arrow_back Home

Privacy Policy for the EzguSavdo Connector app for Shopify

What data the app processes from your Shopify store

history_edu Edition of 29 August 2026. In force from the moment of publication on ezgusavdo.uz.

This Policy applies to the EzguSavdo Connector app (the App) — an application listed in the Shopify App Store and installed by the User into their own Shopify store.

The Policy describes what data the App reads from the Shopify store, which of it the rights holder stores, for how long and in what form, and how that data is deleted. Terms of use for the App are set out in the Terms of Service. Processing of data inside the EzguSavdo service, into which the App imports the catalog, is additionally governed by the general Privacy Policy; where the App is concerned, this document takes precedence.

The Russian edition of this document is the legally binding one. It is published at ezgusavdo.uz/ru/legal/connector-privacy.


1. Rights holder and operator

1.1. The rights holder of the App and the operator of data processing is EZGUPRO LLC, tax ID (INN) 313189635, Republic of Uzbekistan, Tashkent (the Operator). Full details are in section 10.

1.2. The User is a natural person, sole trader or legal entity that has installed the App into their Shopify store.

1.3. The Store is the User’s Shopify store instance with the App installed, identified by a domain of the form your-store.myshopify.com.

2. Purpose of the App and the direction of data transfer

2.1. The App transfers the product catalog, prices and inventory from the Store into the EzguSavdo service, so that those products can be sold in the EzguSavdo chat channels (Telegram, Instagram, web widget).

2.2. Data transfer is one-way: from Shopify into EzguSavdo. The App does not create, modify or delete any object in the Store. The only records the App creates on the Shopify side are subscriptions to webhooks about changes to the catalog it reads.

2.3. The App requests three read-only access scopes and nothing else:

  • read_products — products, variants, options, prices, images, collections;
  • read_inventory — stock levels per location;
  • read_locations — the list of the Store’s locations.

2.4. The App does not request and technically does not receive access to orders, customers, checkout, payments, shipping, staff accounts, themes or files. The scopes read_orders, read_customers, read_checkouts, any payment scope and any write scope are not requested by the App.

3. Data the App reads from the Store

3.1. The following is read from the Store:

  • products: identifier (GID), title, description, publication status, tags, type, vendor, collections;
  • variants: identifier (GID), title, option values, SKU, barcode, price, compare-at price, whether inventory is tracked;
  • images and media: file addresses of product images;
  • inventory: available quantity at each location;
  • locations: identifier, name, active flag;
  • store details: name, myshopify.com domain, currency, time zone, money format, the store owner’s contact e-mail.

3.2. No personal data of the Store’s customers is read. The App has no access to orders or customers, so names, phone numbers, addresses and e-mail addresses of buyers, as well as payment and cart data, are unavailable to the App as a matter of technical fact rather than of policy.

3.3. The store owner’s contact e-mail in clause 3.1 is data of the User, not of a customer. It is used solely to make contact about how the integration is working.

4. Data the Operator stores

4.1. The following is stored on the Operator’s servers:

  • Store identity: myshopify.com domain, name, currency, owner’s contact e-mail, the Admin API version in use;
  • the access token for the Store’s Admin API, issued by Shopify — in encrypted form only (see section 5);
  • the list of granted access scopes (read_products, read_inventory, read_locations) and timestamps of installation, connection and removal of the App;
  • the imported catalog: products, variants, prices, stock, image links and Shopify identifiers (GIDs), stored in the User’s store inside the EzguSavdo service;
  • mapping settings: currency conversion rate, markup, selected locations, rules for handling products that disappear, sync interval;
  • the sync journal: start and finish times, the number of products and variants processed, the number of records created, updated and skipped, error texts;
  • the webhook journal: delivery identifier, Store domain, event topic, event body, number of processing attempts and the outcome;
  • the data request journal: the fact of receipt and the outcome of customers/data_request, customers/redact and shop/redact requests;
  • technical logs: request time, Store domain, Shopify response code, error class. Tokens and secrets are not written to logs.

