Legal
Privacy Policy
Last updated: August 29, 2026
Lucas Ferry Enterprises LLC (“Syfted,” “we,” “us,” or “our”) operates the Syfted website at shopsyfted.com and the Syfted mobile application (collectively, the “Platform”). This Privacy Policy explains what personal information we collect, how we use and share it, and your rights with respect to it.
By using the Platform, you agree to the collection and use of information as described in this Privacy Policy. This Policy is incorporated into and subject to our Terms of Service.
1. Information We Collect
Account and Profile Information
When you create an account, we collect your email address and, optionally, your name, username, phone number, and profile photo. During onboarding, we ask about your style preferences, preferred sizes, and shopping preferences — this information is used to personalize your experience and is stored in your profile.
Third-Party Authentication
If you sign in using a third-party provider such as Sign in with Apple, we receive limited profile information from that provider, which may include a name and an email address (which may be an Apple relay address if you choose to hide your real email). We do not receive your password from any third-party provider.
Purchase and Transaction Data
When you make a purchase, we collect details about the items ordered (including brand, product name, size, quantity, and price), your shipping address, and order status. Where your order ships internationally, the destination country is also used to calculate import duties and to prepare customs documentation, and is shared with the carrier and the relevant customs authority for that purpose. It is also used to determine which currency prices are displayed to you in. Payment details — including your card number, expiration, and CVV — are processed directly by Shopify, which operates the checkout your order goes through, and are never stored on Syfted’s servers. We receive a payment confirmation and a reference for the order (an identifier for the payment, not any card data) so the payment can be reconciled, refunded, and audited. That reference is also shown to the brand fulfilling your items, through their Syfted Brand Portal, so they can confirm the order was genuinely paid for.
So that a rewards discount can be applied to your order and your purchases can be recognised across visits, we store a customer identifier issued by Shopify linked to your Syfted account. That identifier contains no payment card data; all sensitive payment information remains within Shopify’s systems under their privacy policy. Syfted no longer creates or holds a Stripe customer record for buyers; Stripe is used only to pay brands and to bill brand subscriptions.
For each order we also record the commission and shipping amount attributable to each brand in the order. This is internal accounting data about the transaction, not about you, and is retained with the order record.
Syfted Points and Rewards Data
If you participate in the Syfted Points program, we maintain a ledger of your points activity. This includes points earned on each order, the order they relate to, the date they become redeemable and the date they expire, any promotional or early-adopter bonus issued to you, points held during a checkout, points redeemed and the discount applied, and any reversal following a refund. We use this data to calculate your balance, apply discounts at checkout, prevent abuse of the program, and meet our accounting obligations for outstanding rewards liability. It is retained alongside your order history.
Browsing and Activity Data
We collect information about how you interact with the Platform, including:
- Products you view (recently viewed history)
- Product view events, recorded whether or not you are signed in, so that brands can see how many people looked at each of their products. Each event records the product, the time, and whether you were on the website or the mobile app. It is tagged with a random identifier that your browser or the app generates for itself and discards when you close the tab or the app — we do not store your IP address for this purpose and we do not build a device fingerprint. If you are signed in, the event is also linked to your account. Brands only ever see totals and visitor counts, never who you are.
- Products you like or save to your wishlist
- Brands you follow
- Drops you subscribe to receive notifications for, together with which channels you chose (for example email) and the date and time you chose them. We keep the timestamp as a record of your consent to be contacted about that drop. Cancelling the subscription deletes the record.
- Cart contents (stored server-side when you are signed in, to support abandoned cart reminders)
- Search queries and filters used on the Platform
Device and Technical Information
We and our service providers may collect technical information including your device type, operating system, IP address, browser type, and general location derived from IP address. On mobile, we collect your push notification token (with your permission) to send push notifications about orders and drops.
Communications
If you contact us by email or through the Platform, we retain the contents of those communications and your contact information in order to respond.
