Privacy Policy — HermesSync
Last updated: June 30, 2026
HermesSync ("we", "us", "the App") is a Shopify-embedded application that helps merchants discover trending products, source them from third-party suppliers, generate AI product listings and ad creatives, and publish them to their Shopify store. This policy explains what data we collect, why, and how we handle it.
1. Who this policy covers
This policy covers merchants who install and use HermesSync on their Shopify store. The App does not collect, store, or process data belonging to your customers (shoppers).
2. Data we collect
2.1 Merchant & store data
When you install HermesSync, Shopify provides us with:
- Your store domain (
*.myshopify.com) and shop ID - Store contact email and basic shop profile information
- An OAuth access token used to call the Shopify Admin API on your behalf
2.2 Store catalog data (Shopify Admin API)
With your authorization, the App reads and writes the following via the Shopify Admin API, using these access scopes:
read_products,write_products— to import, create, and update products and listingsread_themes,write_themes— to publish HermesSync product-page sections and templates into your online store themeread_discounts,write_discounts— to create and manage discount codes for product bundles/offers
2.3 Data we do not collect
HermesSync does not request or access:
- Customer personal information (names, emails, addresses, phone numbers)
- Order or transaction data
- Payment or financial information of your customers
We hold no Shopify scopes granting access to customer or order data.
2.4 Usage & operational data
We store operational records needed to run the service, including:
- Subscription plan, billing cycle, and feature-usage counters (e.g. number of product imports, AI generations, ad creatives used)
- Job/processing logs for background tasks (product imports, AI generation, theme sync)
- Encrypted credentials you provide for connected third-party services
2.5 Third-party credentials
If you connect external services (e.g. supplier or sourcing accounts), the credentials you supply are stored encrypted at rest in our database and are used only to perform the actions you request.
3. How we use your data
We use the data above solely to:
- Authenticate you and operate the App inside Shopify Admin
- Discover and source products and import them into your store
- Generate AI-assisted product descriptions, page content, and ad creatives
- Publish content and discounts to your store
- Enforce plan limits and billing
- Provide support and improve App reliability
We do not sell your data or use it for advertising.
4. Third-party services
To provide its features, HermesSync shares limited data with the following subprocessors, only as needed to perform a requested action:
| Service | Purpose | Data shared |
|---|---|---|
| Shopify | Core platform & Admin API | Store domain, access token, product/theme/discount data |
| AI providers (e.g. OpenAI) | Generate product listings, page content, ad creatives | Product attributes, copywriting prompts, and media/product images submitted for AI transformation |
| CJ (CJdropshipping) | Product sourcing & supplier catalog/inventory data | Product identifiers and sourcing queries |
| ScrapeCreators | Trend/discovery signals for product research | Product/keyword search parameters |
Each provider processes data under its own privacy terms. We share only what is necessary for the feature you use.
5. Data retention
We retain merchant and operational data for as long as your store has the App installed. When you uninstall the App, Shopify notifies us via the mandatory app/uninstalled webhook and we delete or anonymize your store's data in accordance with Shopify's requirements and applicable law. You may request earlier deletion at any time (see Contact).
6. Data security
- All data is transmitted over encrypted connections (HTTPS/TLS).
- Third-party credentials are encrypted at rest.
- Access tokens and secrets are never hardcoded and are stored securely.
- Access to production data is restricted to authorized personnel.
7. Your rights
Depending on your jurisdiction (e.g. GDPR, CCPA), you may have the right to access, correct, export, or delete the data we hold about your store. To exercise these rights, contact us using the details below.
8. Shopify mandatory compliance webhooks
In line with Shopify requirements, we implement the mandatory privacy webhooks:
customers/data_request— we hold no customer data; we respond accordingly.customers/redact— we hold no customer data; no action required on our side.shop/redact— on receipt, we delete the store's data from our systems.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to merchants.
10. Contact
For privacy questions or data requests, contact:
Email: ike@hermessync.ai