Privacy Policy — mdSync
Last updated: 2026-06-17
mdSync (“the App”) is an application for Shopify stores that converts merchant-owned store content into Markdown files served on the merchant's storefront domain. This Privacy Policy explains what data the App processes when a merchant installs it.
1. Who we are
mdSync is operated by Digimetri (“we”, “us”). You can reach us at [email protected].
2. Data we process
When a merchant installs the App, we receive and store the following data from Shopify on the merchant's behalf:
- Shop identifier and access token — issued by Shopify during the OAuth install flow. Used solely to authenticate API requests on behalf of the installed store.
- Store catalog metadata — product titles, handles, descriptions, prices, images, vendor, tags, status; collection titles, handles, descriptions; page titles, handles, body; blog and article titles, handles, bodies, summaries. This metadata is fetched from Shopify on demand and is cached in our database to reduce API load. No customer data is fetched or stored.
We do not process or store:
- Customer personally identifiable information
- Orders, transactions, or payment data
- Email addresses or contact information of shoppers
- Any data outside the merchant's own catalog
3. How we use data
- To generate Markdown files served at
your-store.com/apps/llms/… for requests made by AI tools, browsers, or other clients.
- To respond to webhook events from Shopify (product, collection, and page updates) in order to keep cached Markdown fresh.
- To authenticate API requests when the merchant or AI tools request the generated content.
4. Sharing
We do not sell, rent, or share data with third parties. The generated Markdown is served only through Shopify's App Proxy on the merchant's own storefront domain — we do not host a third-party feed of merchant content.
5. Storage and retention
- Access tokens and cached Markdown are stored on encrypted servers hosted by our infrastructure provider.
- All shop-related data is automatically deleted when the merchant uninstalls the App: Shopify sends the
app/uninstalled and shop/redact webhooks, and our handlers delete all rows associated with the shop within the regulatory window.
- Customer data redaction requests (
customers/data_request, customers/redact) are acknowledged with a 200 response; the App does not store customer data so no action is required.
6. Your rights
If you are a merchant who has installed mdSync, you may:
- Request a copy of any data we hold about your shop — contact [email protected].
- Uninstall the App at any time; this triggers automatic deletion of all shop data.
- Request immediate deletion ahead of the automatic schedule.
7. Children
mdSync is a business-to-business tool. It is not directed at children under 16 and we do not knowingly process any data about minors.
8. Changes
We may update this Policy from time to time. The latest version will always be published at this URL. Material changes will be communicated to installed merchants via email.
9. Contact
Questions or requests: [email protected]