User-Generated Content
Any reviews, ratings, or other content you submit on the Platform is collected and stored by Syfted and may be displayed publicly.
In-App Notifications
We maintain records of in-app notifications sent to your account (such as order status updates and brand account notices) to support the notification inbox feature. These records are operational and are not used for marketing purposes.
Account Status and Enforcement Records
We keep records relating to the standing of your account, including whether an account has been suspended or restricted and the period any such restriction applies for. These records are used to enforce our Terms of Service and to protect the Platform and its users, and are not used for marketing purposes.
Brand Applicant Information
Submitting a brand application requires a Syfted account, and your application is linked to that account from the moment you submit it. We collect the information you provide, including your brand name, Instagram handle, owner name, business email address, phone number, your storefront’s public website address (if provided), the name and domain of your connected store, store verification status, the date and time you accepted our terms, and any other details you submit. This information is used solely to evaluate your application, communicate with you about its status, and, if approved, to set up your brand account — using the account you already signed in with, with no separate account-setup email required. If you connect your Shopify or Square store as the last step of applying, that connection grants Syfted the same real, functional access a fully connected brand would have, so that we can confirm you control the store and review basic details like your store name, plan, and product count. That access credential is held with your pending application record — on our servers only, never passed through or exposed to your browser — while your application is reviewed. If your application is approved, this same connection automatically becomes your brand’s active store integration (see “Brand Account and Integration Information” below) with no second connection step required. If your application is rejected, or if you connect a store but never finish submitting your application, the stored credential is deleted and never used. Brand application data is subject to this Privacy Policy regardless of whether your application is approved.
Brand Account and Integration Information
Once your Shopify or Square store is connected — whether that happened as the last step of applying and carried forward automatically on approval, or you connect it later through the Brand Portal — we collect and store your store’s API access credentials (access tokens) to enable ongoing product catalog synchronization and to adjust your stock when an item sells on Syfted. These credentials are stored securely and are used solely to operate the integration on your behalf. You may disconnect your store at any time through the Brand Portal, at which point your stored credentials will be removed.
To make your products purchasable through Syfted’s checkout, we reproduce your product listings — titles, descriptions, images, prices, sizes, and stock levels — within Syfted’s own commerce infrastructure, which is operated for Syfted by a third-party commerce platform (currently Shopify) under Syfted’s account, and keep those copies in sync with your store. That platform processes this information as a service provider to Syfted and not for its own purposes. We ask for your permission for this separately during onboarding, and record the date you gave it. You can withdraw it at any time by unpublishing your brand or disconnecting your store.
We record the date on which you accepted the terms presented to you during onboarding, so that we have a record of what you agreed to and when. Where you accepted terms that have since been retired, that acceptance date is retained as a historical record and is not used for any other purpose.
If you hold a brand account we also store information about your seller subscription: your subscription status, the dates your free trial and any grace period end, your next billing date, and the Stripe customer and subscription identifiers for your brand’s billing. Card details for the subscription are handled directly by Stripe and are never stored by Syfted. This data is used to bill you, to determine whether your storefront is visible to buyers, and to send the billing notices described in our Terms of Service.
