Last updated: 4 September 2026.
West Web Agency (« we ») publishes the Shopify application WWA Supplier Sync
(« the app »). This policy explains what the app stores, why, and for how long.
Who the data belongs to
The app connects two independent Shopify stores: a supplier and one of their
resellers. It stores data belonging to both, and its central rule is that
data never crosses between them except as a deliberate, frozen copy of product
information the supplier chose to share.
What we store
About a connected store
- The store’s
myshopify.comdomain, display name and admin language. - The Shopify access token authorising the app, encrypted at rest
(AES-256-GCM). - The role the merchant chose (supplier or reseller) and their subscription
state.
About a supplier’s customers
Only when a supplier explicitly links one of their customers to a reseller, so
that customer’s orders route to them automatically:
- the customer’s Shopify identifier;
- their display name, cached so the supplier’s own screen is readable.
We store no email address, no postal address, no phone number, and no payment information about a supplier’s customers. This data is visible only to the
supplier who created the link. It is never transmitted to a reseller.
About products and orders
- Order numbers, dates and line items of orders a supplier shares with a
reseller, including the unit price that reseller paid. - Frozen copies of the product data a supplier chooses to expose: titles,
descriptions, image URLs, barcodes, SKUs, variants, weights and, when the
supplier enables them, tags, metafields and prices. - A record of which products a reseller imported, so duplicates are not created
and the origin of each product remains traceable.
Why we store it
Solely to operate the app: routing a supplier’s orders to the right reseller,
and letting that reseller copy product information into their own store. We do
not use this data for any other purpose, we do not sell or share it with third
parties, and we do not use it for marketing or profiling.
How long we keep it
| Data | Retention |
|---|---|
| Customer link (identifier and name) | While the connection is open, then 90 days |
| Activity log | 90 days |
| Completed background jobs | 7 days |
| Product snapshots and import records | While the connection exists |
| Everything, after the app is uninstalled | Deleted within approximately 48 hours |
A customer erasure request received from Shopify is applied immediately: the
link and the log entries naming that customer are deleted outright, since the
identifier is itself personal data.
Where it is stored
- Application: Fly.io, Paris region (France).
- Database: Neon,
eu-central-1region (Frankfurt, Germany).
Both are inside the European Union. Data is encrypted in transit (TLS) and at
rest, and access tokens carry an additional layer of application-level
encryption.
Your rights
Merchants and their customers may request access to, correction of, or erasure
of their personal data. Requests submitted through Shopify are routed to the app
automatically and surfaced to the merchant concerned, who has 30 days to
respond. You may also write to us directly at the address below.
Sub-processors
| Provider | Role | Location |
|---|---|---|
| Shopify | Source of the data, hosting of the stores | Ireland / United States |
| Fly.io | Application hosting | Paris, France |
| Neon | Database hosting | Frankfurt, Germany |
Security
Access tokens are encrypted at rest. Access to production systems is restricted
to the publisher and protected by two-factor authentication. Access to customer
data through the app is logged. We maintain a written security incident response
policy and will notify affected merchants and Shopify without undue delay in the
event of a breach.
Changes
Material changes are published here with an updated date. Continued use of the
app after publication constitutes acceptance.
Contact
West Web Agency — contact@west-web-agency.fr
