Privacy Policy
Syntacraft Software Studio (“Syntacraft”, “we”, “us”, or “our”) operates syntacraft.com and builds high-performance commerce applications for the Shopify ecosystem, including NativeQuote and TierBoost. This Privacy Policy details our data practices, zero-PCD architectural commitment, and merchant privacy protections.
Core Privacy Commitment: Zero Protected Customer Data (Zero PCD)
Syntacraft applications are engineered with strict data minimization. We do not collect, monetize, broker, or store shoppers' Personally Identifiable Information (PII) or Protected Customer Data (PCD). We do not require customer-level database access to execute wholesale quoting or checkout discounts.
1. Information We Collect and Process
When you install our applications on your Shopify store, we access store configuration metadata strictly through official Shopify Admin GraphQL APIs:
- Store Metadata: Shop domain, currency, timezone, and active subscription plan.
- Catalog References: Shopify Product IDs, Variant IDs, Collection IDs, and inventory status necessary to configure quoting and tiered discount rules.
- Merchant Settings: UI design tokens (colors, corner radius, layouts), discount rule thresholds, and upsell configurations.
- Wholesale Quotes (NativeQuote): Merchant-reviewed quote requests and staged draft orders generated directly inside your Shopify Admin.
2. How Shopify Functions & Discounts Operate (TierBoost)
TierBoost's volume discounts execute natively inside Shopify's checkout engine using Shopify Functions compiled to WebAssembly (Wasm). Calculations run serverless at Shopify's edge in under 5 milliseconds. No shopper data or payment credentials ever pass through Syntacraft servers during checkout.
3. Data Security & Storage
All store configurations and session tokens are encrypted at rest using industry-standard AES-256 encryption. Our production services run on isolated containers behind hardened firewalls, Cloudflare Zero Trust tunnels, and Tailscale mesh networks. Access to databases is restricted strictly to automated production application processes.
4. GDPR, CCPA & Automated Webhook Compliance
We provide full support for Shopify's mandatory privacy compliance webhooks with cryptographic HMAC validation:
- Customer Data Request: We verify that no personal shopper records are stored.
- Customer Redact: Any referenced customer tokens are immediately expunged.
- Shop Redact: When an app is uninstalled, all store configuration data and access tokens are permanently deleted within 48 hours.
5. Third-Party Sharing
We do not sell, rent, broker, or trade merchant catalog data or store performance metrics with third parties, advertisers, or data brokers.
6. Contact Information
If you have any questions or data requests regarding this Privacy Policy, please contact our Data Protection Officer at:
Syntacraft Software Studio
Email: [email protected]
Founder Contact: [email protected]
Website: https://syntacraft.com