Privacy Policy — ClickUp Sync
Last updated: September 2026
ClickUp Sync ("the App") is operated by Corventia ("we", "us").
The App connects a Shopify store with a ClickUp workspace to create and update
tasks from orders. This policy describes what data the App processes and why.
What data we process
- Order data: order number, line items, totals, order status,
sales channel, customer name (for guest checkouts, the name on the shipping or
billing address) and shipping address — received from Shopify via webhooks and
used solely to create and update the corresponding task in the ClickUp list you
choose.
- Store data: your store domain and the App configuration
(chosen list, filters, sync rules).
- ClickUp credentials: the OAuth access token you authorize,
stored encrypted (AES-256-GCM) and used only to act on the list you selected.
We do not process customer emails, phone numbers or payment
details. We do not sell data, and we do not share it with third parties beyond
the transfer to ClickUp that the App exists to perform.
Where data goes
Order details are sent to ClickUp (clickup.com) to create tasks
in the workspace you connected. ClickUp's own privacy policy applies to data
stored there.
Retention and deletion
- The order snapshot received from Shopify (used for retries and manual
re-sync) is kept for at most 30 days and then purged automatically.
- Sync metadata (order-to-task links, and sync logs with the order number and
customer name) is retained while the App is installed.
- On uninstall, the ClickUp access token is deleted from our systems immediately
(you can also revoke the App's authorization in ClickUp's settings), and the
remaining store data is deleted in line with Shopify's mandatory data-erasure
webhooks (
shop/redact, 48 hours after uninstall).
- Customer-level redaction requests (
customers/redact) remove all
traces of the affected orders from our systems.
- Data-access requests (
customers/data_request) are honored within
30 days via the contact below.
Security
Data is transmitted over TLS. Third-party tokens are encrypted at rest. Encrypted
database backups rotate every 7 days, so deleted data leaves the backups within a
week. Access to production systems is restricted to the operator.
Contact
Questions or requests: support@corventia.com