Pound Pixel Apps / WySync Fitment / Privacy Policy
Privacy Policy
Effective July 2026
What We Collect
WySync Fitment collects only the minimum data required to operate:
- Shop domain (e.g., yourstore.myshopify.com)
- Encrypted Shopify access token
- App configuration — widget and logic settings, mapped collections, filter and spec mappings, normalization rules, and ranking preferences
- Merchant-supplied fitment data — the CSV rows, Google Sheets links, and per-SKU vehicle mappings you provide
- Indexing job history — job status, product counts, and per-product diagnostics
- Billing status — your plan and subscription state, managed through Shopify
Your Product Catalog
Your product catalog is never stored in the WySync Fitment database. Products are read from your Shopify store and indexed into an isolated, per-store search collection used solely to power your storefront widgets. Shopify remains the source of truth, and the search collection is deleted when you uninstall.
What We Do NOT Collect
With one exception — the GDPR compliance request log Shopify sends us (described under GDPR Compliance) — we do not collect, store, or process any of the following:
- Customer personal information (names, emails, addresses). The only customer identifier we ever retain is the customer ID Shopify includes in a compliance webhook, logged solely to evidence that we handled the request.
- Order data or order history — the vehicle and fitment details captured at checkout are stored as line item properties on the order inside your Shopify store, not on our servers
- Payment information
- Browsing or tracking data — shopper vehicle selections and garages are kept in the shopper's own browser, not on our servers
How We Use Your Data
- Access token: Used solely for Shopify API calls to read products, collections, metafields, and inventory for indexing; to register the webhooks your plan requires; and to manage billing through Shopify
- Shop domain: Used for app authentication and session management
- Fitment data and configuration: Used to compute which products fit which vehicles and to render your storefront widgets
Data Storage
- MySQL database hosted on Google Cloud SQL (US region)
- Access tokens encrypted at rest
- Per-store search index hosted on Typesense Cloud, isolated per store
- Short-lived response cache (Upstash Redis), keyed per store
- All API communication over HTTPS
Data Retention
Your data is retained while the app is installed on your store.
When you uninstall, we immediately deactivate your store, drop the per-store search index, flush the response cache, and cancel the subscription record. Shopify then sends the shop/redact webhook roughly 48 hours later, at which point we permanently delete everything that remains — configuration, fitment data, indexing history, subscription records, the GDPR compliance request log, and the shop record itself. All shop data is gone within 48 hours of uninstall.
Third-Party Sharing
Your data is never sold to or shared with third parties. It is processed only by the infrastructure providers that run the service on our behalf — Google Cloud (database), Typesense Cloud (search index), Upstash (cache), and Railway (hosting).
GDPR Compliance
We support all three mandatory Shopify GDPR webhooks. For audit purposes we log each incoming compliance request — its type, the customer ID Shopify supplies, and the request payload — and nothing else. This log is scoped to your store and is deleted along with all other shop data when shop/redact completes.
customers/data_request— We hold no customer records beyond the compliance request log Shopify sends, so there is nothing else to returncustomers/redact— We hold no customer records beyond the compliance request log Shopify sends, so there is nothing else to deleteshop/redact— Deletes all shop data, including the per-store search index and the compliance request log, on uninstall
Contact
For privacy questions, reach us at [email protected].