Privacy Policy
Last updated: March 15, 2026
This Privacy Policy describes how SyncForge Product Sync ("SyncForge", "we", "us", or "our"), operated by DXSoft, collects, uses, and protects your information when you use our Shopify application.
1. Data Collection
Store Data via Shopify API
When you install SyncForge, we access your Shopify store data through the Shopify Admin API. This includes the resources you choose to import or export — such as products, customers, orders, collections, metafields, and other supported resource types. We only access the specific scopes you authorize during installation.
Uploaded Files
Files you upload for import (CSV, XLSX, JSON, XML) are temporarily stored in Vercel Blob Storage for processing. Files are automatically deleted after processing is complete or after 24 hours, whichever comes first.
Connection Credentials
If you configure remote connections (FTP, SFTP, S3, Google Sheets), your credentials are encrypted using AES-256-GCM before being stored in our database. The encryption key is managed separately and never included in backups, logs, or error reports.
2. Data Usage
Import & Export Processing
Your data is used exclusively for the import and export operations you configure. Data flows through our transform pipeline (field mapping, validation, transformation) and is sent to or retrieved from Shopify via the Admin API.
Caching
We use Upstash Redis for temporary caching of API responses and job progress data. Cached data is automatically expired and never used for purposes other than improving application performance and providing real-time job status updates.
Background Jobs
Scheduled imports and exports run as background jobs via Upstash QStash. Job metadata (status, record counts, error summaries) is stored in our database for your review. Actual data payloads are processed in memory and not persisted after job completion.
3. Third-Party Services
SyncForge integrates with the following third-party services:
- Shopify Admin API — for reading and writing store data (governed by Shopify's Privacy Policy)
- Neon (PostgreSQL) — for database storage of app configuration, job history, and encrypted credentials
- Upstash Redis — for temporary caching and rate limiting
- Upstash QStash — for reliable background job execution
- Vercel Blob — for temporary file storage during import/export processing
4. Data Retention & Deletion
We retain your data only as long as necessary to provide our services:
- Uploaded files: Deleted after processing or within 24 hours
- Job history: Retained for 90 days, then automatically purged
- Connection credentials: Stored (encrypted) until you delete the connection or uninstall the app
- Cache data: Automatically expired via TTL (typically 5–60 minutes)
When you uninstall SyncForge, all your data — including job history, templates, connections, and credentials — is permanently deleted within 48 hours.
5. Merchant Rights
As a merchant using SyncForge, you have the right to:
- Access: Request a copy of all data we hold about your store
- Correction: Update or correct any stored configuration data
- Deletion: Request complete deletion of your data at any time by contacting us or uninstalling the app
- Portability: Export your configuration, templates, and job history in JSON format
6. GDPR Compliance
SyncForge is designed with GDPR compliance in mind. We process personal data only as a "data processor" on your behalf. We provide built-in tools for PII detection, data anonymization, and data deletion to help you comply with your obligations as a data controller.
We respond to data subject requests (access, erasure, portability) within 30 days. Contact us at info@dxsoft.io to submit a request.
7. Cookies
SyncForge does not set any cookies on the public-facing pages of this website. Within the Shopify Admin embedded app, session cookies are managed by Shopify's App Bridge for authentication purposes only.
8. Contact
If you have questions about this Privacy Policy or our data practices, contact us at:
DXSoft
Email: info@dxsoft.io