Privacy Policy
Last updated: June 26, 2026 Effective date: June 26, 2026
1. Who we are
Datacrow ("we", "our", "us") is a server-side conversion tracking application for Shopify stores. Datacrow is operated from North Carolina, United States.
Contact:
- Email: privacy@datacrow.app
- Security disclosures: security@datacrow.app
If you are a shopper and want to exercise your data rights, please contact the merchant whose store you interacted with — they are the controller of your personal data, and we are their data processor. We will respond to data requests through them.
2. Scope of this Privacy Policy
This policy explains how Datacrow collects, uses, stores, and shares personal data. It covers:
- Merchants: Shopify store owners who install Datacrow.
- Shoppers: customers of those Shopify stores whose data flows through Datacrow.
Merchants act as the data controller for shopper data. We act as the data processor on the merchant's behalf, governed by our Data Processing Agreement.
3. Data we collect from Shopify APIs (Shopify Section 1)
When a merchant installs Datacrow, Shopify grants us access to specific data via OAuth scopes. We collect only what we need to perform our service. As of the current version, we request these scopes:
| Scope | Why we need it |
|---|---|
read_orders | To process orders/create, orders/paid, and refunds/create webhooks so we can forward purchase and refund events to merchant-configured destinations |
read_checkouts | To process checkouts/update webhooks so we can forward begin-checkout events as a durable fallback when the storefront pixel is blocked by ad-blockers |
read_customer_events | Required by Shopify for our Web Pixel extension to function |
read_pixels / write_pixels | To register and update the Web Pixel that captures storefront events |
From these scopes we read and temporarily store:
- Order data (order ID, total price, currency, line items, billing/shipping addresses, customer email/phone, customer ID, timestamps, IP, user-agent)
- Refund data (refunded order ID, refunded line items and amount, customer identifiers recovered from the original order — via the
refunds/createwebhook) - Checkout data (checkout token, line items, customer contact info as entered during checkout)
- Web Pixel events emitted by the storefront (page views, product views, add-to-cart, begin-checkout, purchase)
- Shop metadata (domain, plan, owner email)
4. Data we collect from merchants (Shopify Section 2)
When merchants configure Datacrow, they provide:
- Account information (Shopify-provided merchant email and shop domain)
- Destination credentials (API keys, access tokens, advertiser/account IDs for Meta CAPI, GA4, Klaviyo, TikTok, Pinterest, Google Ads)
- Configuration preferences (which events fire to which destinations)
- Billing information (handled by Shopify's billing API — we do not see credit card details)
Destination credentials are encrypted at rest using AES-256-GCM with a versioned, service-managed encryption key. We do not see, log, or transmit credentials in plaintext after they are stored.
5. Data we collect from shoppers (Shopify Section 3)
When a shopper interacts with a Shopify store that has Datacrow installed, the storefront's Web Pixel captures events that include:
- Identifiers: email address, phone number, Shopify customer ID (when present)
- Pseudonymous identifiers: a Datacrow anonymous ID (
ld_anon_id), session ID (ld_session_id), GA cookie ID (_ga), Meta cookies (_fbp,_fbc), TikTok identifiers (ttclid,_ttp) - Marketing click identifiers: gclid, gbraid, wbraid (Google Ads), fbclid (Meta)
- Technical metadata: IP address, user-agent, browser language, page URL, referrer URL
- Commerce data: products viewed, items added to cart, checkout details, order details
We do not drop or set any cookies on the storefront ourselves. The cookies above are written by other actors (the shopper's browser, the merchant's own pixels, Shopify's first-party session cookies). Datacrow reads them via the Shopify Web Pixel sandbox and forwards the values server-side.
We honor the shopper's customer-privacy choices as they are signaled to us through Shopify's Customer Privacy API on the storefront. When the storefront communicates that a shopper has declined analytics or marketing processing, we do not forward their events to the corresponding destinations. Where no choice is signaled to us (for example, in regions without a mandatory consent prompt), we treat processing as permitted, consistent with Shopify's own default handling. The merchant, as the controller of shopper data, remains responsible for configuring consent collection on their storefront.
6. How we use this data (Shopify Section 4)
We use shopper and merchant data solely to provide the Datacrow service, which means:
- Forwarding canonical events to the destinations the merchant has configured (Meta CAPI, GA4, Klaviyo, TikTok, Pinterest, Google Ads)
- Hashing or transforming identifiers per each destination's requirements (e.g., SHA-256 for Meta CAPI; passthrough for Klaviyo)
- Deduplicating events between the browser pixel and server-side webhook paths so each destination receives each event once
- Logging delivery success/failure for merchant dashboard reporting and our own operational debugging
- Retrying failed deliveries via our internal queue (BullMQ)
- Operational analytics (queue depth, error rates) — these never include shopper PII
We do not:
- Sell, lease, or share shopper data with any party other than the merchant-configured destinations
- Use shopper data for any purpose unrelated to the service (e.g., training AI models, building cross-merchant audiences, advertising our own product)
- Combine shopper data across merchants
- Retain credentials, identifiers, or events past the retention periods below
Google user data
Datacrow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account access solely to upload the merchant's own conversion events to the merchant's Google Ads account and to list the Google Ads accounts the merchant can choose from. We do not use this data to serve ads, transfer it except to provide the service, or allow humans to read it except for security purposes or to comply with applicable law.
7. Sub-processors
Datacrow uses sub-processors to deliver the service. The current list, with function and geographic location, is published at https://datacrow.app/subprocessors.
The list includes:
- Destination APIs: Meta Conversions API, Google (GA4 + Google Ads), Klaviyo, TikTok, Pinterest
- Infrastructure: Railway (compute + database + Redis hosting), the underlying cloud providers Railway uses
- Observability: Axiom (log aggregation), if enabled
We notify merchants of changes to our sub-processor list at least 30 days before the change takes effect, except when the change is needed to maintain service continuity (e.g., emergency provider migration), in which case we notify as soon as practically possible.
