Privacy Policy

Last Updated: January 19, 2025

Important: TrueMetrics is committed to protecting your privacy and the privacy of your customers. This Privacy Policy explains how we collect, use, and protect data when you use our server-side conversion tracking application. We comply with all Shopify Protected Customer Data requirements and implement industry-leading security measures including encryption at rest, encrypted backups, audit logging, and comprehensive data protection controls.

1. Introduction

TrueMetrics ("we," "our," or "us") provides server-side conversion tracking services for Shopify merchants. This Privacy Policy describes how we handle data when you install and use our application on your Shopify store.

By using TrueMetrics, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Merchant Information

When you install TrueMetrics, we collect:

2.2 Protected Customer Data (PII)

We collect only the minimum data required to provide attribution tracking services:

Data minimization: We do NOT collect phone numbers, addresses, payment information, or other unnecessary personal data.

2.3 Consent Data

We collect and respect customer consent preferences via Shopify's Customer Privacy API:

2.4 Tracking Identifiers

We collect and process analytics tracking identifiers:

Consent enforcement: Tracking data is only sent to platforms when customer has provided explicit consent via Shopify's consent banner.

3. How We Use Your Information

3.1 Primary Purpose

We use the collected data exclusively to:

3.2 Data Processing

When processing order data:

4. Data Sharing and Disclosure

4.1 Third-Party Services

We share data with the following third parties, only as necessary to provide our services:

4.2 What We Do NOT Do

We will never:

5. Data Storage and Retention

5.1 Storage Location

All data is stored securely on Google Cloud Platform servers located in the United States.

5.2 Data Retention Policy

We enforce strict data retention limits in compliance with GDPR and Shopify requirements:

Automated cleanup: Expired data is automatically deleted through daily cleanup processes. No manual intervention required.

5.3 Data Encryption

Encryption at Rest:

Encryption in Transit:

6. Data Security

We implement enterprise-grade security measures exceeding Shopify's Protected Customer Data requirements:

6.1 Encryption

6.2 Access Controls

6.3 Audit Logging

6.4 Security Incident Response

6.5 Infrastructure Security

7. Your Rights and Choices

7.1 Customer Consent Controls

We respect and enforce customer consent preferences:

7.2 Merchant Access and Control

As a merchant, you have the right to:

7.3 Data Processing Agreement

A GDPR-compliant Data Processing Agreement (DPA) is available:

7.4 Uninstalling the App

When you uninstall TrueMetrics:

7.5 Data Deletion Requests

To request immediate data deletion:

8. GDPR Compliance

TrueMetrics is fully compliant with the General Data Protection Regulation (GDPR) for merchants and customers in the European Economic Area (EEA):

8.1 Legal Basis for Processing

8.2 Data Subject Rights

All GDPR rights are fully supported:

8.3 Data Protection Officer

For GDPR-related inquiries, contact our privacy team at truemetricsapp@gmail.com

8.4 Data Processing Agreement

8.5 Breach Notification

9. CCPA Compliance

For California residents, we comply with the California Consumer Privacy Act (CCPA):

9.1 California Consumer Rights

9.2 Categories of Personal Information Collected

9.3 Do Not Sell My Personal Information

We do NOT sell personal information. We share data only with platforms you explicitly configure (GA4, Meta, TikTok) solely for attribution tracking purposes.

9.4 Exercising Your Rights

To exercise CCPA rights, contact: truemetricsapp@gmail.com

10. Shopify Protected Customer Data Compliance

TrueMetrics meets all 16 requirements of Shopify's Protected Customer Data policy:

Level 1 Requirements (All Apps)

Level 2 Requirements (Sensitive PII)

Compliance Status: 100% (16/16 requirements met)

11. Cookies and Tracking

TrueMetrics reads the following cookies from your customer's browsers:

Consent-based tracking: These cookies are read only when customer has provided explicit consent via Shopify's consent banner. No tracking occurs without consent.

12. Children's Privacy

TrueMetrics is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately at truemetricsapp@gmail.com for immediate deletion.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

Continued use of TrueMetrics after changes constitutes acceptance of the updated policy.

Version history: Previous versions of this policy available upon request.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Response Time: We respond to all privacy-related inquiries within 72 hours.

15. Shopify App Certification

As a certified Shopify app, we comply with all Shopify App Store Requirements:

Shopify Partner ID: [Your Partner ID]

App Review Status: Approved and compliant

Privacy Policy Summary:

Questions? Contact truemetricsapp@gmail.com - We respond within 72 hours.