Legal · App Privacy Policy

App Privacy Policy

What the WySync Fitment Shopify app accesses, what we store, who processes it, and the data protection commitments we make to merchants.

Applies to: the WySync Fitment application distributed through the Shopify App Store and installed on merchant Shopify stores. Provider: Pound Pixel LLC, trading as WySync ("WySync", "we", "us"). Last updated: 12 August 2026.

This policy covers the app. Our website is covered separately by the wysync.com privacy policy.

1. Who is responsible for what#

When you install WySync Fitment, two different relationships exist at once, and they carry different obligations.

RoleApplies to
You, the merchantControllerYour store's product, order and customer data. You decide what is collected and why.
WySyncProcessorThe same data, which we process only to provide the app to you, on your documented instructions.
WySyncControllerYour own account data — the shop record, plan, billing state, support correspondence.

Where we act as processor, Section 10 sets out the commitments we make to you.

2. What the app accesses in your Shopify store#

Shopify asks you to approve a set of access scopes at install. This is every scope the app requests and the specific reason for each one. We do not use them for any other purpose.

ScopeWhat it reachesWhy
read_productsTitles, variants, SKUs, prices, product metafieldsThe catalog that gets indexed and made searchable
write_productsProduct metafield definitions onlyCreates the wysync.universal_fit and wysync.fitment_note definitions at install so the fitment editor has somewhere to write
read_product_listingsPublication statusDetermines which products are visible on your storefront
read_inventoryStock levelsThe in stock / low stock / out of stock facet
read_metaobjects, write_metaobjectsMetaobjects in your storeStores fitment sources and mapping configuration
read_ordersOrder line items and their propertiesReads back the vehicle and fitment verdict the app wrote at checkout, for merchant reporting
read_themesTheme structureDetects whether the app's storefront blocks are installed on your published theme
read_customers, write_customersA single customer metafield, wysync.garageSaves a logged-in shopper's garage so it follows them across devices
read_publications, write_publicationsSales channel publicationPublishes generated vehicle landing pages to your Online Store channel
Protected Customer Data

read_customers, write_customers and read_orders are classified by Shopify as Protected Customer Data. Their use here is deliberately narrow: the customer scopes touch exactly one metafield (wysync.garage) and no other customer field, and the order scope reads only line item properties the app itself wrote. We do not read customer names, email addresses, phone numbers, shipping addresses or payment details, and the app has no feature that would use them.

3. What we store#

Stored in WySync's own systems:

  • Shop record — your .myshopify.com domain, plan, entitlements, install state and the Shopify access token used to serve the app.
  • Configuration — mapped collections, filter and metafield mappings, normalization and synonym rules, ranking weights and the fitment copy templates you write.
  • Fitment data you supply — uploaded CSV rows, Google Sheet contents, mappings derived from your product tags, and every override made in the fitment editor.
  • Derived search documents — an indexed representation of your catalog, held in a search index scoped to your shop alone.
  • Aggregate analytics — search queries, vehicle selections and counts. See Section 5.
  • Records of Shopify's privacy webhooks — see Section 8.

4. What we do not store#

  • Customer names, email addresses, phone numbers or postal addresses.
  • Order contents, totals or fulfilment data beyond the line item properties the app itself wrote.
  • Payment card or bank details of any kind. App subscriptions are billed by Shopify; we never see a payment instrument.
  • Your product catalog as a master copy. Shopify remains the source of truth; we hold only derived search documents, which are rebuilt from your store and deleted with it.
  • Any of your data in a table shared with another merchant. Every database row, search index and cache key is scoped to a single shop.

5. Storefront data and shoppers#

The app's storefront widgets process a shopper's vehicle selection — year, make, model and submodel. This is what makes fitment work.

  • Where it lives. In the shopper's own browser, in localStorage. For a shopper logged in to a customer account, the garage may also be written to the wysync.garage metafield on their Shopify customer record, which is stored by Shopify in your store, not by us.
  • What reaches the order. When a shopper adds to cart with a vehicle selected, the vehicle and the fitment verdict are attached as line item properties (_wysync_vehicle, _wysync_vehicle_id, _wysync_fitment_message) and survive into the order in your Shopify admin.
  • What we record for analytics. The search text, the vehicle selected, and counts. Query text is scrubbed of anything shaped like an email address or a phone number before it is written. No customer identifier, IP address, session token or cart token is recorded. Analytics cannot be traced to an individual, by design.
  • No advertising use. We do not sell data, do not share it with advertising networks, and set no advertising or cross-site tracking cookies.

