OrderSync

Privacy and data handling

OrderSync is operated by PuppetVendor. It synchronizes the Shopify order records selected by a merchant into a private dashboard for that merchant.

Data we store

We store store identity, timezone, encrypted Shopify access credentials, client login email and a password hash, order identifiers, dates, payment and fulfillment statuses, currencies, totals, product titles, SKUs and quantities. This version does not request customer names, email addresses, phone numbers or shipping addresses from orders.

How data is used

Data is used to provide synchronization, display orders, generate merchant-requested exports, verify subscriptions and respond to support and privacy requests. Automatic synchronization is disabled until a merchant enables it. Payment approval and subscription billing take place within Shopify.

Access and retention

Each store has a separate authenticated workspace. Shopify credentials are encrypted on the server. Portal passwords are hashed. Uninstalling disables access and sync jobs. Shopify’s shop-redaction notification deletes the store’s application records. Customer redaction notifications delete the specified order records and retain only references needed to prevent their re-import. Routine login sessions expire after eight hours and login attempt records are cleaned up by the worker.

Requests and contact

Merchants can export their orders from the dashboard. Customer data requests received through Shopify are recorded for secure fulfillment by PuppetVendor. Contact support to request access, correction, deletion or details about data processing and retention.

Contact: support@puppetvendor.com

Development privacy notice · September 2026