← LPD Product Sync

Privacy policy

Last updated: 10 August 2026

LPD Product Sync processes only the information needed to synchronise LPD catalogue products and send Shopify orders to the LPD Portal for fulfilment.

Information processed

The app stores the Shopify store domain, Shopify authentication sessions, encrypted LPD credentials, product mappings, sync history and order-delivery records. Order records can contain the customer name, delivery address, postcode, telephone number, email address, purchased product codes, quantities and prices.

How information is used

Catalogue information is used to create and update Shopify products. Order information is sent securely to the configured LPD CreateOrder API endpoint so the merchant can fulfil the order. Information is not used for advertising or sold to third parties.

Storage and security

Data is hosted on an AWS server in the United Kingdom. Connections use HTTPS. LPD credentials, LPD access tokens and stored order payloads are encrypted before storage, and access is restricted to the application service and authorised administrators.

Retention and deletion

Order-delivery records containing customer information are automatically deleted after 30 days. Personal-data access audit records and customer data-request records are kept for up to 365 days for security and compliance. Store-specific application data is also deleted when the app is uninstalled and when Shopify sends an applicable customer or shop redaction request.

Processors and data transfers

Trio Media operates the app as a processor on the merchant's instructions. Shopify supplies order information, Amazon Web Services hosts the application in the United Kingdom, Cloudflare provides network security and delivery, and the merchant's configured LPD Portal receives order information for fulfilment. Data is not sent to unrelated recipients.

Merchant agreement and customer rights

By installing and using the app, the merchant instructs Trio Media to process the information described in this policy solely to provide the integration. Merchants can request access, correction or deletion on behalf of a customer using the contact below. Verified Shopify privacy webhooks are used to process applicable access and deletion requests.

Security incidents

Suspected incidents are investigated, contained and documented under the application security incident response process. Affected merchants and other parties are notified where required by applicable law or Shopify's requirements.

Contact

Privacy and data requests can be sent to [email protected].