6. How we use what we hold#

Only to provide, secure and support the app: indexing your catalog, resolving fitment, serving storefront queries, showing you analytics, billing your subscription and answering your support requests. We do not use merchant data to train models, do not sell or rent it, and do not use one merchant's data to serve another.

7. Sub-processors#

We use the following processors to run the service. All process data only on our instructions and under contract.

Sub-processorPurposeRegion
Shopify Inc.The platform the app runs on and is billed throughUS / global
RailwayApplication hostingUS
TypesensePer-shop search indexUS
UpstashRedis cache for storefront queriesUS
Google Cloud (Cloud SQL)Application databaseUS
Twilio SendGridTransactional and support emailUS

Data is processed in the United States. If you are in the EU, UK or Switzerland, transfers rely on the Standard Contractual Clauses or an equivalent lawful transfer mechanism operated by the processor concerned. We will give notice before adding a sub-processor; write to the address in Section 14 to be notified.

8. Shopify's mandatory privacy webhooks#

Shopify requires every app to implement three webhooks. Ours are HMAC-verified and scoped to the requesting shop.

WebhookWhat we do
customers/data_requestWe record the request and respond. The app holds no customer personal data of its own beyond the garage metafield, which is stored in your Shopify store and returned to the customer by Shopify.
customers/redactWe record the request and clear any garage data held for that customer. Analytics needs no action: nothing there is keyed to a person.
shop/redactSent by Shopify roughly 48 hours after uninstall. We delete the shop record and everything that cascades from it — configuration, fitment data, search index, cache and analytics.

We retain a record of each request — its type, the customer identifier supplied by Shopify, and the request payload — as an audit trail demonstrating that the request was received and actioned.

9. Retention#

DataRetained
Search and vehicle analytics30 days on Starter, 90 days on other plans, then pruned automatically
Shop record, configuration, fitment data, search indexFor as long as the app is installed
All of the above after uninstallDeleted within 48 hours of Shopify's shop/redact webhook
Privacy webhook audit recordsKept as an audit trail
Support correspondence and invoicesAs required for accounting and legal record-keeping

Uninstalling the app revokes our access immediately. Your products, tags, metafields, collections and orders are never modified by uninstall — they were always yours.

10. Our data protection commitments to you#

Where we process personal data on your behalf, we commit that we will:

  1. Process only on your instructions — using the data solely to provide the app, and for no independent purpose of our own.
  2. Keep it confidential — limiting access to personnel who need it to operate or support the service.
  3. Secure it — encryption in transit (TLS) and at rest, HMAC verification on every Shopify webhook, session-token authentication on the admin, per-shop isolation of every query, index and cache key, and access tokens that expire and rotate rather than being held indefinitely.
  4. Engage sub-processors under equivalent obligations, remaining responsible to you for their performance, and give you notice of changes.
  5. Assist you with data subject requests, data protection impact assessments and regulator enquiries, to the extent the request concerns data we process for you.
  6. Notify you without undue delay on becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.
  7. Delete it on termination, on the timeline in Section 9.
  8. Make available the information you reasonably need to demonstrate our compliance with these commitments.

If your organisation requires a separately signed data processing agreement, or has standard clauses of its own, contact us at the address in Section 14 and we will execute one.

Where we act as controller for your merchant account data, we rely on performance of a contract (providing and billing the app) and our legitimate interests in securing the service and communicating with you about it. Where we act as processor, the legal basis for the underlying processing is yours to determine as controller.

12. Your rights#

Depending on where you are, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to complain to a supervisory authority. For data we hold as controller, contact us and we will respond within the period required by the applicable law. For data we hold as processor on a merchant's behalf, please contact that merchant; if a shopper contacts us directly, we will refer them to the merchant and assist as required.

Residents of California and other US states with comparable laws: we do not sell or share personal information as those terms are defined, and we do not process it for cross-context behavioural advertising.

13. Children#

The app is a business tool sold to merchants and is not directed at children. We do not knowingly collect personal data from anyone under 16.

14. Contact and changes#

Questions, requests, or a signed agreement: privacy@wysync.com, or Pound Pixel LLC, trading as WySync.

We will post any change to this policy on this page with a revised date. Material changes affecting how we process merchant data will be notified to installed merchants by email before they take effect.