Privacy Policy
Last updated: August 13, 2026
This policy explains what data Syncproof, a product of Skeg Software, a sole proprietorship operated by Justin Breshears, collects, and why. It covers two different things, because they're at two different stages:
- sync-proof.com, the website you're reading right now. It's live today.
- The Syncproof app, a Shopify + Amazon multichannel inventory sync tool. It's still in development and hasn't launched. The section below titled "When the Syncproof app launches" describes how it will handle data once it's live, so you can review it ahead of time.
The short version for the website: it's a static page. No accounts, no cookies, no analytics, no tracking scripts, no forms. The only thing we ever receive is an email, if you choose to send one to hello@sync-proof.com or support@sync-proof.com.
This website, today
sync-proof.com does not:
- require or offer an account or login
- set cookies of any kind
- run analytics, ad pixels, or third-party tracking scripts
- include any forms that collect information
If you email hello@sync-proof.com or support@sync-proof.com, we receive your email address and whatever you write to us. We use that only to reply to you. We don't add it to a mailing list, use it for marketing, or share or sell it to anyone.
Like any website, our hosting provider automatically logs basic technical request data (IP address, browser type, date and time) for every visit, to keep the site secure and to detect abuse. We don't use these logs for anything beyond that, and nothing on the site links them to you personally.
When the Syncproof app launches
Everything in this section describes planned practices for the Syncproof application, which is still being built. It is not live, and nothing described here is happening yet. We're publishing it now so merchants, reviewers, and platform partners can see how it will work before it does.
What Syncproof will do
Syncproof will be a Shopify app that keeps a merchant's inventory, orders, and listings in sync between their Shopify store and their Amazon Seller Central account, and lets them purchase and track shipping labels for their orders.
Who's responsible for the data
The merchant (the store that installs Syncproof) is the data controller. Skeg Software acts as a data processor, handling data only to provide the app's functionality on the merchant's instructions. If you're a shopper with a question about your data, the store you ordered from is who to contact first. We'll assist them promptly if they reach out to us.
What we'll collect
| Source | Data | Why |
|---|---|---|
| Merchant | Shopify store domain, Shopify and Amazon connection tokens, account contact email, billing plan | Run the app, keep it connected, contact the merchant about their account |
| Shopify orders | Order ID, SKUs, quantities, fulfillment status, and, only for orders where a shipping label is purchased through Syncproof, the buyer's ship-to name, address, and phone number | Reconcile orders across channels; print an accurate shipping label |
| Inventory & listings | SKU/product identifiers, quantity levels, listing status, across each connected channel | Keep stock levels and listings consistent everywhere the merchant sells |
| Amazon orders | Order ID, SKUs, quantities, order status | Reconcile Amazon orders against inventory and Shopify |
We will not collect Amazon buyer personal information. Syncproof's initial release does not request Amazon's restricted data permissions and never calls the Amazon APIs that return a buyer's name, address, or contact details. If we later add a feature that needs that (for example, printing Amazon-fulfilled shipping labels), it will go through Amazon's own restricted-access approval process and this policy will be updated first.
We do not use any of this data for advertising, marketing, profiling, or resale.
Who we'll share it with
We don't sell data. Running the app requires a small set of service providers:
| Provider | Purpose |
|---|---|
| Supabase | Application database, hosted in the United States |
| Vercel | Application hosting |
| Render | Background sync worker |
| EasyPost | Shipping label purchase and tracking |
| Resend | Delivery of transactional email notices |
| Sentry | Error monitoring (technical diagnostics only, not tracking) |
| Backblaze B2 | Encrypted, offsite backup storage |
Separately, Syncproof connects directly to the platforms the merchant chooses to link: Shopify and Amazon (via the Selling Partner API). Those connections are authorized by the merchant, not something we broker on their behalf, and each platform's own privacy terms govern how it handles the data it holds.
How we'll protect it
- Encryption in transit (TLS) everywhere, and encryption at rest (AES-256) for stored data.
- Connection tokens (the credentials that let Syncproof talk to a merchant's store) are encrypted with a separate key from the one protecting buyer personal data, so a compromise of one doesn't expose the other.
- Every time buyer personal data is viewed or used (for example, to print a label), we log it: who or what accessed it, and why.
- Least-privilege access to production systems, with multi-factor authentication.
- Separate development and production databases; production data is never copied into development.
How long we'll keep it
- Buyer ship-to data (name, address, phone) is held for 60 days after the order is fulfilled or delivered by default, then permanently deleted. Merchants can configure a shorter window.
- Our internal sync/activity log, the history that lets a merchant see what Syncproof did and when, and lets us troubleshoot issues, is kept for up to 12 months, and is built so it never contains buyer personal information, only order and product identifiers.
- When a merchant uninstalls the app, we delete their connection tokens immediately and their remaining data on Shopify's standard compliance timeline (below).
- During the early pilot period, shipping-label postage for some merchants may be paid through a platform-level EasyPost account rather than the merchant's own; that's a billing detail, not a data-sharing one, and it will move to per-merchant accounts as Syncproof leaves pilot.
GDPR / CCPA requests
We honor Shopify's mandatory privacy webhooks: a data request is fulfilled within 30 days, a customer redaction request erases that customer's personal data from our records, and a shop redaction request (sent after uninstall) purges the store's data entirely. If you'd like to exercise a data access, correction, export, or deletion right and you're a shopper, please start with the store you ordered from. We support them directly. Merchants, or anyone with a question about how we handle data, can reach us at support@sync-proof.com. If your business needs a signed Data Processing Addendum, ask and we'll provide one.
International transfers
Our service providers are primarily based in and process data within the United States.
Children
Syncproof is a business tool for merchants and isn't directed at children. We don't knowingly collect personal data from children.
Changes to this policy
If we make a material change, we'll update the date at the top of this page and, once the app is live, notify merchants in-app where appropriate.
Contact
Skeg Software, a sole proprietorship operated by Justin Breshears
515 S Fry Road, Ste A PMB 1002, Katy, TX 77450, United States
support@sync-proof.com