8. Retention (Shopify Section 5)
| Data type | Retention period | Why |
|---|---|---|
| Canonical events | 90 days (default) | Dashboard reporting + retry windows; global default, configurable by Datacrow |
| Event delivery logs | 90 days | Same; needed for delivery diagnostics |
| Encrypted destination credentials | Until the merchant uninstalls or removes them | Required for ongoing service |
| Merchant account metadata (shop domain, owner email) | Until 30 days after uninstall | For re-install continuity + audit trail |
| Operational logs (no shopper PII) | 30 days | For debugging |
Shopify GDPR customers/redact webhook | Triggers immediate removal of that shopper's personal identifiers (email, phone, customer ID) from all stored events | |
Shopify shop/redact webhook | Triggers immediate deletion of all data for that merchant's store within the Shopify-mandated window (48 hours) |
Merchants can request earlier deletion at any time by emailing privacy@datacrow.app.
9. Where data is stored and processed (Shopify Section 6)
Datacrow's application servers, database, and queue infrastructure are hosted on Railway, primarily in their US-West region (Oregon, United States). Logs may be replicated to Axiom in the United States.
For merchants based in the European Economic Area (EEA) or the United Kingdom, this means shopper data is transferred to the United States. We rely on the 2021 European Commission Standard Contractual Clauses (SCCs), Module 2 (controller-to-processor) and the UK International Data Transfer Addendum (IDTA) as the legal mechanism for these transfers. The SCCs and IDTA are incorporated into our Data Processing Agreement, which all merchants accept by installing Datacrow.
10. Shopper rights
If you are a shopper whose data has been processed by Datacrow on a merchant's behalf, you have the following rights depending on your jurisdiction:
- Access: know what data we hold about you
- Correction: have inaccurate data corrected
- Erasure / Deletion: have your data deleted
- Restriction: limit how we process your data
- Portability: receive your data in a structured format
- Objection: object to processing for certain purposes
- Opt-out of sale/sharing (CCPA/CPRA): we do not sell or share data, so this right is automatically honored
To exercise these rights, contact the merchant first — they are the controller. Shopify's mandatory data webhooks (customers/data_request, customers/redact) route shopper requests through the merchant to us automatically.
You may also email us directly at privacy@datacrow.app. We will work with the merchant to process your request.
11. CCPA / CPRA disclosures (California shoppers)
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Categories of personal information we collect: identifiers (email, phone, customer ID), internet/network activity (cookies, IPs, page views), commercial information (orders, products viewed), geolocation (from IP, coarse)
- Categories of sources: shoppers (via the Web Pixel and checkout), merchants (their Shopify store via webhooks)
- Business purposes: providing the Datacrow service as described in Section 6
- Categories of third parties we share with: the merchant's configured destinations only (see Sub-processors)
- Sale / Share of personal information: We do not sell or share personal information within the meaning of CCPA/CPRA. This is a contractual commitment in our DPA.
- Sensitive personal information: we do not collect SSN, driver's license, financial account, precise geolocation, race/ethnicity, religion, union membership, health, or sexual orientation data
- Retention: see Section 8
California residents can exercise their CCPA/CPRA rights by contacting the merchant or by emailing privacy@datacrow.app.
12. GDPR / UK GDPR disclosures (EEA and UK shoppers)
- Controller: the merchant whose store you interacted with
- Processor: Datacrow
- Legal basis for our processing: contractual necessity (Art. 6(1)(b)) for the merchant-Datacrow relationship; the merchant relies on their own legal basis (typically consent or legitimate interest) for processing shopper data, and is responsible for documenting that basis to shoppers
- International transfers: see Section 9
- Right to lodge a complaint: with the data protection authority in your country of residence
13. Children's privacy
Datacrow does not knowingly process the personal data of children under 13 (United States) or under 16 (EU, depending on Member State). If we become aware that we have inadvertently collected such data, we will delete it promptly. Merchants must not configure Datacrow on stores directed at children below these thresholds.
14. Security
We implement industry-standard security controls including:
- Encryption at rest (AES-256-GCM for credentials, encrypted volumes for database backups)
- Encryption in transit (TLS 1.2+ for all data flows)
- Multi-factor authentication on all administrative accounts
- Per-merchant data isolation enforced at the database layer
- Access logging for administrative actions
- Documented incident response procedures (see our internal incident response procedures)
In the event of a personal data breach affecting your data, we notify the affected merchant(s) within 72 hours of becoming aware, and the merchant is responsible for notifying you under their own GDPR/CCPA obligations.
15. Cookies
Datacrow does not set or write cookies on the merchant's storefront. Our Web Pixel runs in Shopify's sandbox and reads cookies set by other actors (the shopper's browser, Shopify's first-party session cookies, the merchant's own marketing pixels).
The Datacrow admin dashboard (which only merchants see, not shoppers) authenticates with short-lived Shopify App Bridge session tokens sent on each request; it does not set an authentication cookie. This is not relevant to shoppers.
16. Changes to this Privacy Policy
We may update this policy from time to time. When we do, we will:
- Update the "Last updated" date at the top
- Notify merchants by email at least 30 days before material changes take effect (except for legally-required changes, where the timeline may be shorter)
- Maintain prior versions in our public repository
17. Contact
- General privacy questions: privacy@datacrow.app
- Security disclosures: security@datacrow.app (PGP key available on request)
- Mailing address: North Carolina, United States
- Data Protection contact: same as general privacy contact
This privacy policy is published in plain English on purpose. If anything in it is unclear, please email us.