Legal Document
Privacy Policy
for Merchants & Website Visitors
Introduction
Welcome to Syncnity, a Shopify application that provides an online review collection and marketing solution, owned and operated by Syncnity (a trade name of Syncnity Team, Proprietor) ("we", "us", "our").
This Privacy Policy (for Merchants and Website Visitors) (the "Policy"), which is incorporated into our Terms of Service and our Website Terms of Use, describes what personal information we collect and the policies and procedures we use regarding your personal information ("You", "Merchant" and "Website Visitor") through our syncnity.com website and through our Shopify web application (together — the "Service").
We are committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), UK GDPR, the California Privacy Rights Act (CPRA), and India's Digital Personal Data Protection Act 2023 (DPDP Act).
The Service is not directed to Merchants or Website Visitors under the age of 18. We do not knowingly collect information from children under 18 or knowingly allow them to use the Service.
This Policy may be amended from time to time. We will post any change at a reasonable time in advance of the effective date and will make efforts to proactively notify you by email where we have your email address.
Contact Us
If you have any questions, comments or concerns regarding this Policy or our processing of your personal information, please contact us:
What We Collect and Why
The table below details the personal information we collect from Merchants and Website Visitors, why we collect it, and the legal basis under GDPR where applicable.
| Category | Data Collected | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Store Identity | Shopify store URL, store name, shop ID (received via Shopify OAuth) | To authenticate and identify your store; to provide the Service | Contract Performance |
| Contact Data | Merchant email address, account name | To communicate with you about the Service, billing, and support | Contract Performance |
| Order & Customer Data | Order IDs, fulfilment status, product names, customer names and emails (from your Shopify store via API) | To trigger automated review request emails on your behalf to your customers | Contract Performance |
| Billing Information | Subscription plan, billing cycle, payment status (processed via Shopify Billing API — we do not store card details) | To manage your subscription and process payments | Contract Performance |
| App Configuration | Widget settings, email templates, dashboard preferences, branding choices | To personalise and deliver the Service to your specification | Contract Performance |
| Usage & Analytics Data | Feature interactions, session data, clicks within the Syncnity dashboard | To improve the Service, fix bugs, and understand how features are used | Legitimate Interests |
| Device & Technical Data | Browser type, operating system, IP address, referring URL | To ensure security, detect abuse, and maintain Service stability | Legitimate Interests |
| Website Visitor Data | Pages visited on syncnity.com, session duration, referral source (via cookies and analytics tools) | To understand website traffic and improve our marketing site | Legitimate Interests / |
| Marketing Communications | Email address (if you opt in to marketing) | To send you product updates, feature announcements, and promotional emails | |
| Support Communications | Content of support tickets, chat messages, email correspondence | To respond to and resolve your support requests | Legitimate Interests |
Methods and Sources for Collecting Your Personal Information
We collect personal information from several sources:
- Directly from Shopify when you install and use the Service through the Shopify App Store, or directly from you when you provide information through contact forms, support channels, and email communications.
- From your Shopify store via the Shopify API — specifically, order data and customer contact details needed to send review requests on your behalf.
- From your customers when they interact with the review collection page and submit review content (text, photos, videos).
- From our service providers who help us operate the Service (see our Sub-processors page).
- Through your device when you access the Service, including through third-party cookies and analytics tools, and our own internal event tracking.
You are not legally obligated to provide us with your personal information, but if you do not, we will not be able to handle your enquiry or fulfil your request to access or use the Service's features.
