Data Handling & Privacy
This page explains what data the LGL Order & Inventory Sync app accesses on your store, why it needs it, where it goes, and how long we keep it. It's written for store owners answering their own privacy questions — if you need something for your privacy policy or a customer inquiry, this is the page to reference.
What the app accesses, and why
| Data | Why we need it |
|---|---|
| Orders (items, customer name, ship-to address, email/phone) | To import LGL-fulfilled orders into our fulfillment system so we can ship them |
| Products & variants (titles, SKUs, options, images, metafields) | To keep your catalog linked to ours — inventory sync, new-variant creation, state-restriction data |
| Inventory levels | To keep the LGL stock location on your store accurate in near real time |
| Fulfillments | To push tracking numbers back to your orders when we ship |
We only access data needed to provide the service. We never read customer data unrelated to LGL-fulfilled orders, and we never use your data for advertising, profiling, or training AI models.
Where order data goes
Fulfilling an order means the ship-to details travel with it. Order data is shared only with the parties who need it to get the box to your customer's door:
- LGL's fulfillment system — the order is recreated on our systems so our warehouse can pick, pack, and ship it.
- ShipStation — our shipping platform, used to buy labels and track shipments.
- Fulfillment partners (3PLs / dropship suppliers) — when an item ships from a partner facility instead of our warehouse, that partner receives the ship-to details for that order only.
- Carriers (UPS, FedEx, USPS, etc.) — on the shipping label, as with any shipment.
Supporting infrastructure that processes data on our behalf: DigitalOcean (app hosting), Supabase (database), and Mailgun (operational email between LGL and your team — never to your customers). We don't sell data or share it with anyone else, and our providers are bound to use it only to provide their services to us.
We never contact your customers. All emails from the sync system go to your team or ours.
How long we keep it
| Data | Retention |
|---|---|
| Order webhook copies (the raw order data received from your store) | 90 days, then automatically deleted |
| Sync activity logs (operation metadata — counts, timestamps, no customer details) | 180 days |
| Operational email history between LGL and your team | 12 months |
| Order records in LGL's fulfillment system | Retained as business records of shipments we fulfilled, per standard legal and accounting requirements |
| Product link records (which of your products map to ours — no personal data) | For the life of our wholesale relationship |
If you uninstall the app
- Our access to your store ends immediately, and we delete our stored access credentials right away.
- 48 hours later, Shopify sends us a purge signal and we automatically delete your store's order data copies, sync logs, and alerts from our systems.
- We keep only records of the wholesale transactions we actually fulfilled (orders in our fulfillment system, invoices, and shipment records), as any supplier would.
Customer privacy requests (GDPR / CCPA)
The app implements Shopify's mandatory privacy webhooks, so requests flow through automatically:
- Data request — if your customer asks what data is held about them, Shopify notifies us and we compile what we hold (copies of their order data) so you can respond within the required window.
- Customer redaction — when you process an erasure request in Shopify admin, we automatically delete our stored copies of that customer's order data.
- Store redaction — after uninstall, your store's data is purged as described above.
If a customer request needs a hand, contact us — see Getting Help.
Security
Access to your store uses Shopify's OAuth with the minimum required scopes. All traffic is encrypted in transit (HTTPS), webhooks are signature-verified, and stored data is encrypted at rest by our database provider. Access to production systems is limited to the LGL team members who operate the service.
If we ever became aware of a breach affecting your data, we would notify Shopify within 24 hours and affected stores promptly, per our incident response process.
