Privacy Policy

Last updated: July 20, 2026

This policy explains how Shopify Sync App and the related central OAuth, webhook relay, and telemetry services process data for Odoo Shopify connector installations.

Contact

Data controller and support contact: Ă–mer Sever, [email protected].

Data We Process

How Data Is Used

Data is used to complete Shopify OAuth authorization, relay verified Shopify webhooks to the connected Odoo instance, prevent replay or duplicate delivery, diagnose connector errors when telemetry is enabled, and provide product support.

OAuth and Token Handling

Shopify access tokens are not redirected through browser URLs. One-Click OAuth returns a short-lived exchange code to Odoo, and Odoo exchanges that code over HTTPS with its local code verifier. Temporary token exchange records are designed to expire quickly and be consumed once.

Telemetry

Remote log export is optional. It requires Odoo-side configuration and consent. Diagnostic payloads are signed, replay protected, and intended for operational support. The connector masks access tokens, client secrets, exchange codes, authorization headers, email, phone, and address fields in technical summaries.

Retention

OAuth sessions, token exchanges, webhook deliveries, install beacons, replay nonces, and diagnostic logs are retained only as needed for operation, security, support, and troubleshooting. Expired and old operational records may be pruned by scheduled maintenance.

Sharing

Data is used to operate the Shopify Sync App service and is not sold. Shopify receives OAuth and API requests required by the merchant-approved Shopify app. Odoo receives the access token and webhook relay payloads for the connected installation.

Security

The service uses HTTPS, HMAC signatures, signed state values, replay protection, short-lived exchange codes, encrypted temporary token storage, and masked logging for sensitive values.

Your Choices

You may disconnect the Shopify instance in Odoo, uninstall the Shopify app from Shopify, disable remote log export, or contact support to request assistance with data access, correction, or deletion.