This Privacy Policy explains how Syncwright handles data when it syncs a merchant's Lightspeed Retail R-Series point of sale with their Shopify store. It is written to be specific and honest: every statement below reflects how the application actually works.
Who we are
Syncwright is a Shopify application operated by Avocado Blvd LLC, trading as Outside Projects (“Syncwright”, “we”, “us”), registered at 2940 Calle Grande Vista, San Clemente, CA 92672. Syncwright is a multi-tenant application that synchronizes product, inventory, order, and customer data between Lightspeed Retail R-Series and Shopify. Each merchant connects their own Lightspeed account and their own Shopify store.
For any privacy question, or to reach the person responsible for data protection, email jonathan@outsideprojects.com or help@syncwright.io.
Our role: processor, not controller
When Syncwright handles the personal information of a merchant's customers, the merchant is the data controller and Syncwright is a data processor acting on the merchant's behalf and on their instructions. We do not decide the purposes for which a merchant's customer data is processed; we move it between the merchant's two systems so their records stay in step. The merchant's own privacy policy governs its relationship with its customers. Our obligations as a processor are set out in our Data Processing Addendum.
For the merchant's own account information (for example, the store owner's contact details and the connection settings needed to run the sync), Syncwright acts as the controller.
What data we process
Merchant account data
To operate the service we hold the information needed to connect and run each store: the Shopify store domain and the connection credentials (OAuth tokens) for Shopify and Lightspeed, plus sync settings and support correspondence.
Customer personal information
To match records and push orders, Syncwright accesses the following customer personal information
from Shopify through the read_customers and read_orders scopes:
- Name
- Email address
- Phone number
- Shipping and billing address
This is Protected Customer Data under Shopify's Protected Customer Data requirements, and the fields above (name, email, phone, and address) are Level 2 protected customer fields. Syncwright does not access payment card data, government identification, passwords, or any account credentials of a merchant's customers.
Why we process it
Syncwright uses customer personal information for three purposes, and only these three:
- Customer matching across the two systems. We match a Shopify customer to a Lightspeed customer, using email as the primary key and name as a fallback, so an order or record is attached to the right person instead of creating duplicates.
- Creating the sale in Lightspeed. When a Shopify order is pushed to Lightspeed, we create the corresponding sale and customer record in the merchant's Lightspeed account.
- Merchant-facing sync error logs. When a sync fails, we record the error so the merchant can fix it. A customer email may appear in that log, and it is shown only to the merchant who owns the store.
Legal bases
Where the EU or UK GDPR applies, processing rests on the following bases:
- Processing on behalf of the merchant (Article 28). Syncwright processes customer personal information as a processor, on the documented instructions of the merchant. The merchant, as controller, is responsible for having a lawful basis for that processing.
- Performance of a contract (Article 6(1)(b)). For merchant account data, we process what is necessary to provide the service the merchant has signed up for.
- Legitimate interests (Article 6(1)(f)). For securing the service, preventing abuse, keeping error logs, and providing support, balanced against the rights of the individuals concerned.
Data minimization
Syncwright reads only the fields it needs for the purposes above. Any other fields returned by
Shopify or Lightspeed are discarded and never stored. For example, the Lightspeed
customSku field is not used. We do not build customer profiles, and we do not enrich
customer records with data from anywhere else.
No sale of data, no secondary use
Syncwright does not sell, rent, or share customer personal information. We do not use it for marketing, advertising, resale, analytics, or profiling, and we do not use it for any purpose other than the three sync purposes listed above. There is no secondary use of a merchant's customer data, full stop.
Data retention
Customer personal information is not stored at rest in the Syncwright database. It passes through the Cloudflare Workers engine to the Lightspeed API in flight only, for the moment it takes to complete a match or create a sale.
Our database (Cloudflare D1) stores only:
- Sync metadata: Shopify and Lightspeed record identifiers, timestamps, and error codes
- Per-merchant connection credentials (OAuth tokens), held as secrets
We keep this metadata for as long as the merchant uses the service, so the sync can reconcile correctly over time. When a merchant uninstalls the app, we delete their data as described below.
Your rights, access, and deletion
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal information, and to object to processing or request portability. Because Syncwright acts as a processor, a shopper should usually contact the merchant (the store they bought from) to exercise these rights. The merchant can then instruct us, and we will assist.
Syncwright honors Shopify's three mandatory compliance webhooks. Each request is verified for
authenticity using an HMAC signature (X-Shopify-Hmac-SHA256) and completed within 30
days:
-
customers/data_request: a request to view stored personal data. Syncwright acknowledges the request; because we do not store customer personal information at rest, there is no stored customer PII for us to export. -
customers/redact: a request to erase a customer. We delete the tenant-scoped sync metadata associated with that customer. -
shop/redact: sent 48 hours after a store uninstalls. We delete all of that store's rows, including its stored connection credentials.
You can also contact us directly at jonathan@outsideprojects.com and we will route your request appropriately.
Subprocessors
We use a small set of subprocessors to run the service. The current list, what each one does, and where it operates is maintained on our Subprocessors page. The optional image-enrichment providers process product images only and never receive customer personal information.
International transfers
Syncwright runs on Cloudflare's global edge network, and our subprocessors operate internationally, so data may be processed in countries other than your own, including the United States. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Details are in our Data Processing Addendum.
Security
We protect data with encryption in transit (TLS) and at rest, store connection credentials as secrets that are never written to logs, require multi-factor authentication for production access, and maintain a written incident-response policy. Our full Security overview describes these measures.
Children
Syncwright is a business-to-business tool for retailers. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. Any customer personal information we process arrives from a merchant's own systems in the course of their sales.
Changes to this policy
We may update this policy as the product or the law changes. The current version always lives on this page, with the effective date at the top. Material changes will be communicated to merchants through the app or by email.
Contact
Questions about this policy, or about how your data is handled, can go to jonathan@outsideprojects.com or help@syncwright.io.