4.2. The Operator does not store the Store’s customer data, the Store’s order data, payment data or bank card data.

5. Storage of access tokens

5.1. The access token for the Store’s Admin API is stored encrypted (symmetric Fernet encryption, AES-128-CBC with HMAC-SHA256) under a dedicated key that is kept separately from the database and does not end up in database backups alongside the ciphertext.

5.2. The token is never sent to the browser and is never displayed in the interface, neither in full nor in part. The App page inside the Shopify admin receives only a short-lived Shopify session token, which cannot be used to call the Admin API.

5.3. The token is used exclusively for requests to the GraphQL Admin API of the Store it was issued for, and is not passed to third parties.

5.4. When the App is removed from the Store (the app/uninstalled webhook), the token ciphertext is deleted immediately.

6.1. Store data is processed in order to perform the contract with the User — to provide the catalog synchronisation the User asked for by installing the App.

6.2. The data is not used for advertising, profiling, training machine learning models on Store data, sale or transfer to third parties.

7. Transfer to third parties

7.1. Store data is processed on servers leased by the Operator. The Operator does not transfer Store data to third parties, except in cases directly provided for by the legislation of the Republic of Uzbekistan.

7.2. Product titles and descriptions may be transferred to artificial intelligence model providers to the extent necessary to compose replies to a customer in the EzguSavdo chat channels. Such transfer is governed by the general Privacy Policy and does not include access tokens, data about the Store as a legal entity, or customer data.

8. Retention periods and deletion of data

8.1. Removal of the App from the Store (app/uninstalled): synchronisation stops and the access token is deleted. Products already imported remain in the User’s store inside the EzguSavdo service — the User keeps selling them, and deleting them automatically would be a loss of the User’s data rather than protection of Shopify’s data.

8.2. A request to erase store data (shop/redact, which Shopify sends 48 hours after the App is removed): access tokens, integration settings and the sync journal are deleted; imported products are marked as deleted and excluded from the catalog, from search and from offers. Products are not removed by a physical DELETE operation, because the User’s own order history inside EzguSavdo references them, and removing it would destroy data unrelated to Shopify.

8.3. A customer data request (customers/data_request) and a customer erasure request (customers/redact): the Operator records the request and answers that it holds no data about that customer, because the App requests no access scope for customers or orders (clause 2.4).

8.4. The journal of requests handled under clauses 8.2–8.3 is retained after the data is deleted: it is the evidence that the request was carried out, and it contains the Store domain, the kind of request, the date and the outcome, but not the deleted data itself.

8.5. Webhook journal entries are deleted 30 days after successful processing. Technical logs are kept for no longer than 90 days.

8.6. The User may disconnect the integration at any time on the App page in the Shopify admin or in the EzguSavdo panel, and may request deletion of the imported catalog at the address in section 10. The procedure for deleting data from the EzguSavdo service is described in the Data deletion document.

9. Security

9.1. All connections to Shopify and to the EzguSavdo service are made over HTTPS/TLS.

9.2. Shopify webhooks are accepted only when the HMAC-SHA256 signature computed with the app secret matches; requests with an invalid signature are rejected with code 401.

9.3. The App page in the Shopify admin is authenticated by a Shopify session token: the signature, the validity period, and the fact that the token was issued for this app and for this Store are all verified.

9.4. Access by the Operator’s staff to the data is limited to what their duties require. Administrator actions in the panel are recorded in an audit log.

10. Details and contacts

EZGUPRO LLC Tax ID (INN): 313189635 Registered address: Republic of Uzbekistan, Tashkent, Yakkasaray district, MFY Meros, Bogiboston street, 186/188 Official e-mail: i@ezgupro.uz Support: i@ezgusavdo.uz, Telegram @ezgu_savdo Phone: +998 93 933 90 90 Contacts: ezgusavdo.uz/en/contacts

Send requests about processing and deletion of data to i@ezgupro.uz with the subject “Data deletion” and the myshopify.com domain of your store. The review period is 30 calendar days.

11. Changes to this Policy

11.1. The Operator may change this Policy. The current edition is published on this page, and the edition date is stated at the top of the document.

11.2. Changes that materially expand the list of data processed or of Shopify access scopes requested take effect no earlier than 14 days after publication.