Syncline

Privacy Policy

Effective 31 July 2026 · Last updated 31 July 2026

1. Introduction and Scope

This Privacy Policy explains how Second Act Labs ("Second Act Labs," "we," "us," or "our," the "Operator") collects, uses, stores, discloses, and protects information in connection with Syncline (the "Service"), a Shopify application that synchronizes product and inventory data between a merchant's Shopify store and a Google Sheet.

This Policy applies to all users who install, connect, or otherwise use the Service, including Shopify merchants and any staff accounts they authorize (collectively, "you" or "User"). It does not apply to Shopify's own data practices, Google's own data practices, or any third-party website or service you may link to — each is governed by its own privacy policy.

By installing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, do not install or continue using the Service.

The Service is made available at the Operator's sole discretion and may be modified, restricted, or discontinued at any time as described in Section 18. This Policy should be read together with the Terms of Service, which governs your use of the Service and takes precedence on all matters of liability, availability, and dispute resolution.

2. Definitions

3. Data Controller / Data Fiduciary

"Second Act Labs" is the trade name under which the Service is operated (the "Operator"). Second Act Labs is not represented, and should not be construed, as a registered company, corporation, partnership, or other formal legal entity unless expressly stated otherwise. References to "we," "us," or "our" throughout this Policy refer to the Operator.

The Service and this Policy are governed primarily by the laws of India, including the Digital Personal Data Protection Act, 2023 ("DPDPA"), consistent with the governing-law provisions of the Terms of Service. Where a User or the individual whose data is processed is located in the European Economic Area, UK, or Switzerland, certain GDPR obligations may also apply by virtue of that law's extraterritorial reach (Art. 3 GDPR) — we describe those obligations in this Policy for completeness and because Google requires certain of them contractually as a condition of API access, not as a concession on choice of forum for disputes (see Terms of Service, Governing Law).

All communications regarding this Policy, including data subject requests, should be directed to the contact channel below. We do not publish individual personnel names in connection with the Service; this is standard practice for independently operated software projects and does not affect your rights or our obligations under this Policy.

Contact: syncline@secondactlabs.io

4. Data We Collect

We collect only what is necessary to operate the sync you configure, grouped below by source.

4.1 Shopify store data

  • Store domain and the OAuth access token Shopify issues on install.
  • Product, variant, and inventory-item identifiers, titles, prices, SKUs, quantities, and location data.
  • Shop-level metadata needed for API calls (shop name, plan, timezone).

We do not request or receive customer records, order data, or payment information. Syncline's Shopify permission scope is limited to products, inventory, and locations.

4.2 Google account and Drive data

  • Google account email address, used only to display which account is connected.
  • OAuth access and refresh tokens, scoped to drive.file (access limited to files this app creates), plus openid, email, and profile.
  • The ID and configuration of the spreadsheet Syncline creates.
  • A shared secret used to authenticate the optional Apps Script integration.

We do not request the broader drive or spreadsheets scopes. We cannot see, list, search, or open any file in your Drive other than the one we create for you, unless you explicitly share another file with the app.

4.3 Sync state and logs

  • Cryptographic hashes of synced field values, used to detect changes without retaining a duplicate copy of your catalogue.
  • Row-to-product mappings and timestamps.
  • Activity and error logs describing sync events, for audit and troubleshooting.

4.4 Technical and usage data

  • IP address, request timestamps, and user-agent strings captured in standard infrastructure logs (Cloudflare) for security and abuse prevention.
  • We do not use cookies or client-side tracking technologies beyond what is strictly necessary for the Shopify embedded app session to function.

4.5 Data we never collect

We do not collect, request, or store customer personal data, order history, payment card data, health data, or any other sensitive personal data. If you configure custom fields that inadvertently include such data, you are solely responsible for that configuration; see Section 6 of the Terms of Service. We accept no liability for User-introduced sensitive data as set out in the Terms of Service.

5. Legal Basis for Processing

Under India's DPDPA, we process Personal Data on the basis of your consent, given when you connect your Shopify store and Google account, and as reasonably necessary to provide the Service you have requested.

Where GDPR applies extraterritorially (i.e., where you are located in the EEA/UK/Switzerland), we process on the following bases: performance of a contract (Art. 6(1)(b)) for core account and sync data; legitimate interests (Art. 6(1)(f)) for security and abuse-prevention logs; consent (Art. 6(1)(a)) for the Google account connection, revocable at any time; and legal obligation (Art. 6(1)(c)) where required.

Nothing in this Section creates an obligation on the Operator beyond what is legally mandatory in the jurisdiction where a given User or data subject is actually located.

