Privacy policy
HyperSync copies data between two Shopify stores you own. This page says exactly what it reads, what it keeps, for how long, and where.
Who we are
HyperSync is built and operated by Hypermetron. For anything on this page, write to shopify@hypermetron.com or use the contact form.
What HyperSync accesses in your store
When you install HyperSync, Shopify asks you to approve a specific set of permissions. Those are the only things the app can reach:
- Products. Products, variants, options and their images.
- Content. Pages, blog posts, URL redirects and navigation menus.
- Files. Images and other files in your store's file library.
- Metafields and metaobjects. Custom fields and custom content types, including their definitions.
- Inventory and locations. Stock levels and the locations that hold them.
- Publications. Which sales channels a product or collection is published to.
HyperSync does not request access to customers or orders. It cannot read names, email addresses, shipping addresses, payment details or order history, because Shopify does not grant it those permissions. If that changes, this policy changes first.
What we store, and why
To copy a resource from one store to another, HyperSync temporarily stores the resource as it read it from the source store. It also stores a record of which item in the target store came from which item in the source — that mapping is what makes a second run update your data instead of duplicating it.
Alongside that we keep operational records: which runs happened, what they moved, what they skipped and why, and who started them. We process all of it to provide the service you installed the app for, and to be able to tell you what happened when a run goes wrong.
If you use in-app support, we store what you type and what the assistant answered, for 90 days. To answer you, the text of your question is sent to OpenAI, which processes it in the United States. Please do not paste customer details into support — HyperSync does not ask Shopify for customer or order access, so the only way that information reaches us is if you send it.
We do not sell data, we do not share it with advertisers, and we do not use it to train machine learning models — including the text you send to support.
How long we keep it
| Data | Kept for |
|---|---|
| Copied resource data | Deleted 30 days after the job that used it finishes |
| Export archives | Deleted 30 days after they are created |
| Run records — what moved, what was skipped | 90 days |
| Support messages and bug reports — what you typed to us | 90 days |
| Audit log — who ran what | 12 months |
| Everything belonging to a store | Deleted when Shopify sends the erasure request, 48 hours after uninstall |
Copied resource data expires fastest because it is the largest and most sensitive thing we hold and has no value once a job has succeeded. Nothing is kept indefinitely.
Where it is stored
Your store’s data stays in the European Union. The database is in Frankfurt, the application servers are in the EU, and export archives are in EU-jurisdiction object storage. Everything HyperSync reads from your store, writes to another store, or packages into an archive is processed there and nowhere else.
One thing leaves the EU, and only if you use it. If you ask the in-app support assistant a question, the text of that question is sent to OpenAI in the United States to answer it. Nothing else goes with it — not your products, not your customers, not your archives. If you would rather nothing left the EU at all, use the “report a problem” form instead; that reaches us by email and stays in the EU.
These are the third parties that process data on our behalf:
| Processor | Used for | Location |
|---|---|---|
| Neon | Database | Frankfurt, Germany |
| Vultr | Application servers | EU |
| Cloudflare R2 | Export archive storage | EU jurisdiction |
| Brevo | Notification email | EU |
| OpenAI | In-app support assistant | United States |
| Shopify | The stores you connect | Per Shopify's own terms |
Anything added later — error tracking, analytics — joins this list on this page before it goes live.
Uninstalling
Uninstalling HyperSync from a store ends our access to it immediately. Shopify then sends us an erasure request for that store 48 hours later, and we delete everything we hold for it — run history, copied data, export archives and audit records. You do not need to ask, and there is no 30-day wait.
One consequence worth stating plainly: if the store was paired with another, the shared history of that pairing is deleted too, because it is a record of the erased store as much as of the other one. The other store keeps everything from its other pairings.
Your rights
Under the GDPR you can ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. Write to shopify@hypermetron.com and we will answer within 30 days. If you are a shopper rather than a merchant: HyperSync holds no shopper data, so a request about your own orders or account belongs with the store you bought from, not with us.
You also have the right to complain to your national data protection authority.
Security
Data is encrypted in transit and at rest. Access tokens for your store are stored encrypted and are used only to carry out runs you start. Access to production systems is limited to the people who operate the service.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects what we collect or how long we keep it, we will tell installed merchants by email rather than relying on you re-reading this page.