feature usage, dashboard clicks, session data Analytics tools; internal tracking Product improvement, security
Professional / Business Information Shopify store name, business type Shopify Personalising the Service
Communications Data Support tickets, email correspondence Directly from you Customer support

Disclosures to Third Parties for Business Purposes (Past 12 Months)

Category Disclosed Recipient Type Business Purpose
Identifiers Sub-processors (hosting, email, analytics) Service operation, email delivery, analytics
Internet / Network Activity Analytics providers Service improvement
Commercial Information Shopify (billing) Payment processing

Your CPRA Rights

  • Right to Know — the categories and specific pieces of personal information collected about you, the sources, the business purpose, and the third parties to whom we disclose.
  • Right to Delete — request deletion of your personal information, subject to applicable legal exceptions.
  • Right to Correct — request correction of inaccurate personal information we hold about you.
  • Right to Opt-Out of Sale/Sharing — we do not sell or share your data for cross-context behavioural advertising.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any CPRA right.
  • Right to Limit Use of Sensitive Personal Information — we do not collect sensitive personal information as defined by CPRA beyond what is necessary.

Exercising Your CPRA Rights
Contact us at info@syncnity.com. We will use a 2–3 point identity verification process before responding. You may also designate an authorised agent — provide the agent with written permission and we will require your independent identity verification as well.

If you are a Merchant's customer wishing to exercise CPRA rights regarding data we processed on the Merchant's behalf, please note that we act as a Service Provider following the Merchant's instructions. Submit your request directly to the Merchant.

Do Not Track

We do not currently respond to browser "Do Not Track" signals or similar mechanisms. We do permit third-party analytics providers to collect usage data when you use our Service, as described in our Cookies Policy.

Additional Information for Individuals in India

If you are an individual residing in India, the following additional provisions apply pursuant to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.

Grievance Officer

In accordance with the DPDP Act 2023 and the IT Act, we have appointed a Grievance Officer to address any concerns regarding our processing of your personal data:

Name Syncnity Team
Designation [Designation]
Email info@syncnity.com
Response Time Within 30 days of receipt of your grievance

Your Rights Under the DPDP Act 2023

  • Right to Access — request a summary of personal data processed and processing activities.
  • Right to Correction and Erasure — request correction of inaccurate or incomplete data, or erasure where retention is no longer necessary.
  • Right to Grievance Redressal — raise a grievance with our Grievance Officer; we will respond within 30 days.
  • Right to Nominate — nominate another individual to exercise rights on your behalf in the event of death or incapacity.

Consent

Where we rely on your consent to process personal data under the DPDP Act, you have the right to withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing prior to withdrawal. To withdraw consent or exercise any DPDP right, contact our Grievance Officer at info@syncnity.com.

Related documents: Data Processing Addendum · Privacy Policy for End Users · Sub-processors · Cookies Policy

Syncnity

Sync Everything. Scale Anywhere

Simple review collection and display for Shopify—no complexity.

info@syncnity.com

Product

  • Features
  • How it works
  • Pricing
  • FAQ
  • Get started

Resources

  • Docs
  • Help Center
  • About

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookies Policy
  • Data Processing Agreement
  • Grievance Officer

© 2026 Syncnity · All rights reserved