Control for Sylius
Privacy Policy

The app talks to your Sylius store and to nobody else. We never see your store, your customers or your orders.

Effective 24 August 2026. This policy covers the iOS application Control for Sylius (bundle identifier shop.3brs.sylius.app.control), published by 3BRS.

The short version

Control for Sylius connects directly to the Sylius store you point it at. Your store address, your credentials and everything the app reads from your store stay on your device. None of it passes through or is stored on 3BRS servers. The only thing we receive is anonymous crash and usage diagnostics that tell us whether the app is working.

How the app works

  • Your server, your connection - You enter the address of your own Sylius installation and your own API credentials. From then on the app speaks to that server directly over HTTPS, the same way any other API client would. 3BRS operates no proxy, no relay and no backend for this app, and is never part of that connection.
  • Your data stays with you - Orders, customers, products, stock levels and anything else the app displays are fetched from your store, held on your device for as long as you use the app, and are never transmitted to 3BRS or to anyone else.
  • No account with us - There is nothing to sign up for. We do not know who installs the app, and we hold no user accounts, names, email addresses or store addresses.

What is stored on your device

  • Your store address and API credentials - saved in the app's own storage on the device so you do not have to type them in every time. They are never sent to 3BRS.
  • Cached store data and app settings - kept locally so the app is quick to open.

All of it is removed from the device when you delete the app. You can also clear the stored connection from within the app at any time.

What we do collect

To know whether the app is stable and which parts of it people actually use, the app sends diagnostic and usage information to two service providers. This information is not linked to your identity and never contains data from your store.

  • Crash and error diagnostics (Sentry) - When the app crashes or hits an error, a report is sent to Sentry containing the error message and technical stack trace, the app version, the device model and the iOS version. Sentry also sees the IP address the report arrives from, as any internet service does. We use these reports only to find and fix faults. See the Sentry privacy policy.
  • Usage measurement (Google Analytics) - The app records which screens are opened and which features are used, together with the app version, the device model, the iOS version and an approximate region derived from the IP address. These events are tied to a randomly generated identifier for the app installation, not to you, not to your store and not to any account. See the Google privacy policy.

In Apple's App Store terms this is Diagnostics and Usage Data, and it is not linked to your identity. We do not use it to track you across other companies' apps or websites, and the app contains no advertising identifier.

What we never collect

  • Your store's address, API credentials, or any other login details.
  • Orders, customers, products, prices, stock or any other content from your store.
  • Your name, email address, postal address or telephone number.
  • Your precise location, contacts, photos, calendar or health data.
  • Anything at all that we could use to identify you or your business.

Sharing and selling

We do not sell, rent or trade any data, and we do not share it for advertising. The only third parties involved are Sentry and Google, named above, who process the diagnostics on our instructions as our service providers. We may disclose information if the law requires it, though in practice we hold almost nothing that could be disclosed.

How long we keep it

Crash reports are kept for up to 90 days and then deleted. Aggregated usage statistics are kept for up to 14 months. Data held on your device stays there until you delete it or remove the app.

Your rights

If you are in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR give you the right to access, correct, delete or restrict the processing of your personal data, and to object to it or lodge a complaint with your data protection authority. Because the diagnostics we receive are not linked to your identity, we are usually unable to connect a request to a particular person; if you get in touch we will explain what we hold and do what we can. Our lawful basis for collecting diagnostics is our legitimate interest in keeping the app working correctly.

Children

Control for Sylius is a tool for people running online shops. It is not directed at children and we do not knowingly collect anything from anyone under 16.

Security

The app communicates with your store over HTTPS. Keeping your own Sylius installation, its API and its credentials secure remains your responsibility, as does protecting the device the app is installed on. If you think a credential has been exposed, revoke it in your store.

Changes to this policy

If we change how the app handles data, we will update this page and change the effective date at the top. Material changes will also be described in the app's release notes.

Contact us

The data controller is 3BRS, 20-22 Wenlock Road, N1 7GU London, United Kingdom. For any question about this policy, or to exercise your rights, please get in touch.