Applies to: the WySync Fitment application distributed through the Shopify App Store and installed on merchant Shopify stores. Provider: Pound Pixel LLC, trading as WySync ("WySync", "we", "us"). Last updated: 12 August 2026.
This policy covers the app. Our website is covered separately by the wysync.com privacy policy.
1. Who is responsible for what#
When you install WySync Fitment, two different relationships exist at once, and they carry different obligations.
| Role | Applies to | |
|---|---|---|
| You, the merchant | Controller | Your store's product, order and customer data. You decide what is collected and why. |
| WySync | Processor | The same data, which we process only to provide the app to you, on your documented instructions. |
| WySync | Controller | Your own account data — the shop record, plan, billing state, support correspondence. |
Where we act as processor, Section 10 sets out the commitments we make to you.
2. What the app accesses in your Shopify store#
Shopify asks you to approve a set of access scopes at install. This is every scope the app requests and the specific reason for each one. We do not use them for any other purpose.
| Scope | What it reaches | Why |
|---|---|---|
read_products | Titles, variants, SKUs, prices, product metafields | The catalog that gets indexed and made searchable |
write_products | Product metafield definitions only | Creates the wysync.universal_fit and wysync.fitment_note definitions at install so the fitment editor has somewhere to write |
read_product_listings | Publication status | Determines which products are visible on your storefront |
read_inventory | Stock levels | The in stock / low stock / out of stock facet |
read_metaobjects, write_metaobjects | Metaobjects in your store | Stores fitment sources and mapping configuration |
read_orders | Order line items and their properties | Reads back the vehicle and fitment verdict the app wrote at checkout, for merchant reporting |
read_themes | Theme structure | Detects whether the app's storefront blocks are installed on your published theme |
read_customers, write_customers | A single customer metafield, wysync.garage | Saves a logged-in shopper's garage so it follows them across devices |
read_publications, write_publications | Sales channel publication | Publishes generated vehicle landing pages to your Online Store channel |
read_customers, write_customers and read_orders are classified by Shopify as Protected Customer Data. Their use here is deliberately narrow: the customer scopes touch exactly one metafield (wysync.garage) and no other customer field, and the order scope reads only line item properties the app itself wrote. We do not read customer names, email addresses, phone numbers, shipping addresses or payment details, and the app has no feature that would use them.
3. What we store#
Stored in WySync's own systems:
- Shop record — your
.myshopify.comdomain, plan, entitlements, install state and the Shopify access token used to serve the app. - Configuration — mapped collections, filter and metafield mappings, normalization and synonym rules, ranking weights and the fitment copy templates you write.
- Fitment data you supply — uploaded CSV rows, Google Sheet contents, mappings derived from your product tags, and every override made in the fitment editor.
- Derived search documents — an indexed representation of your catalog, held in a search index scoped to your shop alone.
- Aggregate analytics — search queries, vehicle selections and counts. See Section 5.
- Records of Shopify's privacy webhooks — see Section 8.
4. What we do not store#
- Customer names, email addresses, phone numbers or postal addresses.
- Order contents, totals or fulfilment data beyond the line item properties the app itself wrote.
- Payment card or bank details of any kind. App subscriptions are billed by Shopify; we never see a payment instrument.
- Your product catalog as a master copy. Shopify remains the source of truth; we hold only derived search documents, which are rebuilt from your store and deleted with it.
- Any of your data in a table shared with another merchant. Every database row, search index and cache key is scoped to a single shop.
5. Storefront data and shoppers#
The app's storefront widgets process a shopper's vehicle selection — year, make, model and submodel. This is what makes fitment work.
- Where it lives. In the shopper's own browser, in
localStorage. For a shopper logged in to a customer account, the garage may also be written to thewysync.garagemetafield on their Shopify customer record, which is stored by Shopify in your store, not by us. - What reaches the order. When a shopper adds to cart with a vehicle selected, the vehicle and the fitment verdict are attached as line item properties (
_wysync_vehicle,_wysync_vehicle_id,_wysync_fitment_message) and survive into the order in your Shopify admin. - What we record for analytics. The search text, the vehicle selected, and counts. Query text is scrubbed of anything shaped like an email address or a phone number before it is written. No customer identifier, IP address, session token or cart token is recorded. Analytics cannot be traced to an individual, by design.
- No advertising use. We do not sell data, do not share it with advertising networks, and set no advertising or cross-site tracking cookies.
