Privacy
Privacy.
Sync Master is built around a simple idea: only handle the data needed to sync inventory, and nothing else.
What we work with
Sync Master reads inventory quantities and product metafields from the Google Sheet you connect, and updates the matching variants in your Shopify store.
What we never touch
Sync Master does not collect customer personal data, order details, addresses, or payment information. It does not write back to your Google Sheet.
How your data is used
Your data is used solely to perform the inventory and metafield syncs you configure. It is never sold, never shared with third parties for marketing, and never used for advertising or profiling.
Storage
Configuration and credentials needed to operate the app are stored encrypted on Google Cloud (Tokyo region). Sync execution logs and inventory operation logs are retained for 30 days, then automatically deleted.
Deleting your data
You can disconnect Google access at any time from inside the app, which immediately deletes the stored tokens. Uninstalling Sync Master from your Shopify store immediately removes your associated data.
GDPR
Sync Master honors Shopify's standard customer data and shop redaction requests.
How we handle Google user data
Sync Master (provided by MTS APPS) accesses the following Google user data when you connect a Google account. Access is granted only through your explicit consent on the Google OAuth consent screen.
| Requested scope | Data accessed | Why we need it |
|---|---|---|
https://www.googleapis.com/auth/spreadsheets.readonly | The sheet names and cell values of the Google Spreadsheet you select inside the app — specifically the columns and rows you map (inventory quantities, SKU / barcode, and values written to metafields). | To read the contents of the sheet you select and apply them to the inventory quantities and metafields of the matching variants in your Shopify store. Access is read-only: we never write to, create, or delete any spreadsheet. |
https://www.googleapis.com/auth/userinfo.email | The email address of the connected Google account. | To identify which Google account is connected and display it in the app, so you do not sync with an unintended account. |
We do not access data from any other Google service, including Gmail, other files in Google Drive, Calendar, or Contacts.
Retention of the data we read
Cell values read from your spreadsheet are processed in memory only for as long as a sync run or a pre-apply preview requires, and are not stored afterwards. Audit logs record only the identifier being synced (SKU / barcode), the inventory quantity before and after the change, the timestamp, and the result status; records older than 30 days are removed automatically by a daily job. The Google account email address and the OAuth access and refresh tokens are retained only while the connection is active.
Sharing with third parties
We never sell Google user data. We never use it for advertising, targeting, profiling, or creditworthiness assessment, and we never allow humans to read it. It is not used to train AI or machine learning models. Sharing is limited to the infrastructure provider required to operate the app (Google Cloud Platform, Tokyo region); we disclose it to no other third party except where required by law.
Limited Use compliance
Sync Master's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect sensitive data
The following technical and organizational measures protect the Google user data obtained through the sensitive scope (spreadsheets.readonly) and the associated OAuth tokens.
- Encryption in transit
- All traffic to and from the app is encrypted with HTTPS (TLS) via Google Cloud Run. HTTP connections are automatically redirected to HTTPS.
- Encryption at rest
- The database (Cloud SQL) and logs are protected by Google Cloud's default encryption at rest (AES-256).
- Credential protection
- Google OAuth access and refresh tokens are encrypted with AES-256-GCM at the application layer before they are written to the database. The encryption key, the OAuth client secret, and the database connection string are managed in Google Secret Manager and loaded only at runtime. Tokens are never written to logs in plain text.
- Access control
- Access to the production environment (Cloud Run, Cloud SQL, Secret Manager) is restricted through Google Cloud IAM to personnel who need it for their role (principle of least privilege). Two-step verification is required on the Google accounts used for that access, and operations are recorded in Cloud Audit Logs.
- Data minimization
- We read only the cell values in the columns required for a sync. We neither read nor store customer personal data, order details, addresses, or payment information from your Shopify store.
- Retention and automatic deletion
- Sync execution logs and inventory operation logs are deleted automatically after 30 days. Sync configuration and credentials are retained only while the app remains installed.
- Your right to deletion
- Disconnecting Google from inside the app immediately deletes the stored OAuth tokens. Uninstalling the app from Shopify immediately deletes the associated data — sessions, Google credentials, sync configuration, and execution logs — and a final deletion is performed when Shopify sends the shop redaction request (shop/redact) 48 hours later. For deletion requests, contact studio@hit-an.com.
- Operational practices
- The infrastructure runs on Google Cloud (Tokyo region, asia-northeast1), and dependencies are continuously monitored for vulnerabilities and updated. If we become aware of a personal data breach, we notify the relevant supervisory authority and affected users within the deadlines set by applicable law.
Contact
For questions about this policy or how your data is handled, and for data deletion requests, contact MTS APPS (Chuo-ku, Tokyo) at studio@hit-an.com.
This page is the complete privacy policy for Sync Master and is readable in full without signing in or installing the app. Last updated: August 7, 2026.