Privacy Policy for Sagify (Sage Business Cloud Accounting)
ezApps Software Inc.
Effective Date: July 21, 2026
ezApps Software Inc. ("ezApps," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use Sagify for Sage Business Cloud Accounting (the "Service"), our Shopify app that syncs your store into Sage Business Cloud Accounting.
This Policy applies solely to the B2B use of the Service and should be read in conjunction with our Terms of Service. It is specific to the Sage Business Cloud Accounting app; our Sage 50 desktop products are covered by their own policies.
1. Scope of This Policy
Sagify is a business automation service for merchants. When you connect your Shopify store and your Sage Business Cloud Accounting account, the Service reads commercial data from Shopify and writes the corresponding accounting records into your own Sage account: orders become sales invoices, refunds and cancellations become credit notes, Shopify payouts become bank receipts, and products become Sage items.
Important:
Sagify does not store your customers' personal information. Customer names, email addresses, and shipping or billing addresses are read from Shopify and written directly into your Sage account in real time — they are not retained in our database.
Sagify is a hosted service, so it does keep a small operational record for each store — connection credentials and per-document sync status — as described in Section 2. This is what makes the Service resumable, idempotent, and safe to retry.
2. Information We Collect
Merchant & Account Data
- Your Shopify store domain (e.g.
your-store.myshopify.com) - Shopify session records for staff who open the app, which may include a staff name, email address, and locale supplied by Shopify
- Your store's contact email address, used for onboarding and essential service notifications
- An optional notification email address you configure in Settings
- Shopify and Sage access credentials, stored encrypted (see Section 5)
- The name, country, and currency of the Sage business you connect
Configuration Data
- Your app settings — sync mode, tax and ledger defaults, bank account selections, and notification preferences
- Mappings between your Shopify product variants and your Sage items, including any per-product overrides you set
Sync Records
For each document the Service processes, we store a status row so that work is never duplicated, can be resumed after an interruption, and can be audited or undone:
- Shopify identifiers (order, refund, payout, and product IDs) and the order's display name (e.g. "#1001")
- Sage identifiers for the documents we created (invoice, credit note, receipt, and contact IDs and numbers)
- Sync status, attempt counts, timestamps, and any error message returned by Shopify or Sage
- Product titles and variant counts, for display in the app
Billing & Usage Data
- Your subscription plan, billing period, and trial status
- Counts of documents synced during each billing cycle, used to calculate charges
Operational Telemetry
- Aggregate, non-financial events such as "an order posted," "an order was parked for review," or "a Sage connection expired," keyed by store domain and used to monitor reliability and improve the product
We Do Not Store:
- Customer names
- Customer email addresses
- Customer shipping or billing addresses
- Payment card numbers or any payment instrument details
- Order line items, quantities, or order totals
- Invoice or credit note documents
- Customer tax IDs
Where this information is required to create an accounting record, it is read from Shopify, transmitted to your Sage account, and discarded. It is not written to our database.
3. How We Use Information
We use the information described above strictly to:
- Provide the Service — authenticate with Shopify and Sage, and create the accounting records you have asked us to create
- Guarantee correctness — prevent duplicate invoices, resume interrupted work, and let you review or undo a sync
- Surface problems to you — flag orders that need your attention and, if you opt in, email you about sync issues or a disconnected Sage account
- Measure usage for billing
- Monitor system performance, detect security abuse, and improve product stability
- Send onboarding and essential account emails
We never sell, trade, rent, or monetize your data or your customers' data, and we do not use it to train machine-learning models.
4. Roles & Legal Basis for Processing
With respect to your store's data, you are the data controller and ezApps acts as a data processor, processing data only on your documented instructions — which you give by configuring and using the Service.
We process this data under the following legal bases:
- Performance of a contract (providing the Service to you)
- Legitimate business interests (billing, security, and system integrity)
Sagify is a commercial B2B system and is not intended for consumer personal use.
5. Data Security
We implement commercially reasonable security measures including:
- Encryption of Sage OAuth tokens at rest using AES-256-GCM
- Short-lived access tokens with refresh tokens that rotate on every use
- Encrypted connections (HTTPS / TLS) for all traffic
- Cryptographic (HMAC) verification of every inbound Shopify webhook
- Role-restricted internal access
- Infrastructure-level firewall protections
However, no system can be guaranteed 100% secure, and you acknowledge and accept this risk.
6. Data Storage & Retention
- Data is stored on protected servers operated by our hosting provider, located in Canada.
- Sync records are retained for the life of your account so that historical syncs remain auditable and reversible.
- Billing and usage records are retained as required for billing verification, regulatory defense, and dispute resolution.
- When you uninstall the app, your Shopify session and your Sage connection credentials are deleted immediately, and the app stops receiving data from your store.
- Approximately 48 hours after uninstall, Shopify sends a shop redaction request and we erase all remaining data associated with your store.
Deleting our records does not delete the invoices, credit notes, or receipts already created in your Sage account. Those are your accounting records and remain under your control.
7. Third-Party Platforms & Sub-Processors
The Service operates by connecting to:
- Shopify — source of your order, product, payout, and customer data
- Sage Business Cloud Accounting — destination for the accounting records we create on your behalf
We also rely on the following sub-processors to operate the Service:
- Fly.io — application hosting and database storage (Canada)
- Resend — delivery of onboarding and transactional emails to you, the merchant
Your customer, order, and invoice data remains within Shopify, Sage, and your own systems. ezApps does not control, store, or access those third-party systems beyond the access you authorize, and we do not share your data with advertisers or data brokers.
8. Permissions We Request
Shopify requires apps to request explicit permission for the data they access. Sagify requests access to orders (including historical orders), customers, products, inventory, locations, and Shopify Payments payout data — each of which is necessary to produce accurate accounting records. We request no permission we do not use.
9. Your Customers' Rights
We support Shopify's mandatory privacy webhooks. If one of your customers exercises a data right through your store:
- Data request — we confirm that we hold no personal information about that customer.
- Redaction request — there is no customer personal information in our database to erase. Any Sage invoice or credit note referencing that customer is a financial record you are legally required to retain, and is not deleted by us.
- Shop redaction — all data for your store is erased, as described in Section 6.
10. Your Rights
As a Sagify customer, you have the right to:
- Request access to the data we hold about your account
- Request correction of account-related records
- Request deletion of your account and its data upon termination
- Disconnect your Sage account at any time from within the app
Requests may be submitted to: support@ezapps.io
11. Children's Privacy
Sagify is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
12. International Data Transfers
Your data is processed in Canada and may be processed in other jurisdictions where our infrastructure providers operate. Where data is transferred out of the EEA or the UK, we rely on appropriate safeguards, including Standard Contractual Clauses. All data is protected using commercially reasonable safeguards.
13. Data Breach Procedures
In the event of a confirmed security breach affecting your data:
- We will investigate immediately
- We will notify affected customers without unreasonable delay, and regulators where required by law
- We will take immediate steps to mitigate further exposure
Because Sagify does not store your customers' personal information, order contents, or payment details, breach exposure is limited to connection credentials, configuration, and sync status records.
14. Policy Updates
We may update this Privacy Policy from time to time.
- Material changes will be communicated via email or on our website
- Continued use of the Service after the effective date constitutes acceptance
15. Contact Information
For all privacy-related questions or requests:
ezApps Software Inc.
support@ezapps.io