6. How we use what we hold#
Only to provide, secure and support the app: indexing your catalog, resolving fitment, serving storefront queries, showing you analytics, billing your subscription and answering your support requests. We do not use merchant data to train models, do not sell or rent it, and do not use one merchant's data to serve another.
7. Sub-processors#
We use the following processors to run the service. All process data only on our instructions and under contract.
| Sub-processor | Purpose | Region |
|---|---|---|
| Shopify Inc. | The platform the app runs on and is billed through | US / global |
| Railway | Application hosting | US |
| Typesense | Per-shop search index | US |
| Upstash | Redis cache for storefront queries | US |
| Google Cloud (Cloud SQL) | Application database | US |
| Twilio SendGrid | Transactional and support email | US |
Data is processed in the United States. If you are in the EU, UK or Switzerland, transfers rely on the Standard Contractual Clauses or an equivalent lawful transfer mechanism operated by the processor concerned. We will give notice before adding a sub-processor; write to the address in Section 14 to be notified.
8. Shopify's mandatory privacy webhooks#
Shopify requires every app to implement three webhooks. Ours are HMAC-verified and scoped to the requesting shop.
| Webhook | What we do |
|---|---|
customers/data_request | We record the request and respond. The app holds no customer personal data of its own beyond the garage metafield, which is stored in your Shopify store and returned to the customer by Shopify. |
customers/redact | We record the request and clear any garage data held for that customer. Analytics needs no action: nothing there is keyed to a person. |
shop/redact | Sent by Shopify roughly 48 hours after uninstall. We delete the shop record and everything that cascades from it — configuration, fitment data, search index, cache and analytics. |
We retain a record of each request — its type, the customer identifier supplied by Shopify, and the request payload — as an audit trail demonstrating that the request was received and actioned.
9. Retention#
| Data | Retained |
|---|---|
| Search and vehicle analytics | 30 days on Starter, 90 days on other plans, then pruned automatically |
| Shop record, configuration, fitment data, search index | For as long as the app is installed |
| All of the above after uninstall | Deleted within 48 hours of Shopify's shop/redact webhook |
| Privacy webhook audit records | Kept as an audit trail |
| Support correspondence and invoices | As required for accounting and legal record-keeping |
Uninstalling the app revokes our access immediately. Your products, tags, metafields, collections and orders are never modified by uninstall — they were always yours.
10. Our data protection commitments to you#
Where we process personal data on your behalf, we commit that we will:
- Process only on your instructions — using the data solely to provide the app, and for no independent purpose of our own.
- Keep it confidential — limiting access to personnel who need it to operate or support the service.
- Secure it — encryption in transit (TLS) and at rest, HMAC verification on every Shopify webhook, session-token authentication on the admin, per-shop isolation of every query, index and cache key, and access tokens that expire and rotate rather than being held indefinitely.
- Engage sub-processors under equivalent obligations, remaining responsible to you for their performance, and give you notice of changes.
- Assist you with data subject requests, data protection impact assessments and regulator enquiries, to the extent the request concerns data we process for you.
- Notify you without undue delay on becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.
- Delete it on termination, on the timeline in Section 9.
- Make available the information you reasonably need to demonstrate our compliance with these commitments.
If your organisation requires a separately signed data processing agreement, or has standard clauses of its own, contact us at the address in Section 14 and we will execute one.
11. Legal bases (UK/EU GDPR)#
Where we act as controller for your merchant account data, we rely on performance of a contract (providing and billing the app) and our legitimate interests in securing the service and communicating with you about it. Where we act as processor, the legal basis for the underlying processing is yours to determine as controller.
12. Your rights#
Depending on where you are, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to complain to a supervisory authority. For data we hold as controller, contact us and we will respond within the period required by the applicable law. For data we hold as processor on a merchant's behalf, please contact that merchant; if a shopper contacts us directly, we will refer them to the merchant and assist as required.
Residents of California and other US states with comparable laws: we do not sell or share personal information as those terms are defined, and we do not process it for cross-context behavioural advertising.
13. Children#
The app is a business tool sold to merchants and is not directed at children. We do not knowingly collect personal data from anyone under 16.
14. Contact and changes#
Questions, requests, or a signed agreement: privacy@wysync.com, or Pound Pixel LLC, trading as WySync.
We will post any change to this policy on this page with a revised date. Material changes affecting how we process merchant data will be notified to installed merchants by email before they take effect.