VGC Order Sync — Privacy Policy
Effective 4 October 2026
VGC Order Sync is a Shopify app that connects a merchant's Shopify store to the merchant's own VGC account at viewmoney.us. It is provided by Apex Meridian Group LLC, which operates VGC (see Company & Legal Notice). This policy explains what the app accesses, what it keeps, and for how long. It applies in addition to the general VGC Privacy Policy.
What the app does
- Shows the store's orders in the merchant's VGC dashboard as they are placed and updated.
- Lets the merchant add a tracking number to an order from VGC; the tracking is written to the order in Shopify and Shopify sends its own shipping notification to the customer.
- Counts storefront visits, add-to-carts and checkouts so the merchant can see today's traffic.
Information the app accesses
- Orders (Shopify Admin API, read only): order number, date, status, items, totals, fulfilment and tracking, and the customer details that are part of an order (name, email, phone, shipping and billing address). Used only to display the order to the merchant and to add tracking.
- Fulfilment orders: to attach a tracking number when the merchant asks.
- Storefront events (Shopify web pixel), only for visitors whose consent covers analytics:
the event type (page viewed, product viewed, product added to cart, checkout started, checkout completed), the page
path without its query string (pages whose path identifies one shopper — checkout, order status, account,
cart links — are stored under a generic name such as
/checkout), the time, Shopify's anonymous browser identifier, the visitor's country (looked up on VGC's server from the address the event arrives from, using DB-IP's IP-to-country database; the address itself is not stored), the browser family (for example "Chrome / Windows" — never the full user agent), and on the first page of a visit the host name of the referring site and the landing URL'sutm_source,utm_mediumandutm_campaignand which advertising click identifier it carried (the identifier's value is not collected). For a product viewed: its SKU, title and price (the store's own catalogue data). For a completed checkout: the order total and the order's id, so the merchant can see which traffic source an order came from. The pixel never collects names, email addresses, postal addresses, payment details or cart contents.
What is stored, and for how long
- Orders are read from Shopify when the merchant views them; they are not copied into VGC's database. To spare Shopify repeated requests, an answer may be held in a server-side cache for up to 15 seconds; cached answers are deleted within an hour.
- When an order is placed or paid, VGC keeps a short notification record (order number, status, total and the customer's name) so the merchant is notified once. The customer's name is removed from it after 90 days.
- Storefront events are stored with the anonymous identifier replaced by a one-way hash (salted per store, so a visitor cannot be followed across stores), and are deleted after 90 days.
- When a tracking or order email is sent through VGC (by the merchant, or automatically once the merchant has set up a mailbox for the store in VGC), the recipient's address and the message are kept as a delivery record for the merchant, until the merchant deletes it or the customer's data is redacted (below).
- The store's Shopify access token is stored encrypted and deleted as soon as the app is uninstalled.
Sharing
Data is used only to provide these features to the merchant who installed the app. It is not sold, not used for advertising, and not shared with third parties other than the hosting provider that runs VGC.
Customer and shop data requests
- Access requests sent by Shopify are recorded and the merchant is given what VGC holds about that customer within 30 days.
- Deletion requests sent by Shopify remove the customer's email address and message text from the merchant's delivery records and their name from order notifications.
- Shop deletion: 48 hours after the app is uninstalled, Shopify asks for the shop's data to be erased; VGC removes the shop's customer addresses, storefront events, tokens and installation record.
Security
All traffic uses TLS. Access tokens and app secrets are encrypted at rest, and so are the customer details VGC keeps: the address and text of emails sent for an order, the customer's name in an order notification and cached order lists are stored encrypted (AES-256) and decrypted only when shown to the merchant, so database backups hold them only in encrypted form. Access to VGC requires an account, with optional two-factor authentication; each account sees only its own stores; and sensitive actions are written to an audit log. Suspected incidents are handled under VGC's Security Policy: contained, investigated, and reported to the affected merchants and to Shopify without undue delay.
Contact
Questions or requests about this policy: App@imc-marketing.com. See also Support.