C Capyo
de
Auf Shopify installieren

Privacy Policy

Last updated: 2026-09-10

This policy explains what data the Shopify app Capyo: ChatGPT Ads Pixel & ROAS and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as an advertiser or as a data controller.

1. Who is responsible

The controller for the processing described here is Capyo, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.

Operator legal name and address: [to be added]

For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses — see section 2 for exactly what it does read and store.

2. Data the app processes

It comes from Shopify when you install the app, from your storefront's own Web Pixel, and from you. In detail:

Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.

3. What the storefront pixel sends, and what it stores in the browser

The kliq-pixel Web Pixel extension runs inside Shopify's own strict sandbox: no DOM access, and no vendor script from OpenAI or anyone else is loaded. It subscribes to five standard Shopify storefront events (page view, product view, add to cart, checkout started, checkout completed) and sends them in small batches — a single network request per batch, using keepalive so a closing tab doesn't drop the last one — to Capyo's own /collect endpoint. No third-party analytics and no advertising tags run alongside it.

The extension stores one value in the browser: the ad platform's attribution identifier (oppref), read from the landing page URL when a shopper arrives from a ChatGPT ad, kept for 90 days in localStorage (key kliq_oppref) with a same-purpose cookie (_kliq_oppref) as a fallback. This value identifies an ad click, not a person, and exists solely so that an order placed later in the same browser can be matched back to the ad that brought the visit. Whether the extension runs at all, and whether this value is written, is governed by Shopify's own Customer Privacy API: your consent configuration decides, and events Shopify itself drops for lack of consent never reach Capyo.

IP address and user agent. The /collect request Shopify's sandbox makes carries your visitor's IP address and user agent, the way any web request does. Capyo holds these values in memory for up to 10 minutes, only to attach them to the outbound Conversions API event so OpenAI can match it, and then discards them. They are never written to disk or to the database — neither in the event outbox, the debug samples, nor anywhere else described in section 2.

4. What we never process

Order id, order totals, line items and the anonymous click-attribution data in section 2 are processed — that is the app's purpose — but none of it identifies your customer as a person.

Shopify sends every public app the two mandatory customer-privacy webhooks (customers/data_request and customers/redact). Capyo acknowledges them; because it holds no customer personal data, there is nothing to return, and customers/redact erases the delivery records and click ids tied to the named orders as a precaution.

5. This website

This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.

6. Why we process it, and on what legal basis

We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.

7. How long we keep it

8. Who else is involved (sub-processors)

Sub-processorCompany countryWhat they doWhere the servers are
Shopify International Ltd Ireland The platform the app runs on and the source of all store data; also handles billing Per Shopify's own DPA
OpenAI United States Receives the events Capyo relays (page views, product views, cart adds, checkout and order data — ids, amounts, currency, no customer identity) at your own instruction, through your own Pixel ID and Conversions API key, into your own OpenAI Ads account — not an account Capyo controls Per OpenAI's own terms
Resend United States Would deliver alert emails to the address you set, to your address only — not active today. It starts processing data only once a sending domain is bought and verified; until then, alerts are shown as in-app banners and Resend receives nothing Per Resend's own terms
Hostinger International Ltd Cyprus Application hosting — the virtual server the app runs on Boston, Massachusetts, United States
netcup GmbH Germany Database hosting — the PostgreSQL database holding everything in section 2 Manassas, Virginia, United States
GitHub, Inc. United States Hosting of this website only — no app data reaches it GitHub Pages global infrastructure

There is no analytics provider, no error-tracking SaaS, no email marketing tool and no CRM in this list. We will update this table before any new sub-processor starts processing, including when Resend becomes active.

9. International transfers

Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The events Capyo relays to OpenAI, and any future alert email through Resend, also involve United States-based processors.

For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 10. The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere beyond the anonymous click-attribution values described in section 3. What crosses the border is the store configuration, order-attribution records, feed data and access tokens listed in section 2.

Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.

10. Security

We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.

11. Protected customer data

Capyo requests Shopify's Level 1 protected customer data (order information) so that order totals and line items can be attributed to a ChatGPT ad click and shown in your revenue report. It does not request, and does not use, customer name, email, phone or address fields. A request for Level 2 fields (for hashed match keys, a possible future feature) would only follow a separate Shopify approval and a change to this policy before it started.

12. Your rights

Under the GDPR you can ask us to:

Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app triggers deletion automatically, as described in section 7.

You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.

13. Changes to this policy

When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.

14. Contact

gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.