6. How We Use Data

We use collected data solely to:

We do not sell Personal Data. We do not use it for advertising, behavioral profiling, or to train machine-learning models. Google user data obtained via Syncline is used only to provide user-facing features of the app, consistent with the Google API Services User Data Policy, including its Limited Use requirements.

7. Google API Services User Data Policy

Syncline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

This section reflects Google's platform requirements for maintaining API access and is independent of the liability and jurisdiction terms in the Terms of Service.

8. Sub-processors and Third-Party Disclosure

We use the following sub-processors:

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, compute (Workers), and database storageGlobal edge network, U.S.-headquartered
Shopify Inc.The store platform you connectCanada-headquartered, global infrastructure
Google LLCThe Drive/Sheets account you connectU.S.-headquartered, global infrastructure

We do not otherwise share, rent, sell, or disclose Personal Data to third parties, except:

We give no assurance regarding the ongoing availability, security practices, or continuity of any sub-processor and accept no liability for their acts or omissions, to the maximum extent permitted by law (see Terms of Service, Limitation of Liability).

9. International Data Transfers

Our sub-processors operate global infrastructure, which means your data may be processed outside your country of residence, including in the United States. We rely on each sub-processor's own compliance mechanisms (including, where applicable, Standard Contractual Clauses) for transfers out of the EEA/UK/Switzerland. As a small, India-based operation, we do not independently execute additional transfer safeguards beyond what our sub-processors provide.

10. Security Measures

We maintain the following safeguards on a reasonable-efforts basis, given our size and stage:

No security measure is perfect. We make no representation or warranty, express or implied, that the Service is or will remain secure, or that unauthorized access, token compromise, or data loss cannot occur. You accept this risk by using the Service. See Terms of Service, Disclaimer of Warranties and Limitation of Liability, which govern the legal consequences of any security incident.

11. Data Breach Notification

We will make commercially reasonable efforts, appropriate to our size as a small operator, to investigate and contain a security incident affecting Personal Data we hold. Where required by applicable law (including the DPDPA or GDPR, as relevant to the affected individual), we will notify the competent authority and/or affected individuals within the timeframe required by that law. Outside of a strict legal requirement to do so, notification timing and method are at our discretion, and delay or difficulty in providing notice does not, by itself, create liability beyond what is mandated by applicable law. Our maximum liability in connection with any such incident is governed by the Terms of Service.

12. Data Retention and Deletion

13. Your Rights

Where applicable law (DPDPA, GDPR, CCPA, or equivalent) gives you rights over your Personal Data — including access, correction, erasure, portability, restriction, objection, or withdrawal of consent — you may exercise them by emailing syncline@secondactlabs.io. We will respond within the time required by the applicable law governing your specific request; where no specific law applies, we will respond within a reasonable time. We may need to verify your identity before acting on a request. Users in India may also contact the Data Protection Board of India per DPDPA grievance-redressal procedures; EEA/UK users may contact their local supervisory authority.

14. Children's Privacy

The Service is intended for business use by Shopify merchants and is not directed at, and should not be used by, individuals under 18. We do not knowingly collect Personal Data from children.

15. Cookies and Similar Technologies

The Service does not use advertising or analytics cookies. It may use strictly necessary session identifiers required for the Shopify embedded app framework to function.

16. Automated Decision-Making

We do not use Personal Data for automated decision-making or profiling producing legal or similarly significant effects on you. Sync logic — matching rows to products, detecting changed hashes — is deterministic processing configured by you.

17. No Guarantee of Continuity

The Service is provided on a discretionary, at-will basis. We make no commitment, express or implied, as to how long the Service will remain available, and we may modify, restrict, suspend, or discontinue it, in whole or in part, at any time and for any reason, including reasons personal to the Operator (such as change in circumstances, availability, health, business priorities, or simple discontinuation of interest), without prior notice and without liability. See Section 18 and the Terms of Service (Suspension, Modification, and Discontinuation; Limitation of Liability) for the full terms governing this.

18. Effect of Suspension or Discontinuation on Your Data

If the Service is suspended or discontinued for any reason:

19. Changes to This Policy

We may update this Policy at any time, at our discretion. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance. We are not obligated to provide advance notice of changes, though we may do so where required by law.

20. Contact

Questions or data-related requests:

Second Act Labs
Email: syncline@secondactlabs.io

Because the Operator is based in India and has no establishment in the EEA/UK, no EU/UK representative has been appointed under GDPR Art. 27; this is a known gap that would need to be closed if the Service acquires a meaningful EEA/UK user base, but is not something we commit to doing on any particular timeline.