Privacy Policy

Last updated: September 11, 2026

Gelato Sync ("Gelato Sync", "we", "us") is a print-on-demand connector for merchants who run stores on the OpoShop platform. It helps you put your artwork on Gelato blanks and import them into your store, and connects your store to YOUR OWN Gelato account so new orders can be placed, tracked, and marked shipped automatically. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Gelato Sync admin application and its background fulfillment engine.

The short version. Gelato Sync reads your store's orders so it can fulfill them through Gelato, and writes tracking numbers back. We never collect or store payment-card numbers. We never sell your data or your customers' data. You stay in control of what spends money: Gelato Sync does not place a real Gelato order unless you explicitly turn live ordering on. Until you do, every order is created on Gelato as a draft: visible in your own Gelato dashboard, never charged, never printed.

1. Information we collect

Store and account data

When Gelato Sync is installed on your store, we receive your store identifier, subdomain, store name, and owner email from the OpoShop platform, plus an access token used to read orders and push tracking back on your behalf. We create an account record so you can sign in to the Gelato Sync dashboard.

Order and fulfillment data

Gelato connection

You connect your own Gelato account in Setup. We store the Gelato API key you provide, encrypted at rest, so we can place and track orders on your behalf. It is stored server-side, is never shown back in the interface once saved, and is never written to a log. Your Gelato payment method is charged only once you have explicitly turned live ordering on in Settings; until then Gelato Sync creates every order as a Gelato draft, which is never charged and never printed. When you uninstall the app we delete the stored Gelato key.

Payment card data

We do not collect or store payment-card numbers, bank details, or passwords. Customer payments are processed by OpoShop and its payment providers; supplier payments are handled by Gelato through your own Gelato account. Gelato Sync never touches raw card data and never handles your customers’ payments.

Product analytics

We use privacy-respecting product analytics to understand feature usage and fix problems. We do not sell personal data and we configure analytics to avoid collecting unnecessary personal information.

2. How we use information

3. Sharing

We share data only with: (a) the OpoShop platform your store runs on, as needed to operate the app; (b) Gelato, to place and track the supplier orders you choose to fulfill (including the shipping details required to deliver the order); (c) infrastructure providers that host Gelato Sync under confidentiality obligations; and (d) authorities where required by law. We do not sell your data or your customers' data.

4. Data retention and deletion

We keep order, mapping, and fulfillment data for as long as Gelato Sync is installed on your store, so your fulfillment history stays accurate.

When you uninstall Gelato Sync, we immediately and permanently delete your stored Gelato API key and stop reading your store's orders. We deliberately keep your product mappings and fulfillment history, so that reinstalling restores your catalogue and your order history rather than starting you from nothing — and so an order that is still in production at Gelato still has a record to reconcile against. To have that history deleted too, email us and we will remove it.

5. Security

Data is transmitted over TLS and access tokens and supplier credentials are stored server-side. Every request is scoped to the authenticated store, and payment actions are gated so a supplier order can never be charged without your explicit configuration.

6. Children

Gelato Sync is a business tool and is not directed to children under 13.

7. Changes

We may update this policy; we will revise the "Last updated" date above when we do.

8. Contact

Questions about this policy or a data request? Email brandon@tryfound.io.