Privacy policy
Last updated 23 July 2026.
The short version
Paid Signal reads your Shopify orders so it can tell your ad platforms which
orders were actually paid for. We do not store your customers’ names, email
addresses or phone numbers in readable form — they are hashed before they are
written down, and the hash cannot be turned back into the original value.
What we collect
From your Shopify store, for each order:
- Irreversible hashes of email, phone, first and last name, city and country. These are SHA-256 digests. We never store the plaintext.
- Order facts: order id and number, total value, currency, payment status, payment gateway, and the times the order was placed and paid.
- Advertising click identifiers present on the order (for example Meta’s fbc/fbp, Google’s gclid, TikTok’s ttclid, Snapchat’s sccid) plus the landing URL and UTM parameters.
- Refunds and returns, so a conversion that later reversed can be corrected.
From you, the merchant: your email address, a hashed password, and the access
tokens for the services you connect. We do not store card or bank details, and
Paid Signal never takes payment inside the app.
Why we collect it
Meta, TikTok and Snapchat match a server-side conversion to the right person
using hashed identifiers — that is the format their APIs require. The hashes
exist for that single purpose. The order facts drive your dashboard. The click
identifiers attribute an order to the campaign that produced it.
We do not sell data, we do not share it between merchants, and we do not use
one merchant’s data to build anything for another.
Field by field — what is read, what it becomes, and what breaks without it
— is set out in how we use protected customer data.
Who we send it to
- The ad platforms you switch on, and only those: Meta, TikTok, Snapchat. They receive the hashed identifiers, the order value, currency and event time. Google receives a CSV you export and import yourself.
- Our database host (Supabase, PostgreSQL) where the data is stored.
- Our email provider (Resend) for account emails such as verification and password resets.
No one else. There are no advertising or analytics trackers on the dashboard.
How it is protected
- All traffic is over HTTPS.
- Access tokens and API secrets are encrypted at rest with AES-256-GCM. They are never written to logs.
- Passwords are stored as scrypt hashes, never in plaintext or reversible form.
- Each workspace is isolated at the database level by PostgreSQL row-level security, and the application connects with a role that cannot bypass it. One merchant cannot read another’s rows even if the application had a bug.
- Every webhook from Shopify is HMAC-verified before it is processed.
How long we keep it
Order records are kept while your workspace is active, because your reporting
depends on them. When you uninstall the app we stop processing immediately, and
when Shopify sends the shop deletion request that follows an uninstall we delete
that workspace’s data.
Your rights, and your customers’
We answer Shopify’s standard data requests automatically:
- Customer data request — we report what is held for that customer. In practice that is hashes and order facts, never readable personal data.
- Customer deletion — we clear every identifier tied to that customer. The order’s money figures remain, because your own revenue reporting depends on them, but they no longer relate to an identifiable person.
- Shop deletion — we delete the workspace’s data entirely.
You can also ask us directly at info@paidsignal.app
and we will action it.
Changes
If this policy changes materially we will tell workspace admins by email before
it takes effect.
Contact
info@paidsignal.app