Privacy policy
Effective date: 17 July 2026
What we collect
LandedCostSync processes the merchant's Shopify shop domain, installation and access-scope status, encrypted Shopify app access tokens, merchant-entered purchase-cost data, Shopify product, variant, inventory-item and location identifiers, inventory receipt signals, and the resulting cost-write audit trail. We do not request customer, order, payment, or fulfilment data.
Why we use it
We use this information only to provide, secure, support, and diagnose the app: staging landed costs, detecting native Shopify inventory receipts, updating Cost per item, and showing the merchant an audit record.
Service providers and transfers
Shopify supplies the installation and inventory data needed by the app. Cloudflare hosts the application, database, queues, key-value storage, and encrypted secrets. Frankfurter, using European Central Bank reference rates, receives only currency codes and dates for Mode A exchange-rate lookups; it receives no shop, product, or merchant-entered cost data. These providers may process data in countries outside the merchant's own country under their applicable contractual and legal safeguards.
Retention and security
Access and refresh tokens are encrypted at rest and removed immediately when the app is uninstalled. Remaining shop data enters a 48-hour retention window after uninstall and is deleted during the next scheduled six-hour cleanup cycle, or when Shopify sends the applicable shop-redact request. Operational logs are minimised and do not intentionally contain access tokens or customer personal data.
Your choices and rights
Merchants can uninstall the app at any time. For access, correction, export, objection, restriction, or deletion requests, email support@landedcostsync.app. We will respond in line with applicable law.
Changes
We may update this policy as the service or legal requirements change. The effective date above identifies the current version.