Privacy Policy
Effective date: August 25, 2026
Draft — pending legal review before this app is submitted to the Shopify App Store. Written to accurately describe what the app's code actually does as of this date, not aspirational or templated language.
This Privacy Policy describes how the ROASify app ("the App", "we", "us") collects, uses, stores, and shares data when you install and use the App.
1. What the App Does
The App connects to your Shopify store via OAuth and to a Google Ads account of your choosing via a separate OAuth connection. When Shopify notifies the App that an order has been refunded or cancelled, the App checks that order's current status through Shopify's Admin API and sends a conversion adjustment (a retraction for a full refund, or a corrected value for a partial refund) to the Google Ads conversion action you select. The App does not send new conversions to Google Ads — it only adjusts conversions already tracked by whatever Purchase-tracking setup you already use (Shopify's native sales channel, another app, etc.).
2. Data Collected
Shopify OAuth access token, refresh token
Shopify token-exchange flow
Encrypted at rest; deleted on uninstall
Google Ads OAuth refresh token
Google OAuth consent flow (a connection you initiate separately in Settings)
Encrypted at rest; deleted when you disconnect Google Ads or uninstall the App
Google Ads Customer ID, conversion action ID
You select these in Settings (or via the "Discover accounts" lookup)
Until you change them or uninstall
Shopify order ID and order-level financial data (amounts, refund/cancellation status, currency)
Shopify refund/cancellation webhooks, plus an Admin API lookup of the order's current status
Raw webhook payloads: up to 90 days, then automatically deleted. Adjustment history (order ID, adjustment type, status): until you clear it or uninstall.
Admin action log (settings changes, Google Ads connect/disconnect, IP address, browser user agent)
Internal — recorded when you use the dashboard
90 days, then automatically deleted
The App requests only Shopify's read_orders scope and has not requested Shopify's Protected Customer Data access. As a result, Shopify does not include your customers' name, email, phone number, or address in the data the App receives — this App is designed to never need that data, since it only ever sends an order ID and an adjustment value to Google Ads, not customer identity.
3. How We Use Data
- Adjustment sync: when a refund or cancellation webhook arrives, we look up the order's current financial status via Shopify's Admin API and send the order ID plus the adjustment type and value to the Google Ads account and conversion action you've selected. No customer data is included in this transmission.
- Event logging: we log each adjustment attempt (order ID, adjustment type, status, error message if any) for display in your dashboard.
- Retry queue: if a Google Ads API call fails with a transient error, the adjustment is retried automatically up to 3 times over about 20 minutes, then moved to a dead-letter list you can review and manually replay from the dashboard.
4. Data Shared with Third Parties
The only third party we share data with is Google LLC, via the Google Ads API. What's shared is limited to an order ID, an adjustment type (retraction or restatement), and — for a partial-refund restatement — a corrected monetary value. No customer name, email, phone number, or address is ever sent to Google Ads by this App. Google's use of this data is governed by Google's Privacy Policy and the Google Ads API Terms of Service.
We do not sell data, share it with advertisers, or use it for any purpose beyond operating the App.
5. Data Security
- Shopify and Google Ads OAuth tokens are encrypted at rest (AES-256-GCM) and transmitted only over HTTPS.
- Webhook deliveries from Shopify are verified against Shopify's signature (HMAC-SHA256) before being processed.
- The dashboard is accessible only through an authenticated session established during Shopify's embedded app connection, with CSRF protection on every change.
6. CCPA / California Privacy Rights
Because the App does not receive or store customer name, email, phone number, or address (see Section 2), there is generally no customer-identifiable personal data for us to disclose or delete under CCPA in connection with your customers. If you believe we hold data that should be corrected or deleted, contact us using the details below.
7. Data Retention and Deletion
- Raw webhook payloads: automatically deleted after 90 days.
- Admin action log: automatically deleted after 90 days.
- Adjustment/event log: you can clear it at any time from your dashboard. All logs are deleted when the App is uninstalled.
- Credentials (Shopify and Google Ads tokens): deleted when the App is uninstalled, or immediately when you disconnect Google Ads from Settings.
- Retry queue: cleared automatically after successful delivery, or after 3 failed attempts (moved to the dead-letter list described above).
8. Children's Privacy
The App is a B2B tool designed for use by Shopify merchants. It is not directed at children under 13, and we do not knowingly collect data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will be updated accordingly. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or your data, please contact us at 7labs@dmitru.com.