Privacy policy
KaratSync: Live Gold Prices · Last updated 25 July 2026
Summary
KaratSync updates product prices in a Shopify store from live metal rates. It does not collect, receive, or store personal information about your customers.
What KaratSync stores
- Your store domain and access token, so the app can read products and write prices on your behalf.
- Your app settings: currency, tax rate and label, safety limits, schedule preferences, and plan.
- Your pricing formulas: metal, purity, wastage, making charges, margin, rounding, and which products they target.
- Price change history: for each update: product and variant identifiers, SKU, the old and new price, the metal rate used, and the outcome.
- Metal rate snapshots: gold and silver rates fetched from our rate providers. These are market data and are not specific to any store.
What KaratSync does not store
No customer names, email addresses, shipping addresses, phone numbers, order contents, or payment details. The app does not request access to customer or order data, and its permissions are limited to reading and writing products.
Per-product pricing data
Item weight, purity, stone value, and price locks are stored as metafields on your products inside Shopify, not in our database. They remain in your store if you uninstall the app.
Third parties
Metal rates are retrieved from metals.dev and cross-checked against gold-api.com. These requests ask only for market rates and contain no information about your store, your products, or your customers.
The app runs on Fly.io, which hosts the application and its database. No other parties receive your data.
Data retention and deletion
Uninstalling the app deletes your settings, formulas, update history, and stored session for that store. Shopify’s mandatory compliance webhooks are implemented: on a shop redaction request all remaining data for the store is deleted. Because no customer personal data is held, customer data requests and customer redaction requests are acknowledged and logged with nothing to return or erase.
Security
Traffic is served over HTTPS. Access tokens are stored server-side and are never exposed to the browser. Incoming webhooks are verified against Shopify’s signature before being processed.
Changes
If this policy changes, the date above is updated. Material changes will be communicated to installed merchants.
Contact
Questions about this policy or your data: kash@codejainfotech.com.