Privacy Policy #3

Last updated: 4 September 2026.


West Web Agency (« we ») publishes the Shopify application WWA Supplier Sync
(« the app »). This policy explains what the app stores, why, and for how long.

Who the data belongs to

The app connects two independent Shopify stores: a supplier and one of their
resellers. It stores data belonging to both, and its central rule is that
data never crosses between them except as a deliberate, frozen copy of product
information the supplier chose to share.

What we store

About a connected store

  • The store’s myshopify.com domain, display name and admin language.
  • The Shopify access token authorising the app, encrypted at rest
    (AES-256-GCM).
  • The role the merchant chose (supplier or reseller) and their subscription
    state.

About a supplier’s customers

Only when a supplier explicitly links one of their customers to a reseller, so
that customer’s orders route to them automatically:

  • the customer’s Shopify identifier;
  • their display name, cached so the supplier’s own screen is readable.

We store no email address, no postal address, no phone number, and no payment information about a supplier’s customers. This data is visible only to the
supplier who created the link. It is never transmitted to a reseller.

About products and orders

  • Order numbers, dates and line items of orders a supplier shares with a
    reseller, including the unit price that reseller paid.
  • Frozen copies of the product data a supplier chooses to expose: titles,
    descriptions, image URLs, barcodes, SKUs, variants, weights and, when the
    supplier enables them, tags, metafields and prices.
  • A record of which products a reseller imported, so duplicates are not created
    and the origin of each product remains traceable.

Why we store it

Solely to operate the app: routing a supplier’s orders to the right reseller,
and letting that reseller copy product information into their own store. We do
not use this data for any other purpose, we do not sell or share it with third
parties, and we do not use it for marketing or profiling.

How long we keep it

DataRetention
Customer link (identifier and name)While the connection is open, then 90 days
Activity log90 days
Completed background jobs7 days
Product snapshots and import recordsWhile the connection exists
Everything, after the app is uninstalledDeleted within approximately 48 hours

A customer erasure request received from Shopify is applied immediately: the
link and the log entries naming that customer are deleted outright, since the
identifier is itself personal data.

Where it is stored

  • Application: Fly.io, Paris region (France).
  • Database: Neon, eu-central-1 region (Frankfurt, Germany).

Both are inside the European Union. Data is encrypted in transit (TLS) and at
rest, and access tokens carry an additional layer of application-level
encryption.

Your rights

Merchants and their customers may request access to, correction of, or erasure
of their personal data. Requests submitted through Shopify are routed to the app
automatically and surfaced to the merchant concerned, who has 30 days to
respond. You may also write to us directly at the address below.

Sub-processors

ProviderRoleLocation
ShopifySource of the data, hosting of the storesIreland / United States
Fly.ioApplication hostingParis, France
NeonDatabase hostingFrankfurt, Germany

Security

Access tokens are encrypted at rest. Access to production systems is restricted
to the publisher and protected by two-factor authentication. Access to customer
data through the app is logged. We maintain a written security incident response
policy and will notify affected merchants and Shopify without undue delay in the
event of a breach.

Changes

Material changes are published here with an updated date. Continued use of the
app after publication constitutes acceptance.

Contact

West Web Agency — contact@west-web-agency.fr