Sharing Your Personal Information
We will not sell your personal information. We will not share your information with third parties, except in the circumstances listed below or when you provide explicit and informed consent.
| Recipient | What We Share | Why | Safeguards |
|---|---|---|---|
| Sub-processors (infrastructure, email, analytics) | Data necessary to provide the relevant service component | To operate the Service (hosting, email delivery, analytics, error monitoring) | Data Processing Agreements; listed at syncnity.com/legal/sub-processors |
| Shopify Inc. | App installation data, billing status | Required to operate within the Shopify platform ecosystem | Governed by Shopify's Partner Agreement and Data Processing Addendum |
| Legal & Regulatory Authorities | Information required by law or court order | To comply with applicable legal obligations | Disclosed only to the extent required; you will be notified where legally permissible |
| Business Successors | Merchant account data and associated records | In the event of a merger, acquisition, or sale of all or part of our business | 30 days' advance notice provided; successor bound by equivalent data protection obligations |
Data Retention and Security
We retain your information for as long as we need it to operate the Service and our business, and thereafter as needed for legal, record-keeping, and dispute resolution purposes. The overall retention period is approximately 7 years.
| Data Type | Retention Period | Reason |
|---|---|---|
| Merchant account & store data | Duration of subscription + 90 days post-termination | To provide the Service and allow data export before deletion |
| Customer data processed on your behalf | While your account is active | Processed per your instructions as data controller |
| Billing records | 7 years | Indian accounting and tax regulations |
| Support communications | 3 years | To resolve disputes and improve support quality |
| Usage analytics & logs | Up to 12 months | Service improvement and security monitoring |
| Website visitor data (cookies) | 12–24 months (per cookie type) | Analytics and session management |
Security Measures
We implement measures to reduce the risks of damage, loss of information, and unauthorized access or use. These include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and multi-factor authentication on all internal systems
- Regular vulnerability scanning and penetration testing
- Data hosted in SOC 2 Type II certified data centres
- Incident response procedures with mandatory breach notification protocols
These measures do not provide absolute information security. Although we make every effort to protect your personal information, we cannot guarantee that it will be immune from all information security risks.
Additional Information for Individuals in the EU or UK
Controller & Processor Status
Syncnity is the data Controller for personal information it collects directly from Merchants and Website Visitors as described in this Policy.
Syncnity is the data Processor for personal information it processes on behalf of Merchants (i.e. your customers' data), as described in our Data Processing Addendum and our Privacy Policy for End Users.
EU & UK Representatives (GDPR Article 27)
As a company based in India offering services to individuals in the EU and UK, we have appointed representatives in these regions:
| EU Representative | [YOUR EU REPRESENTATIVE NAME & URL] Sign up at prighter.com or datarep.com — approx. €100/year |
| EU Contact | info@syncnity.com |
| UK Representative | [YOUR UK REPRESENTATIVE NAME & URL] May be same provider as EU rep — confirm with Prighter/DataRep |
International Data Transfers
If we transfer your information from within the EU or UK to India or other countries not recognised as having adequate data protection, we will do so under a data transfer agreement incorporating Standard Contractual Clauses (SCCs) as determined by the EU Commission (Decision 2021/914), or the UK International Data Transfer Agreement (IDTA) for UK transfers. All transfers include supplementary technical safeguards (encryption in transit and at rest).
Legal Basis for Processing Your Personal Data
The table below sets out the legal basis under GDPR Article 6 for each processing activity:
| Processing Activity | Legal Basis | Detail |
|---|---|---|
| Providing the Service (app functionality) | Art. 6(1)(b) Contract | Necessary to perform the subscription contract with you |
| Sending review request emails to your customers | Art. 6(1)(b) Contract | Core service feature you contracted for |
| Billing and subscription management | Art. 6(1)(b) Contract | Necessary to manage your paid subscription |
| Security, fraud detection, abuse prevention | Art. 6(1)(f) Legitimate Interests | Our legitimate interest in securing the platform |
| Product analytics and Service improvement | Art. 6(1)(f) Legitimate Interests | Our legitimate interest in improving the product |
| Marketing emails (newsletters, product updates) | Only sent with your explicit consent; withdraw anytime | |
| Non-essential cookies on syncnity.com | Via cookie banner on first visit | |
| Record retention for legal obligations | Art. 6(1)(c) Legal Obligation | Tax, accounting, and regulatory requirements |
Your Data Subject Rights
If you are in the EU or UK, you have the following rights under GDPR:
Receive a copy of the personal information we process about you.
Correct inaccurate data and have incomplete data completed.
Request deletion where there is no overriding legitimate ground or legal obligation to retain.