Communication Preferences
We store your email communication preferences, including whether you have opted out of non-transactional marketing emails. This preference is applied across all marketing email flows. Transactional emails (such as order confirmations and shipping updates) are not affected by this preference and are always sent as part of account operations.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate your identity
- Process your orders, take payment, and pass your order to the brand fulfilling it
- Calculate and collect sales tax where we are required to do so as a marketplace facilitator and where tax calculation is supported for your checkout method — see Section 5 of our Terms of Service for current scope
- Personalize your shopping feed based on style preferences and past activity
- Send transactional emails (order confirmations, shipping updates, account notices)
- Send marketing and activity-based emails (abandoned cart reminders, browse activity reminders, drop alerts for brands you follow, price-drop alerts and new-product notifications from brands you follow, re-engagement emails, and welcome series) — you may opt out at any time
- Send brand account emails to brand owners (application decisions, new order alerts, and a weekly sales digest) — some of these are transactional and cannot be opted out of
- Send push notifications for orders and drops you have subscribed to (with your permission)
- Send SMS notifications to brand account holders who provide a phone number, for operational communications such as new order alerts and application status updates
- Detect and prevent fraud, abuse, and violations of our Terms of Service
- Operate, maintain, and improve the Platform
- Comply with applicable law and respond to legal requests
- Enforce our Terms of Service and other legal rights
3. How We Share Your Information
Syfted does not sell your personal information. We share your information only in the following circumstances:
With Brands You Purchase From
When you place an order, we share your shipping name, address, email address, and order details with the brand(s) fulfilling your items so they can ship your order and contact you if something goes wrong with it. We never share your payment details — no card number, expiration, CVV, or billing information is ever passed to a brand. We do attach the payment reference for the order, which identifies the payment without revealing anything about the payment method or the payer.
Those details reach a brand in two ways. Every brand sees them in their Syfted Brand Portal and in the order notification we email them. In addition, where a brand has connected a Shopify store, Syfted writes that order into it so the brand can fulfil from its normal workflow — carrying your name, shipping address, and email address, and no payment data. Shopify then creates a customer record in that brand’s store from your email address, marked as not accepting marketing; that record is created by Shopify rather than by Syfted, and it can remain in the brand’s store after the order itself is gone. A brand can turn order creation off, and some do. Syfted also reduces the stock count for the item you bought so it cannot be sold twice.
Nothing about your order is written into a brand’s Square account — an unpaid order is not visible there, so Syfted only adjusts stock. Whichever route your details take, a brand may use them only to fulfil your order and support it; the Brand & Seller Agreement prohibits every other use, including marketing. If you want your details removed from a brand’s own store as well as from Syfted, tell us and we will pass the request on — see Section 8.
With Service Providers
We use third-party service providers to help operate the Platform, including:
- Stripe — payouts to brands via Stripe Connect and recurring subscription billing for brand seller plans. Stripe no longer processes buyer payments; it may still hold records of purchases made before checkout moved to Shopify, and it is where a refund of one of those orders is issued. Stripe is subject to its own Privacy Policy.
- Stripe Connect — payout infrastructure for brand owners. When brand owners set up payouts, their business and banking information is shared with Stripe under Stripe’s Connected Account Agreement. Brand owners’ payout data is governed by Stripe’s Privacy Policy.
- Shopify — when a brand has connected their Shopify store, Syfted reads their catalog and shipping rates, reduces their stock count when an item sells, and creates the corresponding order in their store so they can fulfil it. That order carries your name, shipping address and email — the minimum needed to ship your item and to contact you about a problem with it. Shopify creates a customer record in the brand’s store from that email address, marked as not accepting marketing. Syfted reads fulfilments only for the orders it created, to pass your tracking number back to you. Separately, Syfted runs its own Shopify store, which processes every checkout; your checkout, shipping and payment data is therefore processed by Shopify on every order, under Shopify’s Privacy Policy.
- Square — when a brand has connected their Square account, Syfted reads their catalog and reduces their stock count when an item sells. No buyer information is sent there.
- Supabase — database hosting, authentication infrastructure, and file storage for images uploaded by brands (logos, banners, product photos, and size charts).
- Zonos — cross-border duty and tax calculation, customs documentation, and shipping labels for orders that cross an international border. Where your order does, we share your shipping name and address, your contact details, and the description, weight, value and country of origin of each item, so that the import duties and taxes can be calculated at checkout, remitted to the destination country’s tax authority, and a customs-cleared shipping label produced for the brand to print. Zonos also passes what customs requires to the carrier and the destination customs authority. Domestic orders are not shared with Zonos. Zonos is subject to its own Privacy Policy.
- Resend — transactional and marketing email delivery.
- Vercel — web application hosting and edge delivery.
- Expo / Apple / Google — mobile push notification infrastructure.
