PrimarySafe privacy policy

Last updated: 14 September 2026

This policy is for merchants who install PrimarySafe on their Shopify stores. It is the copy served at https://primarysafe.fly.dev/privacy for Shopify App Store listing.

Who we are

PrimarySafe is a multi-store inventory quantity sync app. One shop is the Main store (source of truth for quantity). Linked stores follow that Main store. Connecting or removing PrimarySafe cannot wipe, zero, archive, or delete Main-store stock.

What we process (minimum for quantity sync)

PrimarySafe processes only what is required to match SKUs and write Linked-store available quantities:

  • Shop domain and install/session tokens
  • Product variant identifiers, SKUs, barcodes, inventory item IDs, location IDs, and available quantities
  • Connection settings (location pair, buffer, Auto vs Manual)
  • Dry-run confirm tokens and per-SKU apply job state
  • Thin activity / sync history (quantity old→new, reason, actor)

We do not use the app to market to customers, build advertising profiles, or sell personal information.

Order and refund signals

After Protected Customer Data access is approved, PrimarySafe may receive orders/create and refunds/create webhooks so automatic updates can re-read live inventory and write the Linked store toward the Main store.

Those webhooks are used as line-item / inventory signals only. PrimarySafe does not store customer names, emails, addresses, phone numbers, payment details, or full order payloads. Automatic updates re-read Admin inventory quantities; they do not persist customer records.

What we do not do

  • We do not sell, rent, or share customer personal information with advertisers or data brokers.
  • We do not send marketing email or SMS to a merchant’s customers.
  • We do not wipe, zero, archive, or delete inventory or products on uninstall, disconnect, or GDPR redact.
  • Inventory writes from PrimarySafe target Linked stores only. Main-store quantity is whatever Shopify’s own order/refund flow left it. We do not invent stock on the Main store after a Linked-store sale.

Billing data

If you subscribe, Shopify Billing records the charge on the Main store only. Linked-store installs do not open a second bill. PrimarySafe stores plan status (active / trial / none) for that Main store so Settings can show it. We do not store card numbers.

Retention

Activity / sync history is kept for 90 days, then pruned when the history page loads and on uninstall. Connection mappings and shop records remain while the app is installed so quantity sync can resume.

GDPR and uninstall (app database only)

Shopify mandatory webhooks:

  • customers/data_request
  • customers/redact
  • shop/redact
  • app/uninstalled

Those handlers mutate PrimarySafe’s database only. They never receive an Admin API client and never call inventory or catalog mutations. Uninstall does not wipe Main (or Linked) stock.

A customer data request note states that PrimarySafe stores shop domains, SKU mappings, dry-run tokens, and quantity audit logs — not customer personal information.

Merchant control

Merchants can disconnect a store, switch Main store (explicit, with a fresh preview), pause automatic updates, or uninstall the app. Uninstall and redact do not delete products to “fix” sync.

Contact

Contact PrimarySafe through the app’s Shopify listing support. That is the support channel for privacy and product questions. Do not include your customers’ personal information in that message unless Shopify support asks for it to complete a legal request.

The merchant who installed PrimarySafe remains the controller of their Shopify store data.