Skip to content
S ShoopSync
Features Plugins Pricing FAQ Contact PL EN

Privacy policy

Effective date: 2026-07-20

Data controller

ShoopSync (hereinafter: "the App", "we") is a mobile manager for WooCommerce and PrestaShop stores. The controller of data processed by the App and the associated backend api.shoopsync.com is:

Clima Boost Jakub Lipiński
Tax ID PL5971544886
Kościuszki 70A, 55-330 Lutynia, Poland
E-mail: support@shoopsync.com

What data we do NOT process

ShoopSync is a REST API client of your store. Your order list, your customers' data (name, address, e-mail, phone, order numbers, values, invoices, notification content), products and stock levels — the App fetches these directly from your store and displays them on your phone. They never reach our backend.

Your store's API keys (WooCommerce consumer key + consumer secret, or PrestaShop webservice key) are stored exclusively on your phone in SharedPreferences and are not sent to us.

What data we do process

On the api.shoopsync.com backend we store the minimum required to run push notifications and subscription licensing:

DataPurposeLegal basis (GDPR)
FCM token (Google Firebase)Sending push notificationsArt. 6(1)(b) — contract performance
Store hostname (e.g. yourstore.com)Routing pushes to the right phoneArt. 6(1)(b)
Install token (32-byte random)Authenticating requests from the storeArt. 6(1)(b)
E-mail of Premium purchaserInvoicing, subscription contactArt. 6(1)(b), 6(1)(c) — accounting obligation
Android device identifier (ANDROID_ID)Fraud prevention (e.g. reinstalling to get another trial)Art. 6(1)(f) — legitimate interest
Google Play Integrity verdictApp authenticity verificationArt. 6(1)(f)
Device model, App versionTechnical support, error diagnosticsArt. 6(1)(f)
Subscription status (plan, dates, payment status)Subscription contract executionArt. 6(1)(b)
Short store event metadata (order number, total, currency, item count)Push notification contentArt. 6(1)(b)

The push metadata contains only: order number, amount, currency, item count, buyer's name (if your store sends it). We do not store addresses, phone numbers, e-mails of your store's customers, order contents, payment data or shipping data.

Payments

Premium subscription payments are handled by Google Play Billing. Our App has no access to your payment data (card number, CVV) — Google stores them.

We issue a VAT invoice after every settled payment. The invoice contains your name (from the Google Play account) and e-mail address — data required by VAT law.

Who we share data with

Infrastructure providers processing data on our behalf:

  • Google LLC — Firebase Cloud Messaging (push), Google Play Billing (payments), Google Play Integrity (anti-fraud). Google signed EU Standard Contractual Clauses (SCC).
  • Backend infrastructure hosting (Poland) — the server running api.shoopsync.com.

We do not sell your data to any third party. We do not use it for advertising. This website contains no trackers, no advertising pixels, no Google Analytics.

Retention period

DataPeriod
FCM token, install_tokenUntil App uninstall or account deletion
Subscription, license_keyUntil accounting requirements end — 5 years from the end of the fiscal year
VAT invoices5 years from the end of the fiscal year (Polish Tax Ordinance Art. 86 § 1)
Android ID on the trial_used list5 years — anti-fraud, preventing repeated trial abuse
Diagnostic logs (Push diagnostics)90 days

Your rights

Under GDPR you have the right to:

  • Access your data (Art. 15)
  • Rectify incorrect data (Art. 16)
  • Erasure ("right to be forgotten", Art. 17) — the "Delete account" function in App Settings removes all your data from our databases except data required by law (invoices, anti-fraud Android ID)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time

To exercise any of these rights, write to support@shoopsync.com.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (uodo.gov.pl, Poland) or your local supervisory authority.

Security

  • All communication between the App, the backend and your store uses HTTPS (TLS 1.2+).
  • Your store's API keys are stored only on your phone in SharedPreferences, isolated by the Android sandbox.
  • FCM tokens and license_key are stored on the server in a MariaDB database, access limited to the PHP-FPM process account.
  • The App uses the Google Play Integrity API to detect tampered installations.
  • All server-side requests from the App are signed with HMAC-SHA256 using the client's install_token.

Children

ShoopSync is a B2B tool for online sellers. It is not intended for persons under 18.

Policy changes

If we change these terms, we will publish a new version in the App (Settings → Privacy policy) with an effective date. Significant changes will be announced by push notification.

Contact

For matters concerning your personal data: support@shoopsync.com

© 2026 ShoopSync
Privacy policy Terms of service Polski