- Twilio — SMS notification delivery for brand account holders who provide a phone number.
These providers may access your personal information only to perform services on our behalf and are obligated to protect it.
For Legal Reasons
We may disclose your information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Syfted, our users, or the public.
Business Transfers
If Syfted is involved in a merger, acquisition, financing, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Platform if such a transfer occurs and your data will become subject to a different privacy policy.
4. Cookies and Tracking
The Syfted website uses cookies and similar technologies to maintain your session, remember your preferences, and support platform functionality. We use session cookies (which expire when you close your browser) and persistent cookies (which remain until deleted or expired).
We do not currently use third-party advertising or tracking cookies. If this changes, we will update this Privacy Policy accordingly.
Images on our website and mobile app — including brand logos, product photos, and size charts — are served through Syfted, not fetched directly by your browser from a brand’s own servers. Emails are the exception: when you open a Syfted email that contains a product image, your email application may request that image from the brand’s image host, which can reveal your IP address and email application to that host. Most email applications block or proxy remote images by default, and you can disable remote image loading in your email settings.
The Syfted mobile application uses device storage (AsyncStorage) to persist your shopping cart and session data locally on your device. This data does not leave your device except as part of normal app operations (e.g., syncing your cart to our servers when signed in).
Your appearance preference (light mode, dark mode, or follow-your-device) is stored only on the device you set it on — in browser local storage on the website, and in device storage in the mobile app. It is never sent to our servers, is not linked to your account, and does not follow you between devices.
You can control cookie behavior through your browser settings. Disabling cookies may affect the functionality of the Platform.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. Order and transaction records may be retained for up to 7 years to satisfy tax and accounting requirements. Syfted Points ledger entries are retained alongside the order records they relate to, for the same period, so that rewards liability and redemptions remain auditable. If you close your account, we will delete or anonymize your personal data within a reasonable time, except where retention is required by law; any unredeemed points are forfeited at that point, as described in our Terms of Service.
Product view events are deleted after 12 months, automatically and regardless of whether your account is still open. If you close your account, any view events linked to it are unlinked from you and kept only as an anonymous count until they age out on that same schedule.
6. Children’s Privacy
The Platform is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created an account or provided personal information on Syfted, please contact us at support@shopsyfted.com and we will promptly delete that information and terminate the account.
7. Security
We implement commercially reasonable technical and organizational measures to protect your personal information from unauthorized access, loss, or disclosure. These include encrypted data transmission (HTTPS/TLS), row-level security on our database, and access controls limiting who can view personal data.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your information. If you believe your account has been compromised, please contact us immediately at support@shopsyfted.com.
8. Your Rights and Choices
Depending on where you live, you may have certain rights regarding your personal information, including:
- Access — request a copy of the personal information we hold about you
- Correction — request that we correct inaccurate or incomplete information
- Deletion — request that we delete your personal information (subject to legal retention requirements)
- Opt-out of marketing — opt out of non-transactional emails at any time via the unsubscribe link in any email or by contacting us
- Push notifications — manage push notification permissions through your device settings at any time
To exercise any of these rights, contact us at support@shopsyfted.com. We will respond within 45 days. We may need to verify your identity before processing certain requests.
California Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (“CCPA”) grants you the following rights:
- The right to know what personal information we collect, use, disclose, and sell
- The right to request deletion of your personal information
- The right to opt out of the sale of your personal information — Syfted does not sell personal information
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, contact us at support@shopsyfted.com with the subject line “CCPA Request.”
9. International Users
The Platform is operated from the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Platform, you consent to this transfer and processing.
10. Third-Party Links
The Platform may contain links to brand websites and other third-party services. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party services you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or in-app notice. Your continued use of the Platform after changes take effect constitutes your acceptance of the updated Privacy Policy.
Contact Us
Questions, requests, or complaints about this Privacy Policy should be directed to:
Lucas Ferry Enterprises LLC
dba Syfted — Privacy
Mailing address available upon written request.