Skip to content
✓PalSync
Platform Solutions AI Evidence Integrations Guides Pricing Start free
Start free

Privacy Policy

Last updated: July 6, 2026

1. Who we are

PalSync (“PalSync”, “we”, “us”) is a Shopify application that synchronizes order tracking information from a merchant’s Shopify store to the merchant’s PayPal and Stripe accounts, and provides related tools such as historical back-sync, courier mapping and PayPal dispute management. This policy explains what data we handle to provide that service, and the choices you have. It applies to palsync.com and to the PalSync app installed from the Shopify App Store.

2. Information we collect

Store information. When you install PalSync, Shopify shares basic store details with us: your store name and myshopify domain, the store owner’s name and email address, store locale and plan. We use this to run your account, bill through Shopify and contact you about the service.

Order and fulfillment data. To do its job, PalSync reads the order data the sync requires: order numbers and IDs, fulfillment status, tracking numbers, carrier names, transaction references, order dates and amounts. Where an order includes buyer details (such as a name attached to a transaction reference), we process them only as needed to match the order to the right PayPal or Stripe transaction.

Payment platform connections. When you connect PayPal or Stripe, the connection is made through each platform’s official OAuth flow. We store the resulting access tokens and account identifiers (such as your PayPal merchant ID) so the sync can run. We never see, ask for or store your PayPal, Stripe or Shopify passwords, and we never receive your customers’ full card numbers.

Dispute data. If you use dispute management, we read the disputes PayPal exposes for your connected account (case ID, reason, status, transaction reference) so you can track and respond from PalSync.

Support and correspondence. If you contact us, we keep the message and your contact details so we can reply and improve the service.

Technical data. Our servers keep standard logs (IP address, timestamps, request data, sync outcomes) for security, debugging and reliability. The palsync.com website itself does not set advertising cookies.

3. What we do not collect

  • No PayPal, Stripe or Shopify passwords — connections use official OAuth APIs and can be revoked by you at any time.
  • No full payment card numbers.
  • No sale of personal data to advertisers or data brokers — we do not sell personal data.

4. How we use information

  • To provide the service: pushing tracking numbers and carriers to the correct PayPal and Stripe transactions, back-syncing past orders, applying courier mapping rules and surfacing disputes.
  • To operate billing through Shopify’s billing system.
  • To provide support and send service messages (such as sync failures that need your attention).
  • To secure, debug and improve the service.

Where the GDPR or similar laws apply, our legal bases are performance of a contract (running the app you installed), legitimate interests (security, support, service improvement) and consent where required.

5. How information is shared

We share data only as needed to run PalSync: with Shopify, PayPal and Stripe through their official APIs at your direction (that transfer is the product); with infrastructure providers that host our servers and databases under data-processing agreements; and with authorities where the law genuinely requires it. We do not sell or rent personal data.

6. Your customers’ data

For personal data contained in your store’s orders, you (the merchant) are the data controller and PalSync acts as a processor on your instructions. You are responsible for disclosing this processing in your own store’s privacy policy. We process such data only to provide the sync and never for our own marketing.

7. Shopify privacy webhooks

PalSync implements Shopify’s mandatory privacy webhooks. When Shopify sends a customers/data_request, customers/redact or shop/redact request, we honor it automatically: customer data is exported or deleted, and after you uninstall, shop data is deleted when Shopify issues the shop redaction request (48 hours after uninstall).

8. Data retention

We keep data while the app is installed because the service needs it. After uninstall, OAuth tokens are invalidated and store and order data are deleted within 30 days (and in any case upon Shopify’s redaction webhooks), except minimal billing and accounting records we are legally required to keep.

9. Security

Data is encrypted in transit (TLS) and at rest, platform connections use OAuth rather than credentials, and access to production data is restricted to personnel who need it to operate the service. No method of transmission or storage is 100% secure, but we work to protect your data at the level expected of a payments-adjacent service.

10. International transfers

Our infrastructure and the platforms we integrate with (Shopify, PayPal, Stripe) may process data outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

11. Your rights

Depending on where you live (for example under the GDPR, UK GDPR or CCPA), you may have the right to access, correct, delete, restrict or port your personal data, and to object to certain processing. Write to us at support@palsync.com and we will respond within one month. California residents: we do not sell personal information. You may also lodge a complaint with your local supervisory authority.

12. Children

PalSync is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

If we change this policy in a meaningful way, we will update this page and its date, and for significant changes we will notify you in the app or by email.

14. Contact

Questions about privacy: support@palsync.com.

✓PalSync

The PayPal operations layer for ecommerce.

PlatformOverviewAI Evidence CopilotSecurity
SolutionsTracking syncDisputesClaims & chargebacks
CompanyAboutProduct statusEditorial policyAccessibility
PrivacyTermsFAQResourcesPricing
PalSync is an independent application and is not affiliated with, endorsed by, or sponsored by PayPal, Shopify, WooCommerce, BigCommerce, Wix, Salesforce, Adobe, Magento, Squarespace, PrestaShop, OpenCart, OpenAI, Anthropic, Google, Microsoft, or OpenRouter. Product names identify supported or planned integrations only.