Privacy Policy
Last updated: [DATE] · Effective: [EFFECTIVE DATE]
Fill the [bracketed] placeholders (legal entity, contact, jurisdiction, dates) and have this reviewed by qualified counsel before publishing. This template reflects how CRM Sync is configured to process data.
1. Who we are
[LEGAL ENTITY NAME] ("we", "us") operates CRM Sync, a consent-first customer-data and agent-entitlement layer for commerce stores. This policy explains what personal data we process, why, who we share it with, and your rights. It governs the CRM Sync application and the consent, account, and dashboard surfaces it powers on a store. Contact: [CONTACT EMAIL].
2. Data we collect
- Account & identity — name, email, and the provider you sign in with (email/password, Google, or Shopify). We never receive your Google or Shopify password.
- Consent records — your choices for Terms, Privacy, Cookies/Analytics, Marketing, and agent access, each with a timestamp, method, and version.
- Tags & segments — attributes used to personalize content and honor preferences, including a "do not sell or share" flag.
- Agent permissions — agents you authorize, their scope, spending limit, rail, and activity (A2A access and AP2 mandates).
- Commerce data — orders, returns, and cart or checkout activity associated with your account.
- Analytics & device data — usage events and identifiers, processed under Consent Mode and subject to your analytics choices.
3. How we use it
- To provide sign-in, your account, and the consent and preferences dashboard.
- To honor your consent and privacy choices in real time across connected services.
- To authorize, scope, and audit AI agents acting on your behalf, and to enforce spending limits.
- To personalize search, recommendations, and offers where you have consented.
- To measure performance and improve the service, subject to your analytics consent.
4. Legal bases (GDPR)
We rely on consent (marketing, analytics, agent access), contract (operating your account and orders), legitimate interests (security, fraud prevention, service improvement), and legal obligations.
5. Service providers & data sharing
We do not sell your personal information. We share it only with processors that operate the service under contract, listed below.
5.1 Shopify Inc.
- Country
- Canada / United States
- Data
- Customer record, orders, returns, tags
- Purpose
- Commerce, order management, customer sync
- Retention
- Per your Shopify store's retention settings
5.2 Xano, Inc.
- Country
- United States
- Data
- Identity, consent records, tags, agent mandates
- Purpose
- Primary backend data store
- Retention
- Life of account, then deleted or anonymized
5.3 Cloudflare, Inc.
- Country
- United States (global edge)
- Data
- Requests, tokens (encrypted), translation cache
- Purpose
- Edge processing, security, delivery, translation
- Retention
- Transient; cache up to 30 days
5.4 Google LLC (Analytics / GA4)
- Country
- United States
- Data
- Pseudonymous usage events, consent signals
- Purpose
- Analytics and measurement (consent-gated)
- Retention
- Per your GA4 property settings
5.5 Payment providers & rails
- Examples
- Stripe, Apple Pay, Google Pay, Samsung Pay, Venmo, Cash App
- Data
- Transaction metadata for payments you initiate
- Purpose
- Processing customer and agent payments
- Retention
- Per each provider's policy
6. International transfers
Personal data may be processed in countries other than yours. Where required (GDPR Articles 44–49), we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
We keep personal data while your account is active and as needed to provide the service, then delete or anonymize it, except where longer retention is required for legal, tax, or security purposes.
8. Your rights
You can exercise these directly in the Privacy & Permissions panel: download a copy of your data (Export my data), permanently delete your account (Delete my account), opt out of sale or sharing (Do Not Sell or Share My Personal Information), and revoke any AI agent. Requests take effect immediately where possible and otherwise within 30 days. For requests you cannot self-serve, contact [CONTACT EMAIL].
8.1 EU / EEA / UK (GDPR)
- Access, rectification, erasure, restriction, portability, and objection (GDPR Articles 15–21).
- Withdraw consent at any time, and lodge a complaint with your supervisory authority.
8.2 California (CCPA / CPRA)
- Know, delete, and correct your personal information, and the right to opt out of sale or sharing.
- Do Not Sell or Share My Personal Information — use the toggle in the Privacy panel; we do not discriminate for exercising your rights.
8.3 Canada (PIPEDA & CASL)
- Access and correction, and the right to challenge our handling of your personal information.
- Email & anti-spam (CASL) — commercial electronic messages (email/SMS marketing) are sent only with your consent (express or, where permitted, implied); every message identifies the sender and includes a working unsubscribe that we honor within 10 business days. Transactional and service messages are not marketing.
9. Cookies & local storage
We use cookies and local storage for sign-in, security, and—where you consent—analytics and personalization. Analytics tags load only after consent (Consent Mode defaults to denied).
| Name | Type | Purpose | Expiry |
| crm_auth_token | localStorage | Keeps you signed in | On logout / account deletion |
| consent state | localStorage | Remembers your consent choices | Until changed |
| _ga / GA4 | cookie | Analytics (only if consented) | Up to 2 years |
| crmsync.i18n.* | sessionStorage | Caches page translations | End of session |
10. Children
The service is not directed to children under [16/13], and we do not knowingly collect their personal data.
11. Changes
We may update this policy; material changes will be posted here with a new effective date.
12. Contact
[LEGAL ENTITY NAME] · [ADDRESS] · [CONTACT EMAIL]