Legal
Privacy Policy
Last updated — July 16, 2026
1. What this covers
This policy covers the InfiniteSync app for Shopify and the website at infinitesync.ignitedai.com, an IgnitedAI product operated by InfiniteSync (“we”, “us”). It applies from the moment you install the app or use the site.
The one-paragraph version: we read and write image files in one folder of your Google Drive — the InfiniteSync folder — and the product images and titles in your Shopify catalog that those files map to. We collect what we need to run that sync and nothing more, we sell none of it, and your images stay in your own Drive throughout.
2. What we collect
Collected automatically when you install and use the app:
- Store identity — the store name, .myshopify.com domain, and the contact details Shopify passes with the install.
- Google account identity — the email address and basic profile of the Google account you connect, from the OAuth grant.
- Sync logs and error records — which files were matched, moved, or refused, recorded as opaque IDs and hashes rather than file contents.
- Basic usage — product counts, sync counts, and enough detail about failures to fix them.
Handed over by you, when you choose to: support messages and anything you attach to them. That is the whole list.
3. Your Google Drive data
InfiniteSync asks Google for one Drive permission, and it is the narrow one: drive.file, the non-sensitive scope that only lets an app open files and folders it created itself. When you connect, the app creates the InfiniteSync folder in your Drive — which the scope covers, because the app made it.
Your own uploads become readable to us through one explicit grant: the InfiniteSync folder is shared with our dedicated sync account, the identity our servers use to process what you drop in. The share is visible in Drive's sharing dialog like any collaborator, and you can remove it there at any time, without asking us first.
What we read: image files inside the InfiniteSync folder — their names, their order, and their contents. What we write: product images synced down from Shopify, renames, and moves within that folder. Nothing is read or written anywhere else in your Drive.
What deletion means: when a sync calls for a file to go, it is moved to the InfiniteSync - Deleted folder inside your own Drive, where you can inspect it and pull it back. InfiniteSync never permanently deletes your files.
Nothing outside the InfiniteSync folder is ever accessible to us — not your documents, not your photos, not the rest of your Drive. That boundary is enforced by Google's permission model, not by our promise: access to anything else was never granted. The long version is in the permissions section of How it works and in the FAQ — and all three say the same thing on purpose.
4. Your Shopify data
On the Shopify side, InfiniteSync requests access to your products and their images. We read the product and variant list to resolve SKUs — that is how a filename finds its product — and we write product images and, if you use per-product folders, product titles, because folder renames sync as title changes.
We never write to descriptions, prices, inventory, collections, or orders, and we never read your customers or orders at all.
5. How we use it
Every purpose maps to something you can see. Your store identity runs the install and the billing tier. Your Google identity shows you which account is connected. Your files are synced — that is the product. Sync logs exist so support can answer “what happened to this file” with a real answer, and usage numbers tell us when you are close to a tier limit.
And the negatives, because they are the point: we do not sell your data to anyone. We do not use it for advertising or ad targeting. We do not train anything — AI models or otherwise — on your photos.
6. Google API Services Limited Use
InfiniteSync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Limited Use means in practice here: data received from Google APIs is used only to provide the sync features visible in the app. It is never sold, never used for advertising, and never used to train generalized AI or machine-learning models.
No human at InfiniteSync reads your Drive data except with your explicit, documented consent — a support case you opened and asked us to look at — when it is necessary for security, or where the law requires it.
7. Sub-processors
Your data may be processed by these providers: Cloudflare, Google, and Shopify.
That is the whole list. When it changes, this section changes with it.
8. Retention and deletion
While the app is installed, we keep the records in section 2. Sync logs and error records are retained no longer than we need them for security and debugging, then cleared — we do not hold them beyond that need. The one deletion we commit to on a fixed clock is the Google-credential purge described below.
Disconnecting Google in the app pauses sync and revokes the app's OAuth token. The folder share to the sync account is retained so reconnecting later is easy — the app says so at the moment you disconnect.
Remove all access goes further: it also removes the sync account's permission on the InfiniteSync folder, and we verify the removal actually took effect rather than assuming it did.
Uninstalling the app revokes its access and removes the sync account's share on your InfiniteSync folder, and — as with Remove all access — we verify the removal took effect rather than assuming it did. If Drive refuses every removal route we have (for example the folder's owner has turned off editor re-sharing and our Google authorization is already gone), we flag the share as pending removal so we chase it instead of dropping it, and you can remove it yourself in Drive's sharing dialog at any time. Stored Google credentials are deleted within 30 days of uninstall — or right away if you send a Shopify data-erasure request. Store records follow within 30 days of Shopify's data-removal notice.
Your images are not ours to delete. They are in your Drive, under your account, and they stay there through all of the above.
9. Your rights
You can ask for access to the personal data we hold about you, correction of it, deletion of it, a portable copy of it, or that we stop processing it. Email care@ignitedai.com and we answer within 30 days.
If you are in the EEA or the UK, these are your GDPR rights, and you can also complain to your supervisory authority. If you are in California, the CCPA gives you the same shape of rights — and for its definitions, we do not sell or share your personal information.
10. Security
OAuth tokens are stored server-side only, encrypted at rest, and everything moves over TLS in transit. Tokens never appear in browsers, logs, or source control.
The sync account is a per-environment service identity — staging and production use different ones — and its access is bounded to the folders explicitly shared with it. Before every operation, ancestry checks verify that the file actually descends from your InfiniteSync folder; anything that cannot prove it is refused.
When you remove access, we do not take the removal on faith: a denial probe confirms that our own access now fails before the app reports it removed.
11. Changes to this policy
Changes are posted here, with the date at the top updated. For material changes we give at least 14 days' notice by email or in the app before they take effect. Previous versions are available on request.
12. Contact
InfiniteSync operates the app and this site. For anything in this policy — questions, rights requests, security reports — email care@ignitedai.com. It is read by the people who build the product.