Restrict processing in specific circumstances (e.g. while accuracy is contested).
Receive your data in a structured, machine-readable format and transfer it to another controller.
Object to processing based on legitimate interests. We may override if we have compelling grounds.
Withdraw consent for marketing or non-essential cookies at any time, without affecting prior lawful processing.
Complain to your local supervisory authority. In the UK: ico.org.uk.
To exercise any of these rights, contact us at info@syncnity.com. We will ask you to verify your identity using a 2–3 point verification process before disclosing or acting on any personal data. We aim to respond within 30 days.
Additional Information for California Residents
If you are an individual residing in California, we provide the following information pursuant to the California Privacy Rights Act (CPRA). We do not sell or share your personal information for cross-context behavioural advertising and have not done so in the past 12 months.
Categories of Personal Information Collected (Past 12 Months)
| CPRA Category | Examples Collected | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Name, email address, Shopify store URL, IP address | Directly from you; Shopify | Service provision, authentication, communication |
| Commercial Information | Subscription plan, billing history, product features used | Shopify Billing API; internal records | Billing, account management |
| Internet / Network Activity | App feature usage, dashboard clicks, session data | Analytics tools; internal tracking | Product improvement, security |
| Professional / Business Information | Shopify store name, business type | Shopify | Personalising the Service |
| Communications Data | Support tickets, email correspondence | Directly from you | Customer support |
Disclosures to Third Parties for Business Purposes (Past 12 Months)
| Category Disclosed | Recipient Type | Business Purpose |
|---|---|---|
| Identifiers | Sub-processors (hosting, email, analytics) | Service operation, email delivery, analytics |
| Internet / Network Activity | Analytics providers | Service improvement |
| Commercial Information | Shopify (billing) | Payment processing |
Your CPRA Rights
- Right to Know — the categories and specific pieces of personal information collected about you, the sources, the business purpose, and the third parties to whom we disclose.
- Right to Delete — request deletion of your personal information, subject to applicable legal exceptions.
- Right to Correct — request correction of inaccurate personal information we hold about you.
- Right to Opt-Out of Sale/Sharing — we do not sell or share your data for cross-context behavioural advertising.
- Right to Non-Discrimination — we will not discriminate against you for exercising any CPRA right.
- Right to Limit Use of Sensitive Personal Information — we do not collect sensitive personal information as defined by CPRA beyond what is necessary.
Exercising Your CPRA Rights
Contact us at info@syncnity.com. We will use a 2–3 point identity verification process before responding. You may also designate an authorised agent — provide the agent with written permission and we will require your independent identity verification as well.
If you are a Merchant's customer wishing to exercise CPRA rights regarding data we processed on the Merchant's behalf, please note that we act as a Service Provider following the Merchant's instructions. Submit your request directly to the Merchant.
Do Not Track
We do not currently respond to browser "Do Not Track" signals or similar mechanisms. We do permit third-party analytics providers to collect usage data when you use our Service, as described in our Cookies Policy.
Additional Information for Individuals in India
If you are an individual residing in India, the following additional provisions apply pursuant to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
Grievance Officer
In accordance with the DPDP Act 2023 and the IT Act, we have appointed a Grievance Officer to address any concerns regarding our processing of your personal data:
| Name | Syncnity Team |
| Designation | [Designation] |
| info@syncnity.com | |
| Response Time | Within 30 days of receipt of your grievance |
Your Rights Under the DPDP Act 2023
- Right to Access — request a summary of personal data processed and processing activities.
- Right to Correction and Erasure — request correction of inaccurate or incomplete data, or erasure where retention is no longer necessary.
- Right to Grievance Redressal — raise a grievance with our Grievance Officer; we will respond within 30 days.
- Right to Nominate — nominate another individual to exercise rights on your behalf in the event of death or incapacity.
Consent
Where we rely on your consent to process personal data under the DPDP Act, you have the right to withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing prior to withdrawal. To withdraw consent or exercise any DPDP right, contact our Grievance Officer at info@syncnity.com.
Related documents: Data Processing Addendum · Privacy Policy for End Users · Sub-processors · Cookies Policy