Last updated 26 July 2026
Syncline is operated by Second Act Labs. It keeps a Shopify store's products and inventory in sync with a Google Sheet. This policy describes exactly what data that requires, why, and how long we keep it.
Syncline requests a single Google Drive permission, drive.file. This is Google's narrowest Drive scope: it grants access only to files this app itself creates. Syncline cannot see, list, open or search any other file in your Drive, and cannot access a spreadsheet you made yourself unless you explicitly hand it to us.
We deliberately do not request the broader spreadsheets or drive scopes, which would grant access to your entire Drive.
We also request openid, email and profile solely to show which Google account is connected, so you can confirm you linked the right one.
Syncline requests no access to customers, orders, or payment data, and holds none. Its Shopify permissions are limited to products, inventory and locations.
Solely to operate the sync you configured: reading products from Shopify to write them to your sheet, reading your sheet to update Shopify, and showing you the resulting status and history.
We do not sell your data, share it with advertisers, use it for advertising or profiling, or use it to train machine-learning models. Google user data obtained through Syncline is used only to provide this functionality and is handled in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Data is stored on Cloudflare's infrastructure and processed in Cloudflare Workers. Sub-processors are Cloudflare (hosting and database), Shopify (the store you connect) and Google (the Drive account you connect).
Uninstalling Syncline from your Shopify store stops all syncing immediately. Your configuration is retained for up to 30 days so a reinstall can resume where you left off, then deleted.
You can revoke Syncline's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops syncing at once; spreadsheets we created remain in your Drive and stay yours.
To request immediate deletion of all data we hold about your store, email syncline@secondactlabs.io from the address associated with the account. We action such requests within 30 days.
All traffic is served over HTTPS. Google refresh tokens are encrypted at rest with AES-256-GCM using a key held separately from the database. Requests from the Apps Script integration are authenticated with a per-store shared secret compared in constant time.
Questions, access requests, or deletion requests: syncline@secondactlabs.io.