Privacy Policy
EmailOctopus Sync for Shopify · Last updated 15 July 2026
This app ("EmailOctopus Sync for Shopify", the "App") is operated by Tarka Digital Ltd
("we", "us"). It synchronises a Shopify merchant's consented customers into that merchant's
own EmailOctopus account. This policy explains what the
App accesses, why, and how it is handled. The App is a data processor acting on the merchant's
instructions; the merchant is the data controller for their customers' data.
Information the App accesses
- Customer contact data — name and email address of the merchant's customers.
- Marketing consent status — used so that only customers who have
opted in to marketing are ever synced.
- Order-related data — order count, total spent, last product purchased,
last order date, and abandoned-checkout URL, used to enrich contacts and power automations.
- Store information — the shop domain and the merchant's own EmailOctopus
API key, stored so the App can operate the sync on the merchant's behalf.
How the information is used
- To add and update consented customers as contacts in the merchant's EmailOctopus list.
- To tag and enrich those contacts (e.g. order count, total spent) for the merchant's
segmentation and automations.
- To trigger the merchant's chosen EmailOctopus automations (e.g. abandoned-cart recovery).
We do not sell customer data, use it for advertising, or use it for any purpose other than
providing the sync described above.
Consent
The App only syncs customers who have marketing consent in Shopify. Customers without consent
are skipped and never sent to EmailOctopus.
Sharing & sub-processors
- EmailOctopus — data is sent to the merchant's own EmailOctopus account at
the merchant's direction. See EmailOctopus's own privacy policy for how they handle it.
- Hosting — the App runs on a secured private server operated by us. Data is
transmitted over encrypted (HTTPS) connections.
Data storage, security & retention
- The merchant's EmailOctopus API key and minimal operational data are stored securely and
transmitted only over HTTPS.
- When the merchant uninstalls the App, the stored EmailOctopus API key is immediately
removed.
- We honour Shopify's mandatory data-protection webhooks:
customers/redact
(delete a customer's data on request), shop/redact (erase all of a shop's data
~48 hours after uninstall), and customers/data_request (provide stored data on
request).
Your rights
Merchants and their customers may request access to, or deletion of, stored personal data at
any time. Requests submitted through Shopify are handled automatically via the webhooks above;
you can also contact us directly.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last
updated" date above.
Contact
Questions about this policy or your data: support@tarkadigital.com
(Tarka Digital Ltd).