Learn how ClickSync securely handles merchant configurations, sync maps, and API keys. Last updated: August 17, 2026
Short version: ClickSync securely handles merchant configurations and sync maps. We process store webhook payloads (orders, customers, refunds, checkouts, status transitions) strictly to populate tasks in your mapped ClickUp lists. Your ClickUp API tokens are fully encrypted at rest using industry-standard AES-256-GCM. We never share your store or customer data with third parties.
Loopstates ("we", "us", "our") built ClickSync as a WordPress plugin. This policy details what data is processed, how it is secured, and the mechanisms used to connect your WooCommerce store and ClickUp Workspace.
Data Processing & Storage
ClickSync processes store payloads on demand when event webhooks trigger. To perform synchronization, our app acts as a secure transit bridge between WooCommerce and ClickUp:
ClickUp API Access Tokens:
To create tasks and fetch workspace lists on your behalf, we obtain an OAuth access token from ClickUp. This key is instantly encrypted using AES-256-GCM on our database and decrypted only when initiating active sync requests to ClickUp.
WooCommerce Data (Orders, Customers, Pending Orders, Refunds, Checkout events, Status Transitions):
We receive event payloads from WordPress client webhooks. We read only the fields mapped by your rules (e.g. customer name, email, order total, product names, order status) to generate corresponding ClickUp tasks. We do not maintain a permanent database of your customers or orders.
Sync Logs:
To help you troubleshoot and trace sync events, we store execution logs (sync status, timestamp, ClickUp task URL, and any API error messages) for up to 7 days, after which they are automatically pruned.
Third-Party Data Processors (ClickUp)
ClickSync acts as a secure transit bridge transferring merchant-authorized store data (Orders, Customers, Pending Orders, Refunds, Status Transitions) directly to ClickUp, Inc. via ClickUp's official public API and OAuth 2.0 protocol.
Data processing and privacy within your ClickUp Workspace are governed by ClickUp's official agreements:
We prioritize the protection of your merchant credentials and data:
Cryptographic Encryption:
Tokens are encrypted with AES-256-GCM at rest. The master decryption key is managed securely in the app environment and is never logged or exposed.
HMAC Signature Verification:
Every request and webhook originating from WooCommerce / WordPress is cryptographically verified using HMAC SHA-256 headers before processing to ensure the request is genuine.
Safe Communication:
All transfers between WordPress, our servers, and ClickUp's API endpoints are encrypted in transit via Transport Layer Security (TLS 1.3 / HTTPS).
WordPress Core Privacy & Data Rights
ClickSync is fully integrated with the native WordPress privacy tools to support merchants in compliance with GDPR, CCPA, and similar data privacy regulations:
WordPress Personal Data Export: When a site administrator processes a native WordPress data export request for a customer email, ClickSync compiles any temporary sync queue logs or mapped variables associated with that customer.
WordPress Personal Data Erasure: Initiating a native WordPress data erasure request triggers the instant purge of any customer-specific execution logs and transit queue mappings on our servers.
Site Disconnection & Uninstall Cleanup: Disconnecting the ClickUp Workspace or uninstalling the plugin runs a database cleanup routine to permanently delete all local mappings, cached tokens, and options entries from your WordPress database options table.
Billing Portal
All transactions, subscription billing, and plan upgrades are handled exclusively via the **ClickSync Connect Billing Portal**. ClickSync does not collect, process, or store credit card details or bank credentials.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at [email protected].