Privacy Policy
Last updated: July 20, 2026
This policy explains how Shopify Sync App and the related central OAuth, webhook relay, and telemetry services process data for Odoo Shopify connector installations.
Contact
Data controller and support contact: Ă–mer Sever, [email protected].
Data We Process
- shop domain, Odoo database UUID, Odoo instance ID, and connection identifiers.
- OAuth session metadata, requested scopes, granted scopes, state hashes, and exchange status.
- Encrypted temporary Shopify access tokens during short-lived One-Click OAuth token exchange.
- Webhook relay metadata, relay installation identifiers, delivery IDs, topics, headers, and payload delivery status.
- Optional telemetry and diagnostic logs when remote log export is configured and consented to in Odoo.
- Support communications sent by email.
How Data Is Used
Data is used to complete Shopify OAuth authorization, relay verified Shopify webhooks to the connected Odoo instance, prevent replay or duplicate delivery, diagnose connector errors when telemetry is enabled, and provide product support.
OAuth and Token Handling
Shopify access tokens are not redirected through browser URLs. One-Click OAuth returns a short-lived exchange code to Odoo, and Odoo exchanges that code over HTTPS with its local code verifier. Temporary token exchange records are designed to expire quickly and be consumed once.
Telemetry
Remote log export is optional. It requires Odoo-side configuration and consent. Diagnostic payloads are signed, replay protected, and intended for operational support. The connector masks access tokens, client secrets, exchange codes, authorization headers, email, phone, and address fields in technical summaries.
Retention
OAuth sessions, token exchanges, webhook deliveries, install beacons, replay nonces, and diagnostic logs are retained only as needed for operation, security, support, and troubleshooting. Expired and old operational records may be pruned by scheduled maintenance.
Sharing
Data is used to operate the Shopify Sync App service and is not sold. Shopify receives OAuth and API requests required by the merchant-approved Shopify app. Odoo receives the access token and webhook relay payloads for the connected installation.
Security
The service uses HTTPS, HMAC signatures, signed state values, replay protection, short-lived exchange codes, encrypted temporary token storage, and masked logging for sensitive values.
Your Choices
You may disconnect the Shopify instance in Odoo, uninstall the Shopify app from Shopify, disable remote log export, or contact support to request assistance with data access, correction, or deletion.