1. Who we are
Syncstocky is an independently operated software service. When this policy refers to “Syncstocky”, “we”, “us”, or “our”, it means the operator of the Syncstocky service at syncstocky.com.
You can contact us about privacy matters at: privacy@syncstocky.com
2. What data we collect
Account data
When you create an account, we collect your email address, name, and a hashed password (or your Google OAuth identity). We use this to authenticate you and identify your account.
Store and channel data
When you connect a sales channel (Shopify, Amazon, eBay, Etsy, Walmart), we store:
- OAuth access tokens required to call the channel’s API on your behalf
- Your store name, domain, and basic store metadata
- Product data: SKUs, titles, inventory quantities, variant information
- Order data required to trigger inventory sync events
We access this data only to perform inventory synchronisation and the features you’ve explicitly enabled. We do not read your customers’ personal information beyond what is strictly necessary to process sync events (e.g. order quantities).
Sync and usage data
We log every sync event: timestamp, channel, SKU, quantity change, and success/failure status. This data powers your Sync Log and is retained for 90 days. After 90 days, detailed event logs are automatically deleted.
Billing data
Payments are processed by Shopify if you installed Syncstocky from the Shopify App Store, or by Paddle if you signed up directly at syncstocky.com. Syncstocky never sees or stores your credit card number in either case. We receive only confirmation of your plan, billing status, and subscription history — from Shopify’s Partner API, or from Paddle’s webhook events. The privacy policy of whichever provider bills you governs how your payment information is handled.
AI forecasting data
If you use Pro plan AI forecasting features, inventory and sales data is sent to the Anthropic Claude API to generate forecasts and recommendations. We send only aggregated SKU-level data — no personally identifiable customer information. Claude API data handling is governed by Anthropic’s privacy policy. We store one forecast row per SKU and overwrite it on each refresh.
Technical data
We collect standard server logs including IP addresses, browser type, and page requests. These are used for security monitoring and debugging and are not linked to your account for marketing purposes.
3. How we use your data
- To provide the service — syncing inventory across your connected channels in real time
- To authenticate you — keeping your account secure
- To generate AI forecasts — sending SKU data to Claude API on the Pro plan
- To process billing — communicating subscription status with Shopify or Paddle, depending on how you signed up
- To send transactional emails — sync failure alerts, low stock notifications, trial reminders
- To improve the product — understanding which features are used and where errors occur
We do not use your data for advertising. We do not sell your data to third parties. We do not profile your customers.
4. Data sharing
We share data with the following categories of third parties, strictly to operate the service:
- Shopify — payment processing and subscription management for merchants who installed from the Shopify App Store
- Paddle — payment processing and subscription management for merchants who signed up directly
- Anthropic — Claude API for AI forecasting features (Pro plan only)
- Supabase — database and authentication infrastructure
- Render — cloud hosting of the Syncstocky application
- Shopify, Amazon, eBay, Etsy, Walmart — your connected channels, which receive inventory update calls on your behalf
We do not share data with analytics companies, advertising networks, or data brokers.
5. Data retention
- Sync event logs — 90 days, then auto-deleted nightly
- Order line items — 12 months
- AI forecasts — 1 row per SKU, overwritten on each new forecast
- Notifications — 30 days
- Account data — retained while your account is active; deleted within 30 days of account deletion request
6. Your rights
You have the right to:
- Access — request a copy of all data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — request deletion of your account and associated data
- Export — download your sync history and SKU mappings as CSV from your dashboard at any time
- Disconnect channels — revoke Syncstocky’s access to any channel at any time from your Channels page
To exercise any of these rights, email privacy@syncstocky.com. We respond within 14 days.
7. Security
All data is encrypted in transit (TLS 1.2+). OAuth tokens are stored encrypted at rest. We use Supabase Row Level Security to ensure each user can only access their own data. Incoming webhooks from Shopify, Paddle, and your connected channels are verified using HMAC-SHA256 signatures before we act on them. We conduct periodic security reviews of our infrastructure and dependencies.
8. Cookies
Syncstocky uses a single session authentication cookie to keep you logged in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. The session cookie is essential for the service to function.
9. Children
Syncstocky is a business tool not intended for use by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.
10. Changes to this policy
If we make material changes to this policy, we will notify you by email at least 14 days before the change takes effect. The updated policy will always be available at syncstocky.com/privacy.
11. Contact
For privacy questions, data requests, or concerns:
- Email: privacy@syncstocky.com
- Service: Syncstocky (syncstocky.com)