← Back to fairesync.com

Privacy Policy

Last updated: 24 August 2026 · Applies to the Faire Sync application at app.fairesync.com

Faire Sync is an app for OpoShop merchants, published by Found. It connects the store you already run to your own Faire brand account so you can sell wholesale. This page describes exactly what it stores, what it sends to Faire, what it never touches, and how to have your data removed. It describes what the software actually does — nothing here is aspirational.

1. Who we are

Faire Sync is built and operated by Found, an independent studio that builds applications for OpoShop merchants. For anything on this page — a question, a correction, a copy of your data, or a deletion request — write to brandon@tryfound.io. A human reads it.

Faire is a trademark of Faire Wholesale, Inc. Faire Sync is an independent application that connects to Faire through its public API, and is not endorsed or certified by Faire. This policy covers Faire Sync only; what Faire does with data on its own platform is governed by Faire's own privacy policy, and what OpoShop does is governed by OpoShop's.

2. Data from your OpoShop store

When you install Faire Sync, you authorise it through OpoShop's OAuth flow. That grant is what lets the app read your store; it does not give us access to your OpoShop password, and you can revoke it by uninstalling the app.

What we read

What we write back to your store

Faire Sync never writes a price back to your OpoShop storefront, never edits your product content, and never deletes anything in your store.

3. Data you enter in Faire Sync

The wholesale layer is information that does not exist anywhere in an OpoShop catalogue, so you enter it here:

Every money value you enter is stored with who entered it and when. That record exists so a price can be traced back to a person if it is ever disputed, and so the app can refuse to send any figure it cannot attribute to you. It is not used for profiling and is never shared.

4. Data exchanged with Faire

You connect your own Faire brand account to Faire Sync through Faire's OAuth flow. Faire Sync acts on your behalf using that connection and nothing more.

What we send to Faire

Nothing is sent to Faire until you confirm that specific product. There is no bulk publish and no background job that lists something you have not looked at.

What we read from Faire

Retailer email addresses. Faire's order API does not expose an email address for the ordering shop — not on the order, not on the customer, not on the address. Faire Sync therefore never receives one and never stores one. The customer record it creates in your OpoShop store uses a placeholder address on the reserved .invalid domain, which cannot receive mail, purely so the order has something to group on. It is not a real address and must not be emailed.

5. Payment and card data

Faire Sync never sees, receives, stores or transmits card numbers, bank details or any other payment credential. Retailers pay Faire; Faire pays you. Money never moves through this app. The only financial figures it holds are the wholesale terms you typed and the commission and payout amounts Faire reports back on your own orders.

6. Where your data lives, and how it is separated

Faire Sync stores data in its own MongoDB database, used by this application and no other. Every record — listings, wholesale terms, orders, settings, credentials — is scoped to a single store, and every request is resolved to the store it belongs to before any data is read.

If you own more than one OpoShop store, each store gets its own separate account inside Faire Sync. Data is never shared between them, even when the same person owns both.

Credentials are encrypted at rest. Your Faire access token is stored using authenticated AES-256-GCM encryption and is decrypted only in memory, at the moment a request to Faire is made. It is never written to logs, never returned to the browser, and never sent anywhere except Faire.

7. Analytics

Faire Sync records product analytics through PostHog so we can see which features are used and where they fail. These events are identified by your store id only — for example store_1234. No name, no email address, no customer data, no product data and no price is attached to an analytics event.

There is no advertising network on the application, no cross-site tracking and no third-party marketing pixel.

8. Who else touches your data

ServiceWhat it doesWhat it receives
OpoShop The platform your store runs on The API calls Faire Sync makes on your behalf
Faire The wholesale marketplace you are selling on Listings, prices, stock and tracking you publish
MongoDB Atlas Hosted database Everything described in sections 2–4, at rest
Fly.io Application hosting Requests in transit, plus operational logs
PostHog Product analytics Event names and your store id only

We do not sell your data. We do not rent, trade or share it with data brokers, advertisers or list buyers, and we do not use it to train models. The services above are infrastructure we use to run the app for you — not audiences we hand your business to.

9. Logs

The application writes operational logs so failures can be diagnosed: timestamps, request paths, store ids, error messages and the outcome of calls to Faire and OpoShop. Access tokens, refresh tokens and secrets are never logged. Logs are retained by our hosting provider on a rolling basis and are used for debugging and security, nothing else.

10. How long we keep things

Deleting your data here does not remove listings already published on Faire or orders already created in your OpoShop store — those live on their own platforms and are yours to manage there.

11. Disconnecting Faire

You can disconnect your Faire account from inside the app at any time. Doing so deletes the stored access token and stops every further call to Faire. Listings already published stay live on Faire until you change them there.

12. Your rights

Depending on where you live, you may have the right to access the personal data we hold, to have it corrected, to have it deleted, to restrict or object to how it is processed, and to receive a copy in a portable format. Exercise any of these by emailing brandon@tryfound.io. We will not charge you for it and we will not ask why.

We process this data because it is necessary to provide the service you installed. If you are in the EEA or UK and are not satisfied with how we have handled a request, you may complain to your local supervisory authority.

13. Children

Faire Sync is a business tool for merchants. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

14. Security

Traffic to and from the application is served over HTTPS. Credentials are encrypted at rest, sessions are signed and scoped to a single store, and every API request is checked against the store it claims to belong to before any data is returned. No system is perfect; if you find a security issue, please report it to brandon@tryfound.io and we will treat it as urgent.

15. Changes to this policy

If this policy changes in a way that affects what we collect or who receives it, we will update the date at the top of this page and, where the change is material, notify merchants inside the app. Continued use after a change means the updated policy applies.

16. Contact

Found — brandon@tryfound.io
Faire Sync · fairesync.com