Privacy policy
Last updated 20 August 2026
What we store
Two different things happen to your data, and it matters which is which.
Read and dropped. To compare two stores we read both catalogues - titles, descriptions, variants, options, barcodes, weights, images, tags, metafields - and their inventory levels per location. That reading lives in memory for the length of one check and is not written to disk.
Kept while your stores are paired. The links between products in your paired stores, your store's locations, the queue of products waiting for your decision, your plan and subscription, and your store's contact email address, so we can write to you about your own stores (see below).
Kept for 30 days, then deleted automatically. The hourly reports of what the checks found - they name the products and fields that differed and the values on each side - and the journal of every write the app performs in your stores, which records the fields written and what stood there before. That journal is what makes our sync verifiable. The daily full-catalogue reports are kept for as long as the connection exists: they are the history the weekly email and the connection page are built from. Everything, of any age, goes when the app is uninstalled and the store is redacted.
We do not request, read or store customer data or order data. The app's access scopes are limited to products, inventory and locations.
One line on the Shopify install screen deserves an explanation. Because the app asks for access to locations, Shopify lists "staff and contributor data" among the permissions, including name, email, phone and physical address. That is what the permission could cover, not what we ask for: from your locations StoreTwin reads the identifier, the name, whether the location is active and whether it ships inventory - nothing else. No address, no phone number, no staff record is requested or stored.
Why we store it
To provide the sync and audit features you installed the app for. For nothing else. We do not analyse your data, do not aggregate it with other merchants' data, do not train models on it and do not sell it. We share it with no one except the services that deliver it to you: our email provider carries the reports we send to your own address, and the affiliate platform named at the bottom of this page is told that an install happened. Nobody else receives anything.
Email we send you
We store your store's contact email address, the one Shopify shows in your store settings, and use it only to write to you about your own stores: a weekly report of what the checks found, a message when syncing stops by itself or when we lose access to a store, a notice when your plan's product limit is passed, a note when nothing is selected for copying so nothing is being copied, and one setup email after you install. Replies come to a person and we read them.
We never send marketing email, never sell the address and never use it for anything but your own stores. One exception is worth naming: when we lose access to a store and cannot reach it at all, the message goes to the owner of the store it is paired with, because otherwise nobody learns that the sync stopped. If you would rather not receive the weekly report or the setup email, reply to any of them and we stop; the messages about syncing stopping stay, because a sync that fails silently is the one thing this app exists to prevent.
How long
Reports of what the checks found and the write journal are kept while the app is installed and trimmed on a rolling window of thirty days - the same window on every plan. If you uninstall, everything belonging to your store is erased within the period Shopify requires, and your access token is destroyed as soon as Shopify tells us the app was removed. Encrypted database backups are kept for a short period after that and roll off on their own schedule.
How it is protected
Traffic between you and StoreTwin, and between StoreTwin and Shopify, is encrypted in transit. Each store's access token is encrypted at rest with its own key, and that key is stored wrapped by a master key that lives only in the running service's environment - never in the database, never in the repository, never in logs. Database backups are encrypted. There is no console or dashboard that shows your catalogue to anyone; the only way a human reads any of it is a diagnostic command run by the person who operates the service, and only to answer a problem you reported.
This website
The public pages of this site set no cookies and run no analytics, and the app itself - everything behind your Shopify admin - carries no analytics either. One form collects something: the question box in the corner of these pages takes the email address and the text you type, sends them to our support mailbox through our email provider, Resend, and keeps nothing else. If you do not write to us, these pages learn nothing about you.
Two pages - the home page and the how-it-works page - embed a short demo video from YouTube's privacy-enhanced player (youtube-nocookie.com). Loading the page contacts YouTube, so Google sees your IP address as it would for any request to them; the player stores nothing on your device unless you press play. Nothing about your stores or your catalogue is sent there, and the video is the only third-party content on this site.
When you install through a partner
StoreTwin runs an affiliate programme, and an install that arrives through a partner link has to be matched to that partner. To do that, each time the app is installed - including a re-install - we send two things to our affiliate platform, Shoffi (Shoffi Ltd): the myshopify domain of the store being installed, and the IP address the installation request came from.
Nothing else is sent, nothing is sent at any other time, and no customer data is involved - this happens once, during installation. Shoffi acts as a processor for that single purpose. If you would rather this did not happen, install the app directly from the Shopify App Store rather than through a partner link, or write to us and we will exclude your store.
Requests from Shopify
When Shopify forwards a data request or a deletion request for a store, we answer it within the required period. Since we hold no customer records, customer-level requests are confirmed as a no-op; store-level deletion removes everything listed above.