CRM SYNC

Privacy Policy

Last updated: [DATE] · Effective: [EFFECTIVE DATE]
Fill the [bracketed] placeholders (legal entity, contact, jurisdiction, dates) and have this reviewed by qualified counsel before publishing. This template reflects how CRM Sync is configured to process data.

1. Who we are

[LEGAL ENTITY NAME] ("we", "us") operates CRM Sync, a consent-first customer-data and agent-entitlement layer for commerce stores. This policy explains what personal data we process, why, who we share it with, and your rights. It governs the CRM Sync application and the consent, account, and dashboard surfaces it powers on a store. Contact: [CONTACT EMAIL].

2. Data we collect

3. How we use it

4. Legal bases (GDPR)

We rely on consent (marketing, analytics, agent access), contract (operating your account and orders), legitimate interests (security, fraud prevention, service improvement), and legal obligations.

5. Service providers & data sharing

We do not sell your personal information. We share it only with processors that operate the service under contract, listed below.

5.1 Shopify Inc.

Country
Canada / United States
Data
Customer record, orders, returns, tags
Purpose
Commerce, order management, customer sync
Retention
Per your Shopify store's retention settings

5.2 Xano, Inc.

Country
United States
Data
Identity, consent records, tags, agent mandates
Purpose
Primary backend data store
Retention
Life of account, then deleted or anonymized

5.3 Cloudflare, Inc.

Country
United States (global edge)
Data
Requests, tokens (encrypted), translation cache
Purpose
Edge processing, security, delivery, translation
Retention
Transient; cache up to 30 days

5.4 Google LLC (Analytics / GA4)

Country
United States
Data
Pseudonymous usage events, consent signals
Purpose
Analytics and measurement (consent-gated)
Retention
Per your GA4 property settings

5.5 Payment providers & rails

Examples
Stripe, Apple Pay, Google Pay, Samsung Pay, Venmo, Cash App
Data
Transaction metadata for payments you initiate
Purpose
Processing customer and agent payments
Retention
Per each provider's policy

6. International transfers

Personal data may be processed in countries other than yours. Where required (GDPR Articles 44–49), we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Retention

We keep personal data while your account is active and as needed to provide the service, then delete or anonymize it, except where longer retention is required for legal, tax, or security purposes.

8. Your rights

You can exercise these directly in the Privacy & Permissions panel: download a copy of your data (Export my data), permanently delete your account (Delete my account), opt out of sale or sharing (Do Not Sell or Share My Personal Information), and revoke any AI agent. Requests take effect immediately where possible and otherwise within 30 days. For requests you cannot self-serve, contact [CONTACT EMAIL].

8.1 EU / EEA / UK (GDPR)

8.2 California (CCPA / CPRA)

8.3 Canada (PIPEDA & CASL)

9. Cookies & local storage

We use cookies and local storage for sign-in, security, and—where you consent—analytics and personalization. Analytics tags load only after consent (Consent Mode defaults to denied).

NameTypePurposeExpiry
crm_auth_tokenlocalStorageKeeps you signed inOn logout / account deletion
consent statelocalStorageRemembers your consent choicesUntil changed
_ga / GA4cookieAnalytics (only if consented)Up to 2 years
crmsync.i18n.*sessionStorageCaches page translationsEnd of session

10. Children

The service is not directed to children under [16/13], and we do not knowingly collect their personal data.

11. Changes

We may update this policy; material changes will be posted here with a new effective date.

12. Contact

[LEGAL ENTITY NAME] · [ADDRESS] · [CONTACT EMAIL]