1. Operator and scope
This policy explains how Bidson CRM Sync handles personal data. The operator's legal name, organization number, physical address and VAT number (if applicable) must be inserted before the Service is offered to external merchants. Until then, this page is a pre-launch disclosure and not a complete statutory business notice.
The operator is generally an independent controller for merchant contact, account, billing, support and website data. For Shopify customer data synchronized on a merchant's instructions, the merchant is the controller and the operator is its processor.
2. Personal data handled
The Service does not intentionally persist complete raw Shopify customer, order or webhook payloads. Attio access and refresh tokens are encrypted before storage. Shopify credentials are retained only as required to operate the installed app.
- Merchant and administrator data, including shop domain, Shopify session details, staff name and email where supplied by Shopify, billing state, Attio workspace configuration and support correspondence.
- Shopify customer data processed for synchronization, including name, email address, phone number, tags, marketing-consent status, Shopify identifiers and aggregated order count, spend, currency and latest-order information.
- Technical data, including linkage identifiers, job state, timestamps, error categories, opaque support IDs and security events. Logs are designed to exclude access tokens and customer payloads.
- A strictly necessary language-preference cookie named attio_commerce_sync_locale, retained for up to one year.
3. Sources, purposes and legal bases
Data comes from the merchant, Shopify, the merchant-selected Attio workspace and normal use of the Service. It is used to authenticate installations, provide and secure synchronization, administer plans, diagnose failures, answer support requests, meet legal obligations and improve service reliability.
For data controlled by the operator, processing is based as applicable on performance of the merchant agreement, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent where the law requires it. Customer data is processed only on the merchant's documented instructions under the data processing agreement. The merchant remains responsible for its own legal basis and privacy notices.
5. International transfers
Production workloads are configured for a European Railway deployment region, but Railway states that its primary processing operations take place in the United States and that authorized subprocessors may operate in other countries. Railway's DPA provides transfer mechanisms including the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
The merchant controls the Shopify and Attio accounts and should assess the locations and transfer mechanisms applicable under its own agreements. Use of an EU hosting region does not mean that every processing operation or support access remains in the EEA.
6. Retention and deletion
- Completed import and webhook job history is normally deleted after 90 days.
- Fulfilled privacy-request metadata is normally deleted after 30 days.
- Active credentials, configuration and customer-to-Attio linkages are retained while needed to provide the installed Service.
- Failed jobs are currently retained until retried, resolved or otherwise handled. A fixed maximum period must be implemented before broad commercial launch.
- Uninstallation and verified privacy requests trigger application-level deletion or redaction, subject to legal obligations, security needs and technically necessary backup cycles.
7. Security
The Service uses data minimization, encrypted Attio tokens, encrypted transport, restricted technical logging, idempotent processing and provider security controls. No system can guarantee absolute security. Additional organizational controls required for broad commercial launch are tracked in the project readiness checklist.
The Service does not sell customer data or use it for advertising or training AI models. It does not make decisions producing legal or similarly significant effects about individuals.
8. Individual rights and complaints
A Shopify customer should normally contact the merchant that controls the data. The operator assists merchants with access, deletion and redaction requests through Shopify's mandatory privacy workflows. Merchant users may contact support about operator-controlled personal data and, where applicable, request access, correction, deletion, restriction, portability or objection.
Individuals may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority. Rights can be limited by applicable law and the operator may need to verify identity before acting.
10. Contact and changes
Questions and privacy requests can be sent to the support address below. A dedicated privacy/security contact and the operator's complete statutory identity must be published before external production use. Material changes will be reflected